<?xml version="1.0" encoding="UTF-8"?>
<nvd nvd_xml_version="1.2" pub_date="2008-09-05" xmlns="http://nvd.nist.gov/feeds/cve/1.2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd"><!--This XML file has been upgraded to support CVSS version 2.  The following new attributes have been added to CVS entries:
* CVSS_version - Indicates the version of the CVSS data
* CVSS_base_score - The CVSSv2 base score
* CVSS_impact_subscore - The CVSSv2 impact sub-score
* CVSS_exploit_subscore - the CVSSv2 exploit sub-score

The following attributes have been mapped to new content in CVS entries:
* CVSS_score - This attribute is the same as the CVSS_base_score and is now deprecated.
* CVSS_vector - Contains the new CVSSv2 vector string--><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-02" name="CVE-2003-1564" published="2003-12-31" seq="2003-1564" severity="High" type="CVE"><desc><descript source="cve">libxml2, possibly before 2.5.0, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, aka the &quot;billion laughs attack.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref source="MLIST" url="http://mail.gnome.org/archives/xml/2008-August/msg00034.html">[xml] 20080820 Security fix for libxml2</ref><ref source="" url="http://www.reddit.com/r/programming/comments/65843/time_to_upgrade_libxml2"></ref><ref source="" url="http://xmlsoft.org/news.html"></ref></refs><vuln_soft><prod name="Libxml2" vendor="XMLSoft"><vers num="1.7.0"/><vers num="1.7.1"/><vers num="1.7.2"/><vers num="1.7.3"/><vers num="1.7.4"/><vers num="1.8.0"/><vers num="1.8.1"/><vers num="1.8.10"/><vers num="1.8.13"/><vers num="1.8.14"/><vers num="1.8.16"/><vers num="1.8.2"/><vers num="1.8.3"/><vers num="1.8.4"/><vers num="1.8.5"/><vers num="1.8.6"/><vers num="1.8.7"/><vers num="1.8.9"/><vers num="2.0.0"/><vers num="2.1.0"/><vers num="2.1.1"/><vers num="2.2.0"/><vers num="2.2.1"/><vers num="2.2.10"/><vers num="2.2.11"/><vers num="2.2.2"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.2.5"/><vers num="2.2.6"/><vers num="2.2.7"/><vers num="2.2.8"/><vers num="2.2.9"/><vers num="2.3.0"/><vers num="2.3.1"/><vers num="2.3.10"/><vers num="2.3.11"/><vers num="2.3.12"/><vers num="2.3.13"/><vers num="2.3.14"/><vers num="2.3.2"/><vers num="2.3.3"/><vers num="2.3.4"/><vers num="2.3.5"/><vers num="2.3.6"/><vers num="2.3.7"/><vers num="2.3.8"/><vers num="2.3.9"/><vers num="2.4.1"/><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18"/><vers num="2.4.19"/><vers num="2.4.2"/><vers num="2.4.20"/><vers num="2.4.21"/><vers num="2.4.22"/><vers num="2.4.23"/><vers num="2.4.24"/><vers num="2.4.25"/><vers num="2.4.26"/><vers num="2.4.27"/><vers num="2.4.28"/><vers num="2.4.29"/><vers num="2.4.3"/><vers num="2.4.30"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.5.0"/><vers edition="beta" num="2.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2007-1899" published="2008-07-08" seq="2007-1899" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in myWebland myBloggie 2.1.6 allow remote attackers to execute arbitrary SQL commands via (1) the user_id parameter in a viewuser action to index.php, and allow remote authenticated administrators to execute arbitrary SQL commands via (2) the post_id parameter in an edit action to admin.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5975">5975</ref><ref source="" url="http://descriptions.securescout.com/tc/17969"></ref><ref source="" url="http://www.netvigilance.com/advisory0040"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30892">30892</ref></refs><vuln_soft><prod name="myBloggie" vendor="myWebland"><vers num="2.1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="6.3" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="6.9" CVSS_score="6.3" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2007-5474" published="2008-09-05" seq="2007-5474" severity="Medium" type="CVE"><desc><descript source="cve">The driver for the Linksys WRT350N Wi-Fi access point with firmware 2.00.17 on the Atheros AR5416-AC1E chipset does not properly parse the Atheros vendor-specific information element in an association request, which allows remote authenticated users to cause a denial of service (device reboot or hang) or possibly execute arbitrary code via an Atheros information element with an invalid length, as demonstrated by an element that is too long.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/495984/100/0/threaded">20080904 Atheros Vendor Specific Information Element Overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/31012">31012</ref></refs><vuln_soft><prod name="WRT350N" vendor="Linksys"><vers num="2.00.17"/></prod><prod name="ar5416-ac1e_chipset" vendor="Atheros"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.7" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="6.9" CVSS_score="4.7" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2007-6716" published="2008-09-04" seq="2007-6716" severity="Medium" type="CVE"><desc><descript source="cve">fs/direct-io.c in the dio subsystem in the Linux kernel before 2.6.23 does not properly zero out the dio struct, which allows local users to cause a denial of service (OOPS), as demonstrated by a certain fio test.</descript></desc><loss_types><avail/></loss_types><range><local/></range><refs><ref source="MLIST" url="http://lkml.org/lkml/2007/7/30/448">[linux-kernel] 20070731 Re: [PATCH] add check do_direct_IO() return val</ref><ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2008/09/04/1">[oss-security] 20080904 CVE request: kernel: dio: zero struct dio with kzalloc instead of manually</ref><ref source="" url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=848c4dd5153c7a0de55470ce99a8e13a63b4703f"></ref><ref patch="1" source="" url="https://bugzilla.redhat.com/show_bug.cgi?id=461082"></ref><ref source="" url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.23"></ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="1.2"/><vers num="1.3"/><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.10"/><vers num="2.0.11"/><vers num="2.0.12"/><vers num="2.0.13"/><vers num="2.0.14"/><vers num="2.0.15"/><vers num="2.0.16"/><vers num="2.0.17"/><vers num="2.0.18"/><vers num="2.0.19"/><vers num="2.0.2"/><vers num="2.0.20"/><vers num="2.0.21"/><vers num="2.0.22"/><vers num="2.0.23"/><vers num="2.0.24"/><vers num="2.0.25"/><vers num="2.0.26"/><vers num="2.0.27"/><vers num="2.0.28"/><vers num="2.0.29"/><vers num="2.0.3"/><vers num="2.0.30"/><vers num="2.0.31"/><vers num="2.0.32"/><vers num="2.0.33"/><vers num="2.0.34"/><vers num="2.0.35"/><vers num="2.0.36"/><vers num="2.0.37"/><vers num="2.0.38"/><vers num="2.0.39"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.0.6"/><vers num="2.0.7"/><vers num="2.0.8"/><vers num="2.0.9"/><vers num="2.0.9.9"/><vers num="2.1"/><vers num="2.1.132"/><vers num="2.1.89"/><vers num="2.2"/><vers num="2.2.1"/><vers num="2.2.10"/><vers num="2.2.11"/><vers num="2.2.12"/><vers num="2.2.13"/><vers num="2.2.13 pre15"/><vers num="2.2.14"/><vers num="2.2.15"/><vers num="2.2.15 pre16"/><vers num="2.2.15 pre20"/><vers num="2.2.16"/><vers num="2.2.16 pre5"/><vers num="2.2.16 pre6"/><vers num="2.2.17"/><vers num="2.2.17.14"/><vers num="2.2.18"/><vers num="2.2.19"/><vers num="2.2.2"/><vers num="2.2.20"/><vers num="2.2.21"/><vers num="2.2.21 pre1"/><vers num="2.2.21 pre2"/><vers num="2.2.21 pre3"/><vers num="2.2.21 pre4"/><vers num="2.2.21 rc1"/><vers num="2.2.21 rc2"/><vers num="2.2.21 rc3"/><vers num="2.2.21 rc4"/><vers num="2.2.22"/><vers num="2.2.22 rc1"/><vers num="2.2.22 rc2"/><vers num="2.2.22 rc3"/><vers num="2.2.23"/><vers num="2.2.23 rc1"/><vers num="2.2.23 rc2"/><vers num="2.2.24"/><vers num="2.2.24 rc2"/><vers num="2.2.24 rc3"/><vers num="2.2.24 rc4"/><vers num="2.2.24 rc5"/><vers num="2.2.25"/><vers num="2.2.26"/><vers num="2.2.27"/><vers num="2.2.27 pre1"/><vers num="2.2.27 pre2"/><vers num="2.2.27 rc1"/><vers num="2.2.27 rc2"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.2.4 rc1"/><vers num="2.2.5"/><vers num="2.2.6"/><vers num="2.2.7"/><vers num="2.2.8"/><vers num="2.2.9"/><vers num="2.3"/><vers num="2.3.1"/><vers num="2.3.10"/><vers num="2.3.11"/><vers num="2.3.12"/><vers num="2.3.13"/><vers num="2.3.14"/><vers num="2.3.15"/><vers num="2.3.16"/><vers num="2.3.17"/><vers num="2.3.18"/><vers num="2.3.19"/><vers num="2.3.2"/><vers num="2.3.20"/><vers num="2.3.21"/><vers num="2.3.22"/><vers num="2.3.23"/><vers num="2.3.24"/><vers num="2.3.25"/><vers num="2.3.26"/><vers num="2.3.27"/><vers num="2.3.28"/><vers num="2.3.29"/><vers num="2.3.3"/><vers num="2.3.30"/><vers num="2.3.31"/><vers num="2.3.32"/><vers num="2.3.33"/><vers num="2.3.34"/><vers num="2.3.35"/><vers num="2.3.36"/><vers num="2.3.37"/><vers num="2.3.38"/><vers num="2.3.39"/><vers num="2.3.4"/><vers num="2.3.40"/><vers num="2.3.41"/><vers num="2.3.42"/><vers num="2.3.43"/><vers num="2.3.44"/><vers num="2.3.45"/><vers num="2.3.46"/><vers num="2.3.47"/><vers num="2.3.48"/><vers num="2.3.49"/><vers num="2.3.5"/><vers num="2.3.50"/><vers num="2.3.51"/><vers num="2.3.6"/><vers num="2.3.7"/><vers num="2.3.8"/><vers num="2.3.9"/><vers num="2.3.99"/><vers num="2.3.99 pre1"/><vers num="2.3.99 pre2"/><vers num="2.3.99 pre3"/><vers num="2.3.99 pre4"/><vers num="2.3.99 pre5"/><vers num="2.3.99 pre6"/><vers num="2.3.99 pre7"/><vers num="2.3.99 pre8"/><vers num="2.3.99 pre9"/><vers num="2.4.0"/><vers num="2.4.0 test1"/><vers num="2.4.0 test10"/><vers num="2.4.0 test11"/><vers num="2.4.0 test12"/><vers num="2.4.0 test2"/><vers num="2.4.0 test3"/><vers num="2.4.0 test4"/><vers num="2.4.0 test5"/><vers num="2.4.0 test6"/><vers num="2.4.0 test7"/><vers num="2.4.0 test8"/><vers num="2.4.0 test9"/><vers num="2.4.1"/><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.11 pre3"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18"/><vers num="2.4.18 pre1"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre4"/><vers num="2.4.18 pre5"/><vers num="2.4.18 pre6"/><vers num="2.4.18 pre7"/><vers num="2.4.18 pre8"/><vers num="2.4.18 pre9"/><vers num="2.4.19"/><vers num="2.4.19 pre1"/><vers num="2.4.19 pre2"/><vers num="2.4.19 pre3"/><vers num="2.4.19 pre4"/><vers num="2.4.19 pre5"/><vers num="2.4.19 pre6"/><vers num="2.4.2"/><vers num="2.4.20"/><vers num="2.4.21"/><vers num="2.4.21 pre1"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre7"/><vers num="2.4.22"/><vers num="2.4.22 pre10"/><vers num="2.4.23"/><vers num="2.4.23 ow2"/><vers num="2.4.23 pre9"/><vers num="2.4.24"/><vers num="2.4.24 ow1"/><vers num="2.4.25"/><vers num="2.4.26"/><vers num="2.4.27"/><vers num="2.4.27 pre1"/><vers num="2.4.27 pre2"/><vers num="2.4.27 pre3"/><vers num="2.4.27 pre4"/><vers num="2.4.27 pre5"/><vers num="2.4.28"/><vers num="2.4.29"/><vers num="2.4.29 rc1"/><vers num="2.4.29 rc2"/><vers num="2.4.3"/><vers num="2.4.3 pre3"/><vers num="2.4.30"/><vers num="2.4.30 rc2"/><vers num="2.4.30 rc3"/><vers num="2.4.31"/><vers num="2.4.31 pre1"/><vers num="2.4.32"/><vers num="2.4.32 pre1"/><vers num="2.4.32 pre2"/><vers num="2.4.33"/><vers num="2.4.33 pre1"/><vers num="2.4.33.2"/><vers num="2.4.33.3"/><vers num="2.4.33.4"/><vers num="2.4.33.5"/><vers num="2.4.34"/><vers num="2.4.34 rc3"/><vers num="2.4.34.1"/><vers num="2.4.34.2"/><vers num="2.4.35"/><vers num="2.4.35.2"/><vers num="2.4.36"/><vers num="2.4.36.1"/><vers num="2.4.36.2"/><vers num="2.4.36.3"/><vers num="2.4.36.4"/><vers num="2.4.36.5"/><vers num="2.4.36.6"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.4.9 pre5"/><vers num="2.5.0"/><vers num="2.5.1"/><vers num="2.5.10"/><vers num="2.5.11"/><vers num="2.5.12"/><vers num="2.5.13"/><vers num="2.5.14"/><vers num="2.5.15"/><vers num="2.5.16"/><vers num="2.5.17"/><vers num="2.5.18"/><vers num="2.5.19"/><vers num="2.5.2"/><vers num="2.5.20"/><vers num="2.5.21"/><vers num="2.5.22"/><vers num="2.5.23"/><vers num="2.5.24"/><vers num="2.5.25"/><vers num="2.5.26"/><vers num="2.5.27"/><vers num="2.5.28"/><vers num="2.5.29"/><vers num="2.5.3"/><vers num="2.5.30"/><vers num="2.5.31"/><vers num="2.5.32"/><vers num="2.5.33"/><vers num="2.5.34"/><vers num="2.5.35"/><vers num="2.5.36"/><vers num="2.5.37"/><vers num="2.5.38"/><vers num="2.5.39"/><vers num="2.5.4"/><vers num="2.5.40"/><vers num="2.5.41"/><vers num="2.5.42"/><vers num="2.5.43"/><vers num="2.5.44"/><vers num="2.5.45"/><vers num="2.5.46"/><vers num="2.5.47"/><vers num="2.5.48"/><vers num="2.5.49"/><vers num="2.5.5"/><vers num="2.5.50"/><vers num="2.5.51"/><vers num="2.5.52"/><vers num="2.5.53"/><vers num="2.5.54"/><vers num="2.5.55"/><vers num="2.5.56"/><vers num="2.5.57"/><vers num="2.5.58"/><vers num="2.5.59"/><vers num="2.5.6"/><vers num="2.5.60"/><vers num="2.5.61"/><vers num="2.5.62"/><vers num="2.5.63"/><vers num="2.5.64"/><vers num="2.5.65"/><vers num="2.5.66"/><vers num="2.5.67"/><vers num="2.5.68"/><vers num="2.5.69"/><vers num="2.5.7"/><vers num="2.5.8"/><vers num="2.5.9"/><vers num="2.6"/><vers num="2.6 test1"/><vers num="2.6 test10"/><vers num="2.6 test11"/><vers num="2.6 test2"/><vers num="2.6 test3"/><vers num="2.6 test4"/><vers num="2.6 test5"/><vers num="2.6 test6"/><vers num="2.6 test7"/><vers num="2.6 test8"/><vers num="2.6 test9"/><vers num="2.6 test9 CVS"/><vers num="2.6.0"/><vers num="2.6.1"/><vers num="2.6.1 rc1"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc3"/><vers num="2.6.10"/><vers num="2.6.10 rc1"/><vers num="2.6.10 rc2"/><vers num="2.6.10 rc3"/><vers num="2.6.11"/><vers num="2.6.11 rc1"/><vers num="2.6.11 rc1 bk6"/><vers num="2.6.11 rc2"/><vers num="2.6.11 rc3"/><vers num="2.6.11 rc4"/><vers num="2.6.11 rc5"/><vers num="2.6.11.1"/><vers num="2.6.11.10"/><vers num="2.6.11.11"/><vers num="2.6.11.12"/><vers num="2.6.11.2"/><vers num="2.6.11.3"/><vers num="2.6.11.4"/><vers num="2.6.11.5"/><vers num="2.6.11.6"/><vers num="2.6.11.7"/><vers num="2.6.11.8"/><vers num="2.6.11.9"/><vers num="2.6.12"/><vers num="2.6.12 rc1"/><vers num="2.6.12 rc2"/><vers num="2.6.12 rc3"/><vers num="2.6.12 rc4"/><vers num="2.6.12 rc5"/><vers num="2.6.12 rc6"/><vers num="2.6.12.1"/><vers num="2.6.12.12"/><vers num="2.6.12.2"/><vers num="2.6.12.22"/><vers num="2.6.12.3"/><vers num="2.6.12.4"/><vers num="2.6.12.5"/><vers num="2.6.12.6"/><vers num="2.6.13"/><vers num="2.6.13 rc1"/><vers num="2.6.13 rc2"/><vers num="2.6.13 rc3"/><vers num="2.6.13 rc4"/><vers num="2.6.13 rc5"/><vers num="2.6.13 rc6"/><vers num="2.6.13 rc7"/><vers num="2.6.13.1"/><vers num="2.6.13.2"/><vers num="2.6.13.3"/><vers num="2.6.13.4"/><vers num="2.6.13.5"/><vers num="2.6.14"/><vers num="2.6.14 rc1"/><vers num="2.6.14 rc2"/><vers num="2.6.14 rc3"/><vers num="2.6.14 rc4"/><vers num="2.6.14 rc5"/><vers num="2.6.14.1"/><vers num="2.6.14.2"/><vers num="2.6.14.3"/><vers num="2.6.14.4"/><vers num="2.6.14.5"/><vers num="2.6.14.6"/><vers num="2.6.14.7"/><vers num="2.6.15"/><vers num="2.6.15 rc1"/><vers num="2.6.15 rc2"/><vers num="2.6.15 rc3"/><vers num="2.6.15 rc4"/><vers num="2.6.15 rc5"/><vers num="2.6.15 rc6"/><vers num="2.6.15 rc7"/><vers num="2.6.15.1"/><vers num="2.6.15.11"/><vers num="2.6.15.2"/><vers num="2.6.15.3"/><vers num="2.6.15.4"/><vers num="2.6.15.5"/><vers num="2.6.15.6"/><vers num="2.6.15.7"/><vers num="2.6.16"/><vers num="2.6.16 rc1"/><vers num="2.6.16 rc2"/><vers num="2.6.16 rc3"/><vers num="2.6.16 rc4"/><vers num="2.6.16 rc5"/><vers num="2.6.16 rc6"/><vers num="2.6.16 rc7"/><vers num="2.6.16.1"/><vers num="2.6.16.10"/><vers num="2.6.16.11"/><vers num="2.6.16.12"/><vers num="2.6.16.13"/><vers num="2.6.16.14"/><vers num="2.6.16.15"/><vers num="2.6.16.16"/><vers num="2.6.16.17"/><vers num="2.6.16.18"/><vers num="2.6.16.19"/><vers num="2.6.16.2"/><vers num="2.6.16.20"/><vers num="2.6.16.21"/><vers num="2.6.16.22"/><vers num="2.6.16.23"/><vers num="2.6.16.24"/><vers num="2.6.16.25"/><vers num="2.6.16.26"/><vers num="2.6.16.27"/><vers num="2.6.16.28"/><vers num="2.6.16.29"/><vers num="2.6.16.3"/><vers num="2.6.16.30"/><vers num="2.6.16.31"/><vers num="2.6.16.32"/><vers num="2.6.16.33"/><vers num="2.6.16.34"/><vers num="2.6.16.35"/><vers num="2.6.16.36"/><vers num="2.6.16.37"/><vers num="2.6.16.38"/><vers num="2.6.16.39"/><vers num="2.6.16.4"/><vers num="2.6.16.40"/><vers num="2.6.16.41"/><vers num="2.6.16.43"/><vers num="2.6.16.44"/><vers num="2.6.16.45"/><vers num="2.6.16.46"/><vers num="2.6.16.47"/><vers num="2.6.16.48"/><vers num="2.6.16.49"/><vers num="2.6.16.5"/><vers num="2.6.16.50"/><vers num="2.6.16.51"/><vers num="2.6.16.52"/><vers num="2.6.16.53"/><vers num="2.6.16.6"/><vers num="2.6.16.7"/><vers num="2.6.16.8"/><vers num="2.6.16.9"/><vers num="2.6.17"/><vers num="2.6.17 rc1"/><vers num="2.6.17 rc2"/><vers num="2.6.17 rc3"/><vers num="2.6.17 rc4"/><vers num="2.6.17 rc5"/><vers num="2.6.17 rc6"/><vers num="2.6.17.1"/><vers num="2.6.17.10"/><vers num="2.6.17.11"/><vers num="2.6.17.12"/><vers num="2.6.17.13"/><vers num="2.6.17.14"/><vers num="2.6.17.2"/><vers num="2.6.17.3"/><vers num="2.6.17.4"/><vers num="2.6.17.5"/><vers num="2.6.17.6"/><vers num="2.6.17.7"/><vers num="2.6.17.8"/><vers num="2.6.17.9"/><vers num="2.6.18"/><vers num="2.6.18 rc1"/><vers num="2.6.18 rc2"/><vers num="2.6.18 rc3"/><vers num="2.6.18 rc4"/><vers num="2.6.18 rc5"/><vers num="2.6.18 rc6"/><vers num="2.6.18 rc7"/><vers num="2.6.18 stable"/><vers num="2.6.18.1"/><vers num="2.6.18.10"/><vers num="2.6.18.11"/><vers num="2.6.18.12"/><vers num="2.6.18.13"/><vers num="2.6.18.14"/><vers num="2.6.18.15"/><vers num="2.6.18.16"/><vers num="2.6.18.17"/><vers num="2.6.18.18"/><vers num="2.6.18.19"/><vers num="2.6.18.2"/><vers num="2.6.18.20"/><vers num="2.6.18.21"/><vers num="2.6.18.22"/><vers num="2.6.18.23"/><vers num="2.6.18.24"/><vers num="2.6.18.25"/><vers num="2.6.18.26"/><vers num="2.6.18.27"/><vers num="2.6.18.28"/><vers num="2.6.18.29"/><vers num="2.6.18.3"/><vers num="2.6.18.30"/><vers num="2.6.18.31"/><vers num="2.6.18.32"/><vers num="2.6.18.33"/><vers num="2.6.18.34"/><vers num="2.6.18.35"/><vers num="2.6.18.36"/><vers num="2.6.18.37"/><vers num="2.6.18.38"/><vers num="2.6.18.39"/><vers num="2.6.18.4"/><vers num="2.6.18.40"/><vers num="2.6.18.41"/><vers num="2.6.18.42"/><vers num="2.6.18.43"/><vers num="2.6.18.44"/><vers num="2.6.18.45"/><vers num="2.6.18.46"/><vers num="2.6.18.47"/><vers num="2.6.18.48"/><vers num="2.6.18.49"/><vers num="2.6.18.5"/><vers num="2.6.18.50"/><vers num="2.6.18.51"/><vers num="2.6.18.52"/><vers num="2.6.18.53"/><vers num="2.6.18.6"/><vers num="2.6.18.7"/><vers num="2.6.18.8"/><vers num="2.6.18.9"/><vers num="2.6.18_8.1.8.el5"/><vers num="2.6.19"/><vers num="2.6.19 rc1"/><vers num="2.6.19 rc2"/><vers num="2.6.19 rc3"/><vers num="2.6.19 rc4"/><vers num="2.6.19.1"/><vers num="2.6.19.2"/><vers num="2.6.19.3"/><vers num="2.6.19.4"/><vers num="2.6.19.5"/><vers num="2.6.19.6"/><vers num="2.6.19.7"/><vers num="2.6.2"/><vers num="2.6.2 rc1"/><vers num="2.6.2 rc2"/><vers num="2.6.2 rc3"/><vers num="2.6.20"/><vers num="2.6.20.1"/><vers num="2.6.20.10"/><vers num="2.6.20.11"/><vers num="2.6.20.12"/><vers num="2.6.20.13"/><vers num="2.6.20.14"/><vers num="2.6.20.15"/><vers num="2.6.20.16"/><vers num="2.6.20.17"/><vers num="2.6.20.18"/><vers num="2.6.20.19"/><vers num="2.6.20.2"/><vers num="2.6.20.20"/><vers num="2.6.20.21"/><vers num="2.6.20.3"/><vers num="2.6.20.4"/><vers num="2.6.20.5"/><vers num="2.6.20.6"/><vers num="2.6.20.7"/><vers num="2.6.20.8"/><vers num="2.6.20.9"/><vers num="2.6.20_rc2"/><vers num="2.6.21"/><vers num="2.6.21 git1"/><vers num="2.6.21 git2"/><vers num="2.6.21 git3"/><vers num="2.6.21 git4"/><vers num="2.6.21 git5"/><vers num="2.6.21 git6"/><vers num="2.6.21 git7"/><vers num="2.6.21.1"/><vers num="2.6.21.2"/><vers num="2.6.21.3"/><vers num="2.6.21.4"/><vers num="2.6.21.5"/><vers num="2.6.21.6"/><vers num="2.6.21.7"/><vers num="2.6.21_rc3"/><vers num="2.6.21_rc4"/><vers num="2.6.21_rc5"/><vers num="2.6.21_rc6"/><vers num="2.6.21_rc7"/><vers num="2.6.22"/><vers num="2.6.22 rc6"/><vers num="2.6.22.1"/><vers num="2.6.22.10"/><vers num="2.6.22.11"/><vers num="2.6.22.12"/><vers num="2.6.22.13"/><vers num="2.6.22.14"/><vers num="2.6.22.15"/><vers num="2.6.22.16"/><vers num="2.6.22.17"/><vers num="2.6.22.18"/><vers num="2.6.22.19"/><vers num="2.6.22.2"/><vers num="2.6.22.20"/><vers num="2.6.22.21"/><vers num="2.6.22.22"/><vers num="2.6.22.3"/><vers num="2.6.22.4"/><vers num="2.6.22.5"/><vers num="2.6.22.6"/><vers num="2.6.22.7"/><vers num="2.6.22.8"/><vers num="2.6.22.9"/><vers num="2.6.22_rc1"/><vers num="2.6.22_rc7"/><vers num="2.6.23"/><vers num="2.6.23 .2"/><vers num="2.6.23 rc1"/><vers num="2.6.23.09"/><vers num="2.6.23.1"/><vers num="2.6.23.10"/><vers num="2.6.23.11"/><vers num="2.6.23.12"/><vers num="2.6.23.13"/><vers num="2.6.23.14"/><vers num="2.6.23.15"/><vers num="2.6.23.16"/><vers num="2.6.23.17"/><vers num="2.6.23.2"/><vers num="2.6.23.3"/><vers num="2.6.23.4"/><vers num="2.6.23.5"/><vers num="2.6.23.6"/><vers num="2.6.23.7"/><vers num="2.6.23.8"/><vers num="2.6.23.9"/><vers num="2.6.23_rc1"/><vers num="2.6.23_rc2"/><vers num="2.6.23rc1"/><vers num="2.6.23rc2"/><vers num="2.6.24"/><vers num="2.6.24 rc2"/><vers num="2.6.24.1"/><vers num="2.6.24.2"/><vers num="2.6.24.3"/><vers num="2.6.24.4"/><vers num="2.6.24.5"/><vers num="2.6.24.6"/><vers num="2.6.24.7"/><vers num="2.6.24_rc1"/><vers num="2.6.24_rc2"/><vers num="2.6.24_rc3"/><vers num="2.6.24_rc4"/><vers num="2.6.24_rc5"/><vers num="2.6.25"/><vers num="2.6.25.1"/><vers num="2.6.25.10"/><vers num="2.6.25.11"/><vers num="2.6.25.12"/><vers num="2.6.25.13"/><vers num="2.6.25.14"/><vers num="2.6.25.15"/><vers num="2.6.25.2"/><vers num="2.6.25.3"/><vers num="2.6.25.4"/><vers num="2.6.25.5"/><vers num="2.6.25.6"/><vers num="2.6.25.7"/><vers num="2.6.25.8"/><vers num="2.6.25.9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.3" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="6.9" CVSS_score="6.3" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-1144" published="2008-09-05" seq="2008-1144" severity="Medium" type="CVE"><desc><descript source="cve">The Marvell driver for the Netgear WN802T Wi-Fi access point with firmware 1.3.16 on the Marvell 88W8361P-BEM1 chipset does not properly parse EAPoL-Key packets, which allows remote authenticated users to cause a denial of service (device reboot or hang) or possibly execute arbitrary code via a malformed EAPoL-Key packet with a crafted &quot;advertised length.&quot;</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/495982/100/0/threaded">20080904 Marvell Driver EAPoL-Key Length Overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/31013">31013</ref></refs><vuln_soft><prod name="wn802t" vendor="NetGear"><vers num="1.3.16"/></prod><prod name="88w8361w-bem1" vendor="marvell"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.3" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="6.9" CVSS_score="6.3" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-1197" published="2008-09-05" seq="2008-1197" severity="Medium" type="CVE"><desc><descript source="cve">The Marvell driver for the Netgear WN802T Wi-Fi access point with firmware 1.3.16 on the Marvell 88W8361P-BEM1 chipset does not properly parse the SSID information element in an association request, which allows remote authenticated users to cause a denial of service (device reboot or hang) or possibly execute arbitrary code via a &quot;Null SSID.&quot;</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/495983/100/0/threaded">20080904 Marvell Driver Null SSID Association Request Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/30976">30976</ref></refs><vuln_soft><prod name="wn802t" vendor="NetGear"><vers num="1.3.16"/></prod><prod name="88w8361w-bem1" vendor="marvell"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-1389" published="2008-09-04" seq="2008-1389" severity="Medium" type="CVE"><desc><descript source="cve">libclamav/chmunpack.c in the chm-parser in ClamAV before 0.94 allows remote attackers to cause a denial of service (application crash) via a malformed CHM file, related to an &quot;invalid memory access.&quot;</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="" url="http://int21.de/cve/CVE-2008-1389-clamav-chd.html"></ref><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?group_id=86638&amp;release_id=623661"></ref><ref source="" url="http://svn.clamav.net/svn/clamav-devel/trunk/ChangeLog"></ref><ref source="" url="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1089"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/2484">ADV-2008-2484</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31725">31725</ref></refs><vuln_soft><prod name="ClamAV" vendor="Clam Anti-Virus"><vers num="0.93.3" prev="1"/><vers num="0.93.1"/><vers num="0.92"/><vers num="0.92.1"/><vers num="0.93"/><vers num="0.86"/><vers num="0.86.1"/><vers num="0.86.2"/><vers num="0.87"/><vers num="0.87.1"/><vers num="0.88"/><vers num="0.88.1"/><vers num="0.88.2"/><vers num="0.88.3"/><vers num="0.88.4"/><vers num="0.88.5"/><vers num="0.88.6"/><vers num="0.88.7"/><vers num="0.90"/><vers num="0.90.1"/><vers num="0.90.2"/><vers num="0.90.3"/><vers num="0.91"/><vers num="0.91.1"/><vers num="0.91.2"/><vers edition="rc1" num="0.86"/><vers num="0.85"/><vers num="0.85.1"/><vers edition="rc1" num="0.84"/><vers edition="rc2" num="0.84"/><vers num="0.84"/><vers num="0.81"/><vers num="0.82"/><vers num="0.83"/><vers edition="rc1" num="0.81"/><vers edition="rc" num="0.80"/><vers edition="rc2" num="0.80"/><vers edition="rc3" num="0.80"/><vers edition="rc4" num="0.80"/><vers num="0.80"/><vers num="0.15"/><vers num="0.20"/><vers num="0.21"/><vers num="0.22"/><vers num="0.23"/><vers num="0.24"/><vers num="0.51"/><vers num="0.52"/><vers num="0.53"/><vers num="0.54"/><vers num="0.60"/><vers num="0.60p"/><vers num="0.65"/><vers num="0.67"/><vers num="0.68"/><vers num="0.68.1"/><vers num="0.70"/><vers num="0.71"/><vers num="0.72"/><vers num="0.73"/><vers num="0.74"/><vers num="0.75"/><vers num="0.75.1"/><vers num="0.11"/><vers num="0.12"/><vers num="0.13"/><vers num="0.14"/><vers edition="pre" num="0.14"/></prod></vuln_soft></entry><entry CVSS_base_score="9.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="9.2" CVSS_score="9.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:C/A:C)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-1454" published="2008-07-08" seq="2008-1454" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to conduct cache poisoning attacks via unknown vectors, aka &quot;DNS Cache Poisoning Vulnerability,&quot; a different vulnerability than CVE-2008-1447.</descript></desc><loss_types><avail/><int/></loss_types><range><network/></range><refs><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-037.mspx">MS08-037</ref></refs><vuln_soft><prod name="windows-nt" vendor="Microsoft"><vers edition="sp4" num="2000"/><vers edition="sp2" num="XP"/><vers edition="unknown" num="XP"/><vers edition="sp2" num="XP"/><vers edition="sp3" num="XP"/><vers edition="sp1" num="2003"/><vers edition="sp2" num="2003"/><vers edition="sp2" num="2003"/><vers edition="unknown" num="2003"/><vers edition="sp2" num="2003"/><vers edition="sp1" num="2003"/><vers edition="unknown" num="2008"/><vers edition="unknown" num="2008"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-03" name="CVE-2008-1739" published="2008-09-03" seq="2008-1739" severity="Medium" type="CVE"><desc><descript source="cve">Apple QuickTime before 7.4.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted ftyp atoms in a movie file, which triggers memory corruption.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://support.apple.com/kb/HT1241"></ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="3"/><vers num="5.0"/><vers num="5.0.1"/><vers num="5.0.2"/><vers num="6.0"/><vers num="6.1"/><vers num="6.5"/><vers num="6.5.1"/><vers num="6.5.2"/><vers num="7.0"/><vers num="7.0.1"/><vers num="7.0.2"/><vers num="7.0.3"/><vers num="7.0.4"/><vers num="7.0.8"/><vers num="7.1"/><vers num="7.1.1"/><vers num="7.1.2"/><vers num="7.1.3"/><vers num="7.1.4"/><vers num="7.1.5"/><vers num="7.1.6"/><vers num="7.2"/><vers num="7.3"/><vers num="7.3.1"/><vers num="7.3.1.70"/><vers num="7.4"/><vers num="7.4.1"/><vers num="7.4.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-09-03" name="CVE-2008-2101" published="2008-09-03" seq="2008-2101" severity="Low" type="CVE"><desc><descript source="cve">The VMware Consolidated Backup (VCB) command-line utilities in VMware ESX 3.0.1 through 3.0.3 and ESX 3.5 place a password on the command line, which allows local users to obtain sensitive information by listing the process.</descript></desc><loss_types><conf/></loss_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/495869/100/0/threaded">20080830 VMSA-2008-0014 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX address information disclosure, privilege escalation and other security issues.</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-August/064118.html">20080830 VMSA-2008-0014 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX address information disclosure, privilege escalation and other security issues.</ref><ref source="BID" url="http://www.securityfocus.com/bid/30937">30937</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/2466">ADV-2008-2466</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31713">31713</ref></refs><vuln_soft><prod name="esx" vendor="VMWare"><vers num="3.0.1"/><vers num="3.0.2"/><vers num="3.0.3"/><vers num="3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2247" published="2008-07-08" seq="2008-2247" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) for Exchange Server 2003 SP2 and 2007 up to SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified e-mail fields, a different vulnerability than CVE-2008-2248.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-039.mspx">MS08-039</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1020439">1020439</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/30964">30964</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/43328">exchange-owa-email-fields-xss(43328)</ref></refs><vuln_soft><prod name="exchange_srv" vendor="Microsoft"><vers edition="sp2" num="2003"/><vers num="2007"/><vers edition="sp1" num="2007"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2372" published="2008-07-02" seq="2008-2372" severity="Medium" type="CVE"><desc><descript source="cve">The Linux kernel 2.6.24 and 2.6.25 before 2.6.25.9 allows local users to cause a denial of service (memory consumption) via a large number of calls to the get_user_pages function, which lacks a ZERO_PAGE optimization and results in allocation of &quot;useless newly zeroed pages.&quot;</descript></desc><loss_types><avail/></loss_types><range><local/></range><refs><ref source="MLIST" url="http://www.ussg.iu.edu/hypermail/linux/kernel/0804.3/3203.html">[linux-kernel] 20080430 Re: Page Faults slower in 2.6.25-rc9 than 2.6.23</ref><ref source="" url="http://new-ubuntu-news.blogspot.com/2008/06/re-pending-stable-kernel-security_25.html"></ref><ref source="" url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=89f5b7da2a6bad2e84670422ab8192382a5aeb9f"></ref><ref source="" url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.25.9"></ref><ref source="" url="http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0207"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-2629"></ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.24"/><vers num="2.6.25"/><vers num="2.6.25.1"/><vers num="2.6.25.2"/><vers num="2.6.25.3"/><vers num="2.6.25.4"/><vers num="2.6.25.5"/><vers num="2.6.25.6"/><vers num="2.6.25.7"/><vers num="2.6.25.8"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-2436" published="2008-09-05" seq="2008-2436" severity="High" type="CVE"><desc><descript source="cve">Multiple heap-based buffer overflows in the IppCreateServerRef function in nipplib.dll in Novell iPrint Client 4.x before 4.38 and 5.x before 5.08 allow remote attackers to execute arbitrary code via a long argument to the (1) GetPrinterURLList, (2) GetPrinterURLList2, or (3) GetFileList2 function in the Novell iPrint ActiveX control in ienipp.ocx.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/495940/100/0/threaded">20080903 Secunia Research: Novell iPrint Client nipplib.dll </ref><ref source="" url="http://secunia.com/secunia_research/2008-33/advisory"></ref><ref source="BID" url="http://www.securityfocus.com/bid/30986">30986</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/31370">31370</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/44853">novell-iprint-ippcreateserverref-bo(44853)</ref></refs><vuln_soft><prod name="iPrint Client" vendor="Novell"><vers edition="unknown" num="4.26"/><vers edition="unknown" num="4.32"/><vers edition="unknown" num="4.35"/><vers edition="unknown" num="4.36"/><vers edition="unknown" num="5.06"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2441" published="2008-09-04" seq="2008-2441" severity="High" type="CVE"><desc><descript source="cve">CSRadius.exe in Cisco Secure ACS does not properly handle an EAP Response packet in which the value of the length field exceeds the actual packet length, which allows remote attackers to cause a denial of service (service crash) or possibly execute arbitrary code via a crafted (1) EAP-Response/Identity, (2) EAP-Response/MD5, or (3) EAP-Response/TLS packet.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/495937/100/0/threaded">20080903 Cisco Secure ACS EAP Parsing Vulnerability</ref></refs><vuln_soft><prod name="Secure ACS" vendor="Cisco"><vers num=""/></prod><prod name="Cisco Secure Access Control Server" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2591" published="2008-07-15" seq="2008-2591" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Oracle Database Vault component in Oracle Database 9.2.0.8DV, 10.2.0.3, and 11.1.0.6 has unknown impact and remote authenticated attack vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2008.html"></ref></refs><vuln_soft><prod name="Database 11g" vendor="Oracle"><vers num="11.1.0.6"/></prod><prod name="Database 9i" vendor="Oracle"><vers num="9.2.0.8DV"/></prod><prod name="Database 10g" vendor="Oracle"><vers num="10.2.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2595" published="2008-07-15" seq="2008-2595" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Oracle Internet Directory component in Oracle Application Server 9.0.4.3, 10.1.2.3, and 10.1.4.2 has unknown impact and remote attack vectors.  NOTE: the previous information was obtained from the Oracle July 2008 CPU.  Oracle has not commented on reliable researcher claims that this issue is a denial of service (crash) via a malformed LDAP request that triggers a NULL pointer dereference.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2008.html"></ref></refs><vuln_soft><prod name="Database 9i" vendor="Oracle"><vers num="9.0.4.3"/></prod><prod name="Database 10g" vendor="Oracle"><vers num="10.1.2.3"/><vers num="10.1.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="4.9" CVSS_score="5.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2601" published="2008-07-15" seq="2008-2601" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Oracle iStore component in Oracle E-Business Suite 12.0.4 has unknown impact and remote authenticated attack vectors.</descript></desc><loss_types><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2008.html"></ref></refs><vuln_soft><prod name="E-Business Suite" vendor="Oracle"><vers num="12.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-02" name="CVE-2008-2727" published="2008-09-02" seq="2008-2727" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in the rb_ary_splice function in Ruby 1.6.x allows context-dependent attackers to trigger memory corruption via unspecified vectors, aka the &quot;1.6.x variant&quot; of the &quot;REALLOC_N&quot; variant.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MLIST" url="http://www.redhat.com/archives/fedora-security-commits/2008-June/msg00005.html">[fedora-security-commits] 20080620 fedora-security/audit f10, 1.7, 1.8 f8, 1.225, 1.226 f9, 1.215, 1.216</ref><ref patch="1" source="" url="https://bugs.launchpad.net/ubuntu/+source/ruby1.8/+bug/241657"></ref><ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.html">SUSE-SR:2008:017</ref></refs><vuln_soft><prod name="Ruby" vendor="ruby-lang"><vers num="1.6"/><vers num="1.6.8"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-02" name="CVE-2008-2728" published="2008-09-02" seq="2008-2728" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in the rb_ary_splice function in Ruby 1.6.x allows context-dependent attackers to trigger memory corruption, aka the &quot;1.6.x variant&quot; of the &quot;beg + rlen&quot; issue.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MLIST" url="http://www.redhat.com/archives/fedora-security-commits/2008-June/msg00005.html">[fedora-security-commits] 20080620 fedora-security/audit f10, 1.7, 1.8 f8, 1.225, 1.226 f9, 1.215, 1.216</ref><ref patch="1" source="" url="https://bugs.launchpad.net/ubuntu/+source/ruby1.8/+bug/241657"></ref><ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.html">SUSE-SR:2008:017</ref></refs><vuln_soft><prod name="Ruby" vendor="ruby-lang"><vers num="1.6"/><vers num="1.6.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2732" published="2008-09-04" seq="2008-2732" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in the SIP inspection functionality in Cisco PIX and Adaptive Security Appliance (ASA) 5500 devices 7.0 before 7.0(7)16, 7.1 before 7.1(2)71, 7.2 before 7.2(4)7, 8.0 before 8.0(3)20, and 8.1 before 8.1(1)8 allow remote attackers to cause a denial of service (device reload) via unknown vectors, aka Bug IDs CSCsq07867, CSCsq57091, CSCsk60581, and CSCsq39315.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="CISCO" url="http://www.cisco.com/en/US/products/products_security_advisory09186a00809f138a.shtml">20080903 Remote Access VPN and SIP Vulnerabilities in Cisco PIX and Cisco ASA</ref></refs><vuln_soft><prod name="PIX" vendor="Cisco"><vers num="7.2"/><vers num="8.0"/><vers num="8.1"/></prod><prod name="adaptive_security_appliance_5500" vendor="Cisco"><vers num="7.2"/><vers num="8.1"/><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2733" published="2008-09-04" seq="2008-2733" severity="High" type="CVE"><desc><descript source="cve">Cisco PIX and Adaptive Security Appliance (ASA) 5500 devices 7.2 before 7.2(4)2, 8.0 before 8.0(3)14, and 8.1 before 8.1(1)4, when configured as a client VPN endpoint, do not properly process IPSec client authentication, which allows remote attackers to cause a denial of service (device reload) via a crafted authentication attempt, aka Bug ID CSCso69942.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="CISCO" url="http://www.cisco.com/en/US/products/products_security_advisory09186a00809f138a.shtml">20080903 Remote Access VPN and SIP Vulnerabilities in Cisco PIX and Cisco ASA</ref></refs><vuln_soft><prod name="PIX" vendor="Cisco"><vers num="7.2"/><vers num="8.0"/><vers num="8.1"/></prod><prod name="adaptive_security_appliance_5500" vendor="Cisco"><vers num="7.2"/><vers num="8.1"/><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2734" published="2008-09-04" seq="2008-2734" severity="High" type="CVE"><desc><descript source="cve">Memory leak in the crypto functionality in Cisco Adaptive Security Appliance (ASA) 5500 devices 7.2 before 7.2(4)2, 8.0 before 8.0(3)14, and 8.1 before 8.1(1)4, when configured as a clientless SSL VPN endpoint, allows remote attackers to cause a denial of service (memory consumption and VPN hang) via a crafted SSL or HTTP packet, aka Bug ID CSCso66472.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="CISCO" url="http://www.cisco.com/en/US/products/products_security_advisory09186a00809f138a.shtml">20080903 Remote Access VPN and SIP Vulnerabilities in Cisco PIX and Cisco ASA</ref></refs><vuln_soft><prod name="adaptive_security_appliance_5500" vendor="Cisco"><vers num="8.0"/><vers num="8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2735" published="2008-09-04" seq="2008-2735" severity="High" type="CVE"><desc><descript source="cve">The HTTP server in Cisco Adaptive Security Appliance (ASA) 5500 devices 8.0 before 8.0(3)15 and 8.1 before 8.1(1)5, when configured as a clientless SSL VPN endpoint, does not properly process URIs, which allows remote attackers to cause a denial of service (device reload) via a URI in a crafted SSL or HTTP packet, aka Bug ID CSCsq19369.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="CISCO" url="http://www.cisco.com/en/US/products/products_security_advisory09186a00809f138a.shtml">20080903 Remote Access VPN and SIP Vulnerabilities in Cisco PIX and Cisco ASA</ref></refs><vuln_soft><prod name="adaptive_security_appliance_5500" vendor="Cisco"><vers num="8.0"/><vers num="8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2736" published="2008-09-04" seq="2008-2736" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Cisco Adaptive Security Appliance (ASA) 5500 devices 8.0(3)15, 8.0(3)16, 8.1(1)4, and 8.1(1)5, when configured as a clientless SSL VPN endpoint, allows remote attackers to obtain usernames and passwords via unknown vectors, aka Bug ID CSCsq45636.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref source="CISCO" url="http://www.cisco.com/en/US/products/products_security_advisory09186a00809f138a.shtml">20080903 Remote Access VPN and SIP Vulnerabilities in Cisco PIX and Cisco ASA</ref></refs><vuln_soft><prod name="adaptive_security_appliance_5500" vendor="Cisco"><vers num="8.0"/><vers num="8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2826" published="2008-07-02" seq="2008-2826" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in the sctp_getsockopt_local_addrs_old function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) functionality in the Linux kernel before 2.6.25.9 allows local users to cause a denial of service (resource consumption and system outage) via vectors involving a large addr_num field in an sctp_getaddrs_old data structure.</descript></desc><loss_types><avail/></loss_types><range><local/></range><refs><ref source="" url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=735ce972fbc8a65fb17788debd7bbe7b4383cc62"></ref><ref source="" url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.25.9"></ref><ref source="" url="http://lwn.net/Articles/287350/"></ref><ref source="" url="http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0207"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-2629"></ref><ref source="BID" url="http://www.securityfocus.com/bid/29990">29990</ref></refs><vuln_soft><prod name="linux" vendor="kernel"><vers num="2.6.24"/><vers num="2.6.25"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-2879" published="2008-06-26" seq="2008-2879" severity="Medium" type="CVE"><desc><descript source="cve">Benja CMS 0.1 does not require authentication for access to admin/, which allows remote attackers to add or delete a menu.</descript></desc><loss_types><avail/><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/493568/100/0/threaded">20080622 Benja CMS 0.1 (Upload/XSS) Multiple Remote Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/29884">29884</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30834">30834</ref></refs><vuln_soft><prod name="benja_cms" vendor="benjacms"><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-2880" published="2008-06-26" seq="2008-2880" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the IBM AFP Viewer Plug-in 2.0.7.1 and 3.2.1.1 allows remote attackers to execute arbitrary code via a long SRC property value.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/27995">27995</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/43338">ibm-afpviewer-plugin-bo(43338)</ref></refs><vuln_soft><prod name="afp_viewer_plug-in" vendor="IBM"><vers num="2.0.7.1"/><vers num="3.2.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-2881" published="2008-06-26" seq="2008-2881" severity="Medium" type="CVE"><desc><descript source="cve">Relative Real Estate Systems 3.0 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5924">5924</ref><ref source="" url="http://e-rdc.org/v1/news.php?readmore=101"></ref></refs><vuln_soft><prod name="relative_real_estate_systems" vendor="relative_real_estate_systems"><vers num="3.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-2882" published="2008-06-26" seq="2008-2882" severity="High" type="CVE"><desc><descript source="cve">upgrade.asp in sHibby sHop 2.2 and earlier does not require administrative authentication, which allows remote attackers to update a file or have unspecified other impact via a direct request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://milw0rm.com/exploits/5895">5895</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30787">30787</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/43296">shibbyshop-upgrade-urun-unauth-access(43296)</ref></refs><vuln_soft><prod name="shibby_shop" vendor="Aspindir"><vers num="2.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-2883" published="2008-06-26" seq="2008-2883" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in include/plugins/jrBrowser/payment.php in Jamroom 3.3.0 through 3.3.5 allows remote attackers to execute arbitrary PHP code via a URL in the jamroom[jm_dir] parameter.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5876">5876</ref><ref source="" url="http://www.jamroom.net/"></ref><ref source="" url="http://www.jamroom.net/index.php?m=td_tracker&amp;o=view&amp;id=1130"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30806">30806</ref></refs><vuln_soft><prod name="Jamroom" vendor="Jamroom"><vers num="3.3.0"/><vers num="3.3.1"/><vers num="3.3.2"/><vers num="3.3.3"/><vers num="3.3.4"/><vers num="3.3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-2891" published="2008-06-27" seq="2008-2891" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in eMuSOFT emuCMS 0.3 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a category action.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5878">5878</ref><ref source="BID" url="http://www.securityfocus.com/bid/29855">29855</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30804">30804</ref></refs><vuln_soft><prod name="emuCMS" vendor="eMuSOFT"><vers num="0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-2892" published="2008-06-27" seq="2008-2892" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the EXP Shop (com_expshop) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a show_payment action to index.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5893">5893</ref><ref source="BID" url="http://www.securityfocus.com/bid/29869">29869</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30791">30791</ref></refs><vuln_soft><prod name="exp_shop_component" vendor="feellove"><vers num="1.0"/></prod><prod name="com_expshop" vendor="Joomla"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-2893" published="2008-06-27" seq="2008-2893" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in news.php in AJ Square aj-hyip (aka AJ HYIP Acme) allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-2532.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5890">5890</ref><ref source="BID" url="http://www.securityfocus.com/bid/29863">29863</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30794">30794</ref></refs><vuln_soft><prod name="aj_square_aj-hyip" vendor="ajhyip"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2894" published="2008-06-27" seq="2008-2894" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the FTP client in NCH Software Classic FTP 1.02 for Windows allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a response to a LIST command, a related issue to CVE-2002-1345.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://vuln.sg/classicftp102-en.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/29846">29846</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1899/references">ADV-2008-1899</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30708">30708</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/43230">classicftp-list-directory-traversal(43230)</ref></refs><vuln_soft><prod name="nch_software_classic_ftp" vendor="NCH Software"><vers edition="unknown" num="1.02"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2895" published="2008-06-27" seq="2008-2895" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index.php in AproxEngine 5.1.0.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://milw0rm.com/exploits/5884">5884</ref><ref source="BID" url="http://www.securityfocus.com/bid/29860">29860</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30800">30800</ref></refs><vuln_soft><prod name="aproxengine" vendor="aprox"><vers num="5.1.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2896" published="2008-06-27" seq="2008-2896" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index.php in FireAnt 1.3 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5871">5871</ref><ref source="BID" url="http://www.securityfocus.com/bid/29843">29843</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/43229">fireant-index-file-include(43229)</ref></refs><vuln_soft><prod name="fireant" vendor="getfireant"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2897" published="2008-06-27" seq="2008-2897" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in PageSquid CMS 0.3 Beta allows remote attackers to execute arbitrary SQL commands via the page parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5899">5899</ref><ref source="BID" url="http://www.securityfocus.com/bid/29870">29870</ref></refs><vuln_soft><prod name="pagesquid_cms" vendor="pagesquid"><vers edition="beta" num="0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2898" published="2008-06-27" seq="2008-2898" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in includes/header.php in Hedgehog-CMS 1.21 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the c_temp_path parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5904">5904</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30778">30778</ref></refs><vuln_soft><prod name="hedgehog-cms" vendor="hedgehog-cms"><vers num="1.21"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2899" published="2008-06-27" seq="2008-2899" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in includes/classes/page.php in j00lean-CMS 1.03 has unknown impact and attack vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=608171"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30703">30703</ref></refs><vuln_soft><prod name="j00lean-cms" vendor="j00lean-cms"><vers num="1.03"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2900" published="2008-06-27" seq="2008-2900" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in item.php in PHPAuction 3.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5892">5892</ref><ref source="BID" url="http://www.securityfocus.com/bid/29864">29864</ref></refs><vuln_soft><prod name="PHPauction" vendor="PHPauction"><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2901" published="2008-06-30" seq="2008-2901" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 1.4 allow remote authenticated users to execute arbitrary SQL commands via the (1) address parameter to addressbook.php, the (2) getnews parameter to familynews.php, and the (3) poll_id parameter to home.php in a results action.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5811">5811</ref><ref source="BID" url="http://www.securityfocus.com/bid/29722">29722</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30680">30680</ref></refs><vuln_soft><prod name="family_connections_cms" vendor="Haudenschilt"><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2902" published="2008-06-30" seq="2008-2902" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in profile.php in AlstraSoft AskMe Pro 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.  NOTE: The que_id parameter to forum_answer.php is already covered by CVE-2007-4085.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5821">5821</ref><ref source="BID" url="http://www.securityfocus.com/bid/29732">29732</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30672">30672</ref></refs><vuln_soft><prod name="AskMe Pro" vendor="AlstraSoft"><vers num="2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2903" published="2008-06-30" seq="2008-2903" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in news.php in Advanced Webhost Billing System (AWBS) 2.3.3 through 2.7.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the viewnews parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5823">5823</ref><ref source="BID" url="http://www.securityfocus.com/bid/29721">29721</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30646">30646</ref></refs><vuln_soft><prod name="advanced_webhost_billing_system" vendor="awbs"><vers num="2.3.3"/><vers num="2.5"/><vers num="2.6.3"/><vers num="2.7"/><vers num="2.7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2904" published="2008-06-30" seq="2008-2904" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in shop.php in Conkurent PHPMyCart allows remote attackers to execute arbitrary SQL commands via the cat parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5812">5812</ref><ref source="BID" url="http://www.securityfocus.com/bid/29726">29726</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30679">30679</ref></refs><vuln_soft><prod name="phpmycart" vendor="phpmycart"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2905" published="2008-06-30" seq="2008-2905" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in includes/Cache/Lite/Output.php in the Cache_Lite package in Mambo 4.6.4 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5808">5808</ref><ref source="BID" url="http://www.securityfocus.com/bid/29716">29716</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30685">30685</ref></refs><vuln_soft><prod name="Mambo" vendor="Mambo"><vers num="4.0.14"/><vers num="4.5"/><vers num="4.5.0.2"/><vers num="4.5.1 Beta"/><vers num="4.5.1 Beta2"/><vers num="4.5.1.3"/><vers num="4.5.1_1.0.9"/><vers num="4.5.1a"/><vers num="4.5.2"/><vers num="4.5.2.1"/><vers num="4.5.2.2"/><vers num="4.5.2.3"/><vers num="4.5.3h"/><vers num="4.5.4"/><vers num="4.5_1.0.0"/><vers num="4.5_1.0.1"/><vers num="4.5_1.0.2"/><vers num="4.5_1.0.3 Beta"/><vers num="4.5_1.0.9"/><vers num="4.6"/><vers num="4.6.1"/><vers num="4.6.2"/><vers num="4.6.4"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2906" published="2008-06-30" seq="2008-2906" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in lista_anexos.php in WebChamado 1.1 allows remote attackers to execute arbitrary SQL commands via the tsk_id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5802">5802</ref><ref source="BID" url="http://www.securityfocus.com/bid/29711">29711</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30690">30690</ref></refs><vuln_soft><prod name="webchamado" vendor="webchamado"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2907" published="2008-06-30" seq="2008-2907" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in admin/index.php in WebChamado 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the eml parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5798">5798</ref><ref source="BID" url="http://www.securityfocus.com/bid/29701">29701</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30690">30690</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/43060">webchamado-index-sql-injection(43060)</ref></refs><vuln_soft><prod name="webchamado" vendor="webchamado"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2908" published="2008-06-30" seq="2008-2908" severity="High" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in a certain ActiveX control in ienipp.ocx in Novell iPrint Client for Windows before 4.36 allow remote attackers to execute arbitrary code via a long value of the (1) operation, (2) printer-url, or (3) target-frame parameter.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref source="" url="http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5028061.html"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/145313">VU#145313</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1837/references">ADV-2008-1837</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30709">30709</ref></refs><vuln_soft><prod name="iPrint Client" vendor="Novell"><vers edition="unknown, windows" num="4.35" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2909" published="2008-06-30" seq="2008-2909" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in results.php in Clever Copy 3.0 allows remote attackers to execute arbitrary SQL commands via the searchtype parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://milw0rm.com/exploits/5794">5794</ref><ref source="BID" url="http://www.securityfocus.com/bid/29694">29694</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30699">30699</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/43064">clevercopy-results-sql-injection(43064)</ref></refs><vuln_soft><prod name="Clever Copy" vendor="Clever Copy"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2910" published="2008-06-30" seq="2008-2910" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the DXTTextOutEffect ActiveX control (aka the Text-Effect DXT Filter), as distributed in TextOut.dll 6.0.18.1 and mvtextout.dll, in muvee autoProducer 6.0 and 6.1 allows remote attackers to execute arbitrary code via a long FontSetting property value.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5793">5793</ref><ref source="BID" url="http://www.securityfocus.com/bid/29693">29693</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30696">30696</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/43036">autoproducer-dxttextouteffect-activex-bo(43036)</ref></refs><vuln_soft><prod name="autoproducer" vendor="muvee"><vers num="6.0"/><vers num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2911" published="2008-06-30" seq="2008-2911" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.php in Contenido 4.8.4 allow remote attackers to inject arbitrary web script or HTML via the (1) contenido, (2) Belang, and (3) username parameters.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5810">5810</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/29719">29719</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30683">30683</ref></refs><vuln_soft><prod name="Contendio" vendor="Contenido"><vers num="4.8.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2912" published="2008-06-30" seq="2008-2912" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Contenido CMS 4.8.4 allow remote attackers to execute arbitrary PHP code via a URL in the (1) contenido_path parameter to (a) contenido/backend_search.php; the (2) cfg[path][contenido] parameter to (b) move_articles.php, (c) move_old_stats.php, (d) optimize_database.php, (e) run_newsletter_job.php, (f) send_reminder.php, (g) session_cleanup.php, and (h) setfrontenduserstate.php in contenido/cronjobs/, and (i) includes/include.newsletter_jobs_subnav.php and (j) plugins/content_allocation/includes/include.right_top.php in contenido/; the (3) cfg[path][templates] parameter to (k) includes/include.newsletter_jobs_subnav.php and (l) plugins/content_allocation/includes/include.right_top.php in contenido/; and the (4) cfg[templates][right_top_blank] parameter to (m) plugins/content_allocation/includes/include.right_top.php and (n) contenido/includes/include.newsletter_jobs_subnav.php in contenido/, different vectors than C!
 VE-2006-5380.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5810">5810</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/29719">29719</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30683">30683</ref></refs><vuln_soft><prod name="Contenido_cms" vendor="Contenido"><vers num="4.8.4"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2913" published="2008-06-30" seq="2008-2913" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in func.php in Devalcms 1.4a, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the currentpath parameter, in conjunction with certain ... (triple dot) and ..... sequences in the currentfile parameter, to index.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5822">5822</ref><ref source="BID" url="http://www.securityfocus.com/bid/29728">29728</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30585">30585</ref></refs><vuln_soft><prod name="devalcms" vendor="devalcms"><vers num="1.4a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2914" published="2008-06-30" seq="2008-2914" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in jobseekers/JobSearch3.php (aka the search module) in PHP JOBWEBSITE PRO allows remote attackers to execute arbitrary SQL commands via the (1) kw or (2) position parameter.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5807">5807</ref><ref source="BID" url="http://www.securityfocus.com/bid/29713">29713</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30686">30686</ref></refs><vuln_soft><prod name="php_jobwebsite_pro" vendor="preprojects"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2915" published="2008-06-30" seq="2008-2915" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in jobseekers/JobSearch.php (aka the search module) in Pre Job Board allow remote attackers to execute arbitrary SQL commands via the (1) position or (2) kw parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5809">5809</ref><ref source="" url="http://www.spanish-hackers.com/vuln/joss-42.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/29717">29717</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30684">30684</ref></refs><vuln_soft><prod name="pre_job_board" vendor="preprojects"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2916" published="2008-06-30" seq="2008-2916" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Pre ADS Portal 2.0 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) cid parameter to showcategory.php and the (2) id parameter to software-description.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/493371/100/0/threaded">20080615 [ECHO_ADV_98$2008] Pre Ads Portal &lt;= 2.0 Sql Injection Vulnerability</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5804">5804</ref><ref source="" url="http://e-rdc.org/v1/news.php?readmore=98"></ref><ref source="BID" url="http://www.securityfocus.com/bid/29709">29709</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30689">30689</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/43071">preadsportal-showcategory-sql-injection(43071)</ref></refs><vuln_soft><prod name="pre_ads_portal" vendor="preprojects"><vers num="2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2917" published="2008-06-30" seq="2008-2917" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in productsofcat.asp in E-SMART CART allows remote attackers to execute arbitrary SQL commands via the category_id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/493372/100/0/threaded">20080615 E-SMART CART (productsofcat.asp) Remote SQL Injection Vulnerability</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5805">5805</ref><ref source="" url="http://www.spanish-hackers.com/vuln/joss-40.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/29712">29712</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30687">30687</ref></refs><vuln_soft><prod name="e-smart_cart" vendor="preprojects"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2918" published="2008-06-30" seq="2008-2918" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in details.php in Application Dynamics Cartweaver 3.0 allows remote attackers to execute arbitrary SQL commands via the prodId parameter, possibly a related issue to CVE-2006-2046.3.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5815">5815</ref><ref source="BID" url="http://www.securityfocus.com/bid/29727">29727</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30677">30677</ref></refs><vuln_soft><prod name="cartweaver" vendor="Application Dynamics"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2919" published="2008-06-30" seq="2008-2919" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in listing.php in Gryphon gllcTS2 4.2.4 allows remote attackers to execute arbitrary SQL commands via the sort parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5806">5806</ref><ref source="BID" url="http://www.securityfocus.com/bid/29714">29714</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30688">30688</ref></refs><vuln_soft><prod name="gryphon_gllcts2" vendor="gryphonllc"><vers num="4.2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2920" published="2008-06-30" seq="2008-2920" severity="High" type="CVE"><desc><descript source="cve">admin/filemanager/ (aka the File Manager) in EZTechhelp EZCMS 1.2 and earlier does not require authentication, which allows remote attackers to create, modify, read, and delete files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5819">5819</ref><ref patch="1" source="" url="http://ezcms.eztechhelp.com/index.php?page=3&amp;nid=27"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/29738">29738</ref></refs><vuln_soft><prod name="eztechhelp_ezcms" vendor="ezcms"><vers num="1.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-02" name="CVE-2008-2928" published="2008-08-29" seq="2008-2928" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the adminutil library in CGI applications in Red Hat Directory Server 7.1 before SP7 allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted Accept-Language HTTP header.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="" url="http://www.redhat.com/docs/manuals/dir-server/release-notes/7.1SP7/index.html"></ref><ref source="" url="https://bugzilla.redhat.com/show_bug.cgi?id=453916"></ref><ref patch="1" source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2008-0596.html">RHSA-2008:0596</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/30869">30869</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1020771">1020771</ref></refs><vuln_soft><prod name="Directory Server" vendor="redhat"><vers edition="SP3" num="7.1"/><vers edition="SP1" num="7.1"/><vers edition="SP2" num="7.1"/><vers edition="SP4" num="7.1"/><vers edition="SP5" num="7.1"/><vers edition="sp6" num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-09-02" name="CVE-2008-2929" published="2008-08-29" seq="2008-2929" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the adminutil library in the Directory Server Administration Express and Directory Server Gateway (DSGW) web interface in Red Hat Directory Server 7.1 before SP7 and 8 EL4 and EL5, and Fedora Directory Server, allow remote attackers to inject arbitrary web script or HTML via input values that use % (percent) escaping.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="" url="http://www.redhat.com/docs/manuals/dir-server/release-notes/7.1SP7/index.html"></ref><ref source="" url="https://bugzilla.redhat.com/show_bug.cgi?id=454621"></ref><ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2008-0596.html">RHSA-2008:0596</ref><ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2008-0601.html">RHSA-2008:0601</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/30870">30870</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1020772">1020772</ref></refs><vuln_soft><prod name="directory_server" vendor="Fedora"><vers num=""/></prod><prod name="Directory Server" vendor="redhat"><vers edition="SP3" num="7.1"/><vers edition="SP1" num="7.1"/><vers edition="SP2" num="7.1"/><vers edition="SP4" num="7.1"/><vers edition="SP5" num="7.1"/><vers edition="sp6" num="7.1"/><vers edition="EL4" num="8.0"/><vers edition="EL5" num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-09-02" name="CVE-2008-2930" published="2008-08-29" seq="2008-2930" severity="High" type="CVE"><desc><descript source="cve">Red Hat Directory Server 7.1 before SP7, Red Hat Directory Server 8, and Fedora Directory Server 1.1.1 allow remote attackers to cause a denial of service (CPU consumption and search outage) via crafted LDAP search requests with patterns, related to a single-threaded regular-expression subsystem.</descript></desc><loss_types><avail/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="" url="http://www.redhat.com/docs/manuals/dir-server/release-notes/7.1SP7/index.html"></ref><ref source="" url="https://bugzilla.redhat.com/show_bug.cgi?id=454065"></ref><ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2008-0596.html">RHSA-2008:0596</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/30871">30871</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1020773">1020773</ref></refs><vuln_soft><prod name="directory_server" vendor="Fedora"><vers num="1.1.1"/></prod><prod name="Directory Server" vendor="redhat"><vers edition="SP3" num="7.1"/><vers edition="SP1" num="7.1"/><vers edition="SP2" num="7.1"/><vers edition="SP4" num="7.1"/><vers edition="SP5" num="7.1"/><vers edition="sp6" num="7.1"/><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2959" published="2008-07-02" seq="2008-2959" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in a certain ActiveX control (vb6skit.dll) in Microsoft Visual Basic Enterprise Edition 6.0 SP6 might allow remote attackers to execute arbitrary code via a long lpstrLinkPath argument to the fCreateShellLink function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5851">5851</ref><ref source="BID" url="http://www.securityfocus.com/bid/29792">29792</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/43180">visualbasic-vb6skit-bo(43180)</ref></refs><vuln_soft><prod name="Visual Basic Enterprise Edition" vendor="Microsoft"><vers edition="sp6" num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2960" published="2008-07-02" seq="2008-2960" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.11.7, when register_globals is enabled and .htaccess support is disabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving scripts in libraries/.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2008-4"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1904/references">ADV-2008-1904</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30813">30813</ref></refs><vuln_soft><prod name="phpMyAdmin" vendor="phpMyAdmin"><vers num="2.10.0"/><vers num="2.10.0.1"/><vers num="2.10.0.2"/><vers num="2.10.1"/><vers num="2.10.2"/><vers num="2.10.3"/><vers num="2.10.3rc1"/><vers num="2.11.0"/><vers num="2.11.0beta1"/><vers num="2.11.0rc1"/><vers num="2.11.1"/><vers num="2.11.1.1"/><vers num="2.11.1.2"/><vers num="2.11.1rc1"/><vers num="2.11.2"/><vers num="2.11.2.1"/><vers num="2.11.2.2"/><vers num="2.11.3"/><vers num="2.11.3rc1"/><vers num="2.11.4"/><vers num="2.11.4rc1"/><vers num="2.11.5"/><vers num="2.11.5.1"/><vers num="2.11.5.2"/><vers num="2.11.5rc1"/><vers num="2.11.6"/><vers num="2.11.6rc1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2961" published="2008-07-02" seq="2008-2961" severity="Medium" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in view/index.php in CMS Mini 0.2.2 allow remote attackers to read arbitrary local files via a .. (dot dot) in the (1) path and (2) p parameter.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5896">5896</ref><ref source="BID" url="http://www.securityfocus.com/bid/29890">29890</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/43276">cmsmini-index-file-include(43276)</ref></refs><vuln_soft><prod name="cms_mini" vendor="cmsmini"><vers num="0.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2962" published="2008-07-02" seq="2008-2962" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in MyBlog allow remote attackers to inject arbitrary web script or HTML via the (1) s and (2) sort parameters to index.php, and the (3) id parameter to post.php.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5913">5913</ref><ref source="BID" url="http://www.securityfocus.com/bid/29900">29900</ref></refs><vuln_soft><prod name="MyBlog" vendor="MyBlog"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2963" published="2008-07-02" seq="2008-2963" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in MyBlog allow remote attackers to execute arbitrary SQL commands via the (1) view parameter to (a) index.php, and the (2) id parameter to (b) member.php and (c) post.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5913">5913</ref><ref source="BID" url="http://www.securityfocus.com/bid/29900">29900</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/43292">myblog-view-id-sql-injection(43292)</ref></refs><vuln_soft><prod name="MyBlog" vendor="MyBlog"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2964" published="2008-07-02" seq="2008-2964" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in guide.php in ResearchGuide 0.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5911">5911</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/43261">researchguide-guide-sql-injection(43261)</ref></refs><vuln_soft><prod name="researchguide" vendor="researchguide"><vers num="0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2965" published="2008-07-02" seq="2008-2965" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in viewforum.php in JaxUltraBB (JUBB) 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the forum parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/29853">29853</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/43279">jaxultrabb-viewforum-xss(43279)</ref></refs><vuln_soft><prod name="jaxultrabb" vendor="jaxbot"><vers num="2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2978" published="2008-07-02" seq="2008-2978" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in phpi/rss.php in Ourvideo CMS 9.5, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the prefix parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5920">5920</ref><ref source="BID" url="http://www.securityfocus.com/bid/29909">29909</ref></refs><vuln_soft><prod name="ourvideo_cms" vendor="ourvideocms"><vers num="9.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2984" published="2008-07-02" seq="2008-2984" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in backend/umleitung.php in CMReams CMS 1.3.1.1 Beta 2 allows remote attackers to inject arbitrary web script or HTML via the lang[be_red_text] parameter.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5905">5905</ref><ref source="BID" url="http://www.securityfocus.com/bid/29891">29891</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/43266">cmreamscms-umleitung-xss(43266)</ref></refs><vuln_soft><prod name="cmreams_cms" vendor="cmreams"><vers edition="beta_2" num="1.3.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2985" published="2008-07-02" seq="2008-2985" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in load_language.php in CMReams CMS 1.3.1.1 Beta 2, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the page_language parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5905">5905</ref><ref source="BID" url="http://www.securityfocus.com/bid/29891">29891</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/43265">cmreamscms-loadlanguage-file-include(43265)</ref></refs><vuln_soft><prod name="cmreams_cms" vendor="cmreams"><vers edition="beta_2" num="1.3.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2986" published="2008-07-02" seq="2008-2986" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in phpDMCA 1.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the ourlinux_root_path parameter to (1) adodb-errorpear.inc.php and (2) adodb-pear.inc.php in adodb/.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5897">5897</ref><ref source="BID" url="http://www.securityfocus.com/bid/29880">29880</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/43253">phpdmca-ourlinuxrootpath-file-include(43253)</ref></refs><vuln_soft><prod name="phpdmca" vendor="phpdmca"><vers num="1.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2988" published="2008-07-02" seq="2008-2988" severity="High" type="CVE"><desc><descript source="cve">Unrestricted file upload vulnerability in admin/upload.php in Benja CMS 0.1 allows remote attackers to upload and execute arbitrary PHP files via unspecified vectors, followed by a direct request to the file in billeder/.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/493568/100/0/threaded">20080622 Benja CMS 0.1 (Upload/XSS) Multiple Remote Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/29884">29884</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30834">30834</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/43282">benja-upload-file-upload(43282)</ref></refs><vuln_soft><prod name="benja_cms" vendor="benjacms"><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2991" published="2008-07-09" seq="2008-2991" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Adobe RoboHelp Server 6 and 7 allows remote attackers to inject arbitrary web script or HTML via vectors related to the Help Errors log.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://www.adobe.com/support/security/bulletins/apsb08-16.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/30137">30137</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1020442">1020442</ref></refs><vuln_soft><prod name="robohelp_server" vendor="Adobe"><vers num="6"/><vers num="7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2993" published="2008-07-03" seq="2008-2993" severity="High" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in index.php in FOG Forum 0.8.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) fog_lang and (2) fog_skin parameters, probably related to libs/required/share.inc; and possibly the (3) fog_pseudo, (4) fog_posted, (5) fog_password, and (6) fog_cook parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5784">5784</ref><ref source="BID" url="http://www.securityfocus.com/bid/29651">29651</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30613">30613</ref></refs><vuln_soft><prod name="fog_forum" vendor="fog"><vers num="0.8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2994" published="2008-07-03" seq="2008-2994" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PHPEasyData 1.5.4 allow remote attackers to inject arbitrary web script or HTML via the (1) annuaire parameter to (a) last_records.php and (b) annuaire.php and the (2) by and (3) cat_id parameters to annuaire.php.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/493273/100/0/threaded">20080610 PHPEasyData 1.5.4 Multiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/29659">29659</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/42997">phpeasydata-lastrecords-annuaire-xss(42997)</ref></refs><vuln_soft><prod name="phpeasydata" vendor="phpeasydata"><vers num="1.5.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-2995" published="2008-07-03" seq="2008-2995" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in PHPEasyData 1.5.4 allow remote attackers to execute arbitrary SQL commands via (1) the annuaire parameter to annuaire.php or (2) the username field in admin/login.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/493273/100/0/threaded">20080610 PHPEasyData 1.5.4 Multiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/29659">29659</ref></refs><vuln_soft><prod name="phpeasydata" vendor="phpeasydata"><vers num="1.5.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-3022" published="2008-07-07" seq="2008-3022" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in sablonlar/gunaysoft/gunaysoft.php in PHPortal 1.2 Beta allow remote attackers to execute arbitrary PHP code via a URL in (1) icerikyolu, (2) sayfaid, and (3) uzanti parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5996">5996</ref><ref source="BID" url="http://www.securityfocus.com/bid/30064">30064</ref></refs><vuln_soft><prod name="phportal" vendor="phpbbportal"><vers edition="beta" num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-3023" published="2008-07-07" seq="2008-3023" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in FreeStyle Wiki 3.6.2 and earlier, and 3.6.3 dev3 and earlier development versions, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2005-1799.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://jvn.jp/jp/JVN77432756/index.html"></ref><ref source="" url="http://fswiki.org/wiki.pl?page=%CD%FA%CE%F2%2F2008%2D7%2D3"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30923">30923</ref></refs><vuln_soft><prod name="ie" vendor="Microsoft"><vers num=""/></prod><prod name="freestyle_wiki" vendor="fswiki"><vers num="3.6.2" prev="1"/><vers edition="dev3" num="3.6.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="10.0" CVSS_score="6.9" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-3024" published="2008-07-07" seq="2008-3024" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in phgrafx in QNX Momentics (aka RTOS) 6.3.2 and earlier allows local users to gain privileges via a long .pal filename in palette/.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/493816/100/0/threaded">20080701 [SCANIT-2008-001] QNX phgrafx Privilege Escalation Vulnerability</ref><ref source="" url="http://www.scanit.net/rd/advisories/adv01"></ref><ref source="BID" url="http://www.securityfocus.com/bid/30024">30024</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1020411">1020411</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30808">30808</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/43542">momentics-phgrafx-bo(43542)</ref></refs><vuln_soft><prod name="momentics" vendor="QNX"><vers num="6.3.2" prev="1"/></prod><prod name="RTOS" vendor="QNX"><vers num="6.3.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-3077" published="2008-07-08" seq="2008-3077" severity="Medium" type="CVE"><desc><descript source="cve">arch/x86/kernel/ptrace.c in the Linux kernel before 2.6.25.10 on the x86_64 platform leaks task_struct references into the sys32_ptrace function, which allows local users to cause a denial of service (system crash) or have unspecified other impact via unknown vectors, possibly a use-after-free vulnerability.</descript></desc><loss_types><avail/></loss_types><range><local/></range><refs><ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2008/07/03/2">[oss-security] 20080703 2.6.25.10 security fixes, please assign CVE id</ref><ref source="" url="http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.25.y.git;a=commitdiff;h=1e9a615bfce7996ea4d815d45d364b47ac6a74e8"></ref><ref source="" url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.25.10"></ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="1.2"/><vers num="1.3"/><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.10"/><vers num="2.0.11"/><vers num="2.0.12"/><vers num="2.0.13"/><vers num="2.0.14"/><vers num="2.0.15"/><vers num="2.0.16"/><vers num="2.0.17"/><vers num="2.0.18"/><vers num="2.0.19"/><vers num="2.0.2"/><vers num="2.0.20"/><vers num="2.0.21"/><vers num="2.0.22"/><vers num="2.0.23"/><vers num="2.0.24"/><vers num="2.0.25"/><vers num="2.0.26"/><vers num="2.0.27"/><vers num="2.0.28"/><vers num="2.0.29"/><vers num="2.0.3"/><vers num="2.0.30"/><vers num="2.0.31"/><vers num="2.0.32"/><vers num="2.0.33"/><vers num="2.0.34"/><vers num="2.0.35"/><vers num="2.0.36"/><vers num="2.0.37"/><vers num="2.0.38"/><vers num="2.0.39"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.0.6"/><vers num="2.0.7"/><vers num="2.0.8"/><vers num="2.0.9"/><vers num="2.0.9.9"/><vers num="2.1"/><vers num="2.1.132"/><vers num="2.1.89"/><vers num="2.2"/><vers num="2.2.1"/><vers num="2.2.10"/><vers num="2.2.11"/><vers num="2.2.12"/><vers num="2.2.13"/><vers num="2.2.13 pre15"/><vers num="2.2.14"/><vers num="2.2.15"/><vers num="2.2.15 pre16"/><vers num="2.2.15 pre20"/><vers num="2.2.16"/><vers num="2.2.16 pre5"/><vers num="2.2.16 pre6"/><vers num="2.2.17"/><vers num="2.2.17.14"/><vers num="2.2.18"/><vers num="2.2.19"/><vers num="2.2.2"/><vers num="2.2.20"/><vers num="2.2.21"/><vers num="2.2.21 pre1"/><vers num="2.2.21 pre2"/><vers num="2.2.21 pre3"/><vers num="2.2.21 pre4"/><vers num="2.2.21 rc1"/><vers num="2.2.21 rc2"/><vers num="2.2.21 rc3"/><vers num="2.2.21 rc4"/><vers num="2.2.22"/><vers num="2.2.22 rc1"/><vers num="2.2.22 rc2"/><vers num="2.2.22 rc3"/><vers num="2.2.23"/><vers num="2.2.23 rc1"/><vers num="2.2.23 rc2"/><vers num="2.2.24"/><vers num="2.2.24 rc2"/><vers num="2.2.24 rc3"/><vers num="2.2.24 rc4"/><vers num="2.2.24 rc5"/><vers num="2.2.25"/><vers num="2.2.26"/><vers num="2.2.27 pre1"/><vers num="2.2.27 pre2"/><vers num="2.2.27 rc1"/><vers num="2.2.27 rc2"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.2.4 rc1"/><vers num="2.2.5"/><vers num="2.2.6"/><vers num="2.2.7"/><vers num="2.2.8"/><vers num="2.2.9"/><vers num="2.3"/><vers num="2.3.1"/><vers num="2.3.10"/><vers num="2.3.11"/><vers num="2.3.12"/><vers num="2.3.13"/><vers num="2.3.14"/><vers num="2.3.15"/><vers num="2.3.16"/><vers num="2.3.17"/><vers num="2.3.18"/><vers num="2.3.19"/><vers num="2.3.2"/><vers num="2.3.20"/><vers num="2.3.21"/><vers num="2.3.22"/><vers num="2.3.23"/><vers num="2.3.24"/><vers num="2.3.25"/><vers num="2.3.26"/><vers num="2.3.27"/><vers num="2.3.28"/><vers num="2.3.29"/><vers num="2.3.3"/><vers num="2.3.30"/><vers num="2.3.31"/><vers num="2.3.32"/><vers num="2.3.33"/><vers num="2.3.34"/><vers num="2.3.35"/><vers num="2.3.36"/><vers num="2.3.37"/><vers num="2.3.38"/><vers num="2.3.39"/><vers num="2.3.4"/><vers num="2.3.40"/><vers num="2.3.41"/><vers num="2.3.42"/><vers num="2.3.43"/><vers num="2.3.44"/><vers num="2.3.45"/><vers num="2.3.46"/><vers num="2.3.47"/><vers num="2.3.48"/><vers num="2.3.49"/><vers num="2.3.5"/><vers num="2.3.50"/><vers num="2.3.51"/><vers num="2.3.6"/><vers num="2.3.7"/><vers num="2.3.8"/><vers num="2.3.9"/><vers num="2.3.99"/><vers num="2.3.99 pre1"/><vers num="2.3.99 pre2"/><vers num="2.3.99 pre3"/><vers num="2.3.99 pre4"/><vers num="2.3.99 pre5"/><vers num="2.3.99 pre6"/><vers num="2.3.99 pre7"/><vers num="2.3.99 pre8"/><vers num="2.3.99 pre9"/><vers num="2.4.0"/><vers num="2.4.0 test1"/><vers num="2.4.0 test10"/><vers num="2.4.0 test11"/><vers num="2.4.0 test12"/><vers num="2.4.0 test2"/><vers num="2.4.0 test3"/><vers num="2.4.0 test4"/><vers num="2.4.0 test5"/><vers num="2.4.0 test6"/><vers num="2.4.0 test7"/><vers num="2.4.0 test8"/><vers num="2.4.0 test9"/><vers num="2.4.1"/><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.11 pre3"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18"/><vers num="2.4.18 pre1"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre4"/><vers num="2.4.18 pre5"/><vers num="2.4.18 pre6"/><vers num="2.4.18 pre7"/><vers num="2.4.18 pre8"/><vers num="2.4.18 pre9"/><vers num="2.4.19"/><vers num="2.4.19 pre1"/><vers num="2.4.19 pre2"/><vers num="2.4.19 pre3"/><vers num="2.4.19 pre4"/><vers num="2.4.19 pre5"/><vers num="2.4.19 pre6"/><vers num="2.4.2"/><vers num="2.4.20"/><vers num="2.4.21"/><vers num="2.4.21 pre1"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre7"/><vers num="2.4.22"/><vers num="2.4.22 pre10"/><vers num="2.4.23"/><vers num="2.4.23 ow2"/><vers num="2.4.23 pre9"/><vers num="2.4.24"/><vers num="2.4.24 ow1"/><vers num="2.4.25"/><vers num="2.4.26"/><vers num="2.4.27"/><vers num="2.4.27 pre1"/><vers num="2.4.27 pre2"/><vers num="2.4.27 pre3"/><vers num="2.4.27 pre4"/><vers num="2.4.27 pre5"/><vers num="2.4.28"/><vers num="2.4.29"/><vers num="2.4.29 rc1"/><vers num="2.4.29 rc2"/><vers num="2.4.3"/><vers num="2.4.3 pre3"/><vers num="2.4.30"/><vers num="2.4.30 rc2"/><vers num="2.4.30 rc3"/><vers num="2.4.31"/><vers num="2.4.31 pre1"/><vers num="2.4.32"/><vers num="2.4.32 pre1"/><vers num="2.4.32 pre2"/><vers num="2.4.33"/><vers num="2.4.33 pre1"/><vers num="2.4.33.2"/><vers num="2.4.33.3"/><vers num="2.4.33.4"/><vers num="2.4.33.5"/><vers num="2.4.34"/><vers num="2.4.34 rc3"/><vers num="2.4.34.1"/><vers num="2.4.34.2"/><vers num="2.4.35"/><vers num="2.4.35.2"/><vers num="2.4.36"/><vers num="2.4.36.1"/><vers num="2.4.36.2"/><vers num="2.4.36.3"/><vers num="2.4.36.4"/><vers num="2.4.36.5"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.4.9 pre5"/><vers num="2.5.0"/><vers num="2.5.1"/><vers num="2.5.10"/><vers num="2.5.11"/><vers num="2.5.12"/><vers num="2.5.13"/><vers num="2.5.14"/><vers num="2.5.15"/><vers num="2.5.16"/><vers num="2.5.17"/><vers num="2.5.18"/><vers num="2.5.19"/><vers num="2.5.2"/><vers num="2.5.20"/><vers num="2.5.21"/><vers num="2.5.22"/><vers num="2.5.23"/><vers num="2.5.24"/><vers num="2.5.25"/><vers num="2.5.26"/><vers num="2.5.27"/><vers num="2.5.28"/><vers num="2.5.29"/><vers num="2.5.3"/><vers num="2.5.30"/><vers num="2.5.31"/><vers num="2.5.32"/><vers num="2.5.33"/><vers num="2.5.34"/><vers num="2.5.35"/><vers num="2.5.36"/><vers num="2.5.37"/><vers num="2.5.38"/><vers num="2.5.39"/><vers num="2.5.4"/><vers num="2.5.40"/><vers num="2.5.41"/><vers num="2.5.42"/><vers num="2.5.43"/><vers num="2.5.44"/><vers num="2.5.45"/><vers num="2.5.46"/><vers num="2.5.47"/><vers num="2.5.48"/><vers num="2.5.49"/><vers num="2.5.5"/><vers num="2.5.50"/><vers num="2.5.51"/><vers num="2.5.52"/><vers num="2.5.53"/><vers num="2.5.54"/><vers num="2.5.55"/><vers num="2.5.56"/><vers num="2.5.57"/><vers num="2.5.58"/><vers num="2.5.59"/><vers num="2.5.6"/><vers num="2.5.60"/><vers num="2.5.61"/><vers num="2.5.62"/><vers num="2.5.63"/><vers num="2.5.64"/><vers num="2.5.65"/><vers num="2.5.66"/><vers num="2.5.67"/><vers num="2.5.68"/><vers num="2.5.69"/><vers num="2.5.7"/><vers num="2.5.8"/><vers num="2.5.9"/><vers num="2.6"/><vers num="2.6 test1"/><vers num="2.6 test10"/><vers num="2.6 test11"/><vers num="2.6 test2"/><vers num="2.6 test3"/><vers num="2.6 test4"/><vers num="2.6 test5"/><vers num="2.6 test6"/><vers num="2.6 test7"/><vers num="2.6 test8"/><vers num="2.6 test9"/><vers num="2.6 test9 CVS"/><vers num="2.6.0"/><vers num="2.6.1"/><vers num="2.6.1 rc1"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc3"/><vers num="2.6.10"/><vers num="2.6.10 rc1"/><vers num="2.6.10 rc2"/><vers num="2.6.10 rc3"/><vers num="2.6.11"/><vers num="2.6.11 rc1"/><vers num="2.6.11 rc1 bk6"/><vers num="2.6.11 rc2"/><vers num="2.6.11 rc3"/><vers num="2.6.11 rc4"/><vers num="2.6.11 rc5"/><vers num="2.6.11.1"/><vers num="2.6.11.10"/><vers num="2.6.11.11"/><vers num="2.6.11.12"/><vers num="2.6.11.2"/><vers num="2.6.11.3"/><vers num="2.6.11.4"/><vers num="2.6.11.5"/><vers num="2.6.11.6"/><vers num="2.6.11.7"/><vers num="2.6.11.8"/><vers num="2.6.11.9"/><vers num="2.6.12"/><vers num="2.6.12 rc1"/><vers num="2.6.12 rc2"/><vers num="2.6.12 rc3"/><vers num="2.6.12 rc4"/><vers num="2.6.12 rc5"/><vers num="2.6.12 rc6"/><vers num="2.6.12.1"/><vers num="2.6.12.12"/><vers num="2.6.12.2"/><vers num="2.6.12.22"/><vers num="2.6.12.3"/><vers num="2.6.12.4"/><vers num="2.6.12.5"/><vers num="2.6.12.6"/><vers num="2.6.13"/><vers num="2.6.13 rc1"/><vers num="2.6.13 rc2"/><vers num="2.6.13 rc3"/><vers num="2.6.13 rc4"/><vers num="2.6.13 rc5"/><vers num="2.6.13 rc6"/><vers num="2.6.13 rc7"/><vers num="2.6.13.1"/><vers num="2.6.13.2"/><vers num="2.6.13.3"/><vers num="2.6.13.4"/><vers num="2.6.13.5"/><vers num="2.6.14"/><vers num="2.6.14 rc1"/><vers num="2.6.14 rc2"/><vers num="2.6.14 rc3"/><vers num="2.6.14 rc4"/><vers num="2.6.14 rc5"/><vers num="2.6.14.1"/><vers num="2.6.14.2"/><vers num="2.6.14.3"/><vers num="2.6.14.4"/><vers num="2.6.14.5"/><vers num="2.6.14.6"/><vers num="2.6.14.7"/><vers num="2.6.15"/><vers num="2.6.15 rc1"/><vers num="2.6.15 rc2"/><vers num="2.6.15 rc3"/><vers num="2.6.15 rc4"/><vers num="2.6.15 rc5"/><vers num="2.6.15 rc6"/><vers num="2.6.15 rc7"/><vers num="2.6.15.1"/><vers num="2.6.15.11"/><vers num="2.6.15.2"/><vers num="2.6.15.3"/><vers num="2.6.15.4"/><vers num="2.6.15.5"/><vers num="2.6.15.6"/><vers num="2.6.15.7"/><vers num="2.6.16"/><vers num="2.6.16 rc1"/><vers num="2.6.16 rc2"/><vers num="2.6.16 rc3"/><vers num="2.6.16 rc4"/><vers num="2.6.16 rc5"/><vers num="2.6.16 rc6"/><vers num="2.6.16 rc7"/><vers num="2.6.16.1"/><vers num="2.6.16.10"/><vers num="2.6.16.11"/><vers num="2.6.16.12"/><vers num="2.6.16.13"/><vers num="2.6.16.14"/><vers num="2.6.16.15"/><vers num="2.6.16.16"/><vers num="2.6.16.17"/><vers num="2.6.16.18"/><vers num="2.6.16.19"/><vers num="2.6.16.2"/><vers num="2.6.16.20"/><vers num="2.6.16.21"/><vers num="2.6.16.22"/><vers num="2.6.16.23"/><vers num="2.6.16.24"/><vers num="2.6.16.25"/><vers num="2.6.16.26"/><vers num="2.6.16.27"/><vers num="2.6.16.28"/><vers num="2.6.16.29"/><vers num="2.6.16.3"/><vers num="2.6.16.30"/><vers num="2.6.16.31"/><vers num="2.6.16.32"/><vers num="2.6.16.33"/><vers num="2.6.16.34"/><vers num="2.6.16.35"/><vers num="2.6.16.36"/><vers num="2.6.16.37"/><vers num="2.6.16.38"/><vers num="2.6.16.39"/><vers num="2.6.16.4"/><vers num="2.6.16.40"/><vers num="2.6.16.41"/><vers num="2.6.16.43"/><vers num="2.6.16.44"/><vers num="2.6.16.45"/><vers num="2.6.16.46"/><vers num="2.6.16.47"/><vers num="2.6.16.48"/><vers num="2.6.16.49"/><vers num="2.6.16.5"/><vers num="2.6.16.50"/><vers num="2.6.16.51"/><vers num="2.6.16.52"/><vers num="2.6.16.53"/><vers num="2.6.16.6"/><vers num="2.6.16.7"/><vers num="2.6.16.8"/><vers num="2.6.16.9"/><vers num="2.6.17"/><vers num="2.6.17 rc1"/><vers num="2.6.17 rc2"/><vers num="2.6.17 rc3"/><vers num="2.6.17 rc4"/><vers num="2.6.17 rc5"/><vers num="2.6.17 rc6"/><vers num="2.6.17.1"/><vers num="2.6.17.10"/><vers num="2.6.17.11"/><vers num="2.6.17.12"/><vers num="2.6.17.13"/><vers num="2.6.17.14"/><vers num="2.6.17.2"/><vers num="2.6.17.3"/><vers num="2.6.17.4"/><vers num="2.6.17.5"/><vers num="2.6.17.6"/><vers num="2.6.17.7"/><vers num="2.6.17.8"/><vers num="2.6.17.9"/><vers num="2.6.18"/><vers num="2.6.18 rc1"/><vers num="2.6.18 rc2"/><vers num="2.6.18 rc3"/><vers num="2.6.18 rc4"/><vers num="2.6.18 rc5"/><vers num="2.6.18 rc6"/><vers num="2.6.18 rc7"/><vers num="2.6.18 stable"/><vers num="2.6.18.1"/><vers num="2.6.18.10"/><vers num="2.6.18.11"/><vers num="2.6.18.12"/><vers num="2.6.18.13"/><vers num="2.6.18.14"/><vers num="2.6.18.15"/><vers num="2.6.18.16"/><vers num="2.6.18.17"/><vers num="2.6.18.18"/><vers num="2.6.18.19"/><vers num="2.6.18.2"/><vers num="2.6.18.20"/><vers num="2.6.18.21"/><vers num="2.6.18.22"/><vers num="2.6.18.23"/><vers num="2.6.18.24"/><vers num="2.6.18.25"/><vers num="2.6.18.26"/><vers num="2.6.18.27"/><vers num="2.6.18.28"/><vers num="2.6.18.29"/><vers num="2.6.18.3"/><vers num="2.6.18.30"/><vers num="2.6.18.31"/><vers num="2.6.18.32"/><vers num="2.6.18.33"/><vers num="2.6.18.34"/><vers num="2.6.18.35"/><vers num="2.6.18.36"/><vers num="2.6.18.37"/><vers num="2.6.18.38"/><vers num="2.6.18.39"/><vers num="2.6.18.4"/><vers num="2.6.18.40"/><vers num="2.6.18.41"/><vers num="2.6.18.42"/><vers num="2.6.18.43"/><vers num="2.6.18.44"/><vers num="2.6.18.45"/><vers num="2.6.18.46"/><vers num="2.6.18.47"/><vers num="2.6.18.48"/><vers num="2.6.18.49"/><vers num="2.6.18.5"/><vers num="2.6.18.50"/><vers num="2.6.18.51"/><vers num="2.6.18.52"/><vers num="2.6.18.53"/><vers num="2.6.18.6"/><vers num="2.6.18.7"/><vers num="2.6.18.8"/><vers num="2.6.18.9"/><vers num="2.6.18_8.1.8.el5"/><vers num="2.6.19"/><vers num="2.6.19 rc1"/><vers num="2.6.19 rc2"/><vers num="2.6.19 rc3"/><vers num="2.6.19 rc4"/><vers num="2.6.19.1"/><vers num="2.6.19.2"/><vers num="2.6.19.3"/><vers num="2.6.19.4"/><vers num="2.6.19.5"/><vers num="2.6.19.6"/><vers num="2.6.19.7"/><vers num="2.6.2"/><vers num="2.6.2 rc1"/><vers num="2.6.2 rc2"/><vers num="2.6.2 rc3"/><vers num="2.6.20"/><vers num="2.6.20.1"/><vers num="2.6.20.10"/><vers num="2.6.20.11"/><vers num="2.6.20.12"/><vers num="2.6.20.13"/><vers num="2.6.20.14"/><vers num="2.6.20.15"/><vers num="2.6.20.16"/><vers num="2.6.20.17"/><vers num="2.6.20.18"/><vers num="2.6.20.19"/><vers num="2.6.20.2"/><vers num="2.6.20.20"/><vers num="2.6.20.21"/><vers num="2.6.20.3"/><vers num="2.6.20.4"/><vers num="2.6.20.5"/><vers num="2.6.20.6"/><vers num="2.6.20.7"/><vers num="2.6.20.8"/><vers num="2.6.20.9"/><vers num="2.6.20_rc2"/><vers num="2.6.21"/><vers num="2.6.21 git1"/><vers num="2.6.21 git2"/><vers num="2.6.21 git3"/><vers num="2.6.21 git4"/><vers num="2.6.21 git5"/><vers num="2.6.21 git6"/><vers num="2.6.21 git7"/><vers num="2.6.21.1"/><vers num="2.6.21.2"/><vers num="2.6.21.3"/><vers num="2.6.21.4"/><vers num="2.6.21.5"/><vers num="2.6.21.6"/><vers num="2.6.21.7"/><vers num="2.6.21_rc3"/><vers num="2.6.21_rc4"/><vers num="2.6.21_rc5"/><vers num="2.6.21_rc6"/><vers num="2.6.21_rc7"/><vers num="2.6.22"/><vers num="2.6.22 rc6"/><vers num="2.6.22.1"/><vers num="2.6.22.10"/><vers num="2.6.22.11"/><vers num="2.6.22.12"/><vers num="2.6.22.13"/><vers num="2.6.22.14"/><vers num="2.6.22.15"/><vers num="2.6.22.16"/><vers num="2.6.22.17"/><vers num="2.6.22.18"/><vers num="2.6.22.19"/><vers num="2.6.22.2"/><vers num="2.6.22.20"/><vers num="2.6.22.21"/><vers num="2.6.22.22"/><vers num="2.6.22.3"/><vers num="2.6.22.4"/><vers num="2.6.22.5"/><vers num="2.6.22.6"/><vers num="2.6.22.7"/><vers num="2.6.22.8"/><vers num="2.6.22.9"/><vers num="2.6.22_rc1"/><vers num="2.6.22_rc7"/><vers num="2.6.23"/><vers num="2.6.23 .2"/><vers num="2.6.23 rc1"/><vers num="2.6.23.09"/><vers num="2.6.23.1"/><vers num="2.6.23.10"/><vers num="2.6.23.11"/><vers num="2.6.23.12"/><vers num="2.6.23.13"/><vers num="2.6.23.14"/><vers num="2.6.23.15"/><vers num="2.6.23.16"/><vers num="2.6.23.17"/><vers num="2.6.23.2"/><vers num="2.6.23.3"/><vers num="2.6.23.4"/><vers num="2.6.23.5"/><vers num="2.6.23.6"/><vers num="2.6.23.7"/><vers num="2.6.23.8"/><vers num="2.6.23.9"/><vers num="2.6.23_rc1"/><vers num="2.6.23_rc2"/><vers num="2.6.23rc1"/><vers num="2.6.23rc2"/><vers num="2.6.24"/><vers num="2.6.24 rc2"/><vers num="2.6.24.1"/><vers num="2.6.24.2"/><vers num="2.6.24.3"/><vers num="2.6.24.4"/><vers num="2.6.24.5"/><vers num="2.6.24.6"/><vers num="2.6.24.7"/><vers num="2.6.24_rc1"/><vers num="2.6.24_rc2"/><vers num="2.6.24_rc3"/><vers num="2.6.24_rc4"/><vers num="2.6.24_rc5"/><vers num="2.6.25"/><vers num="2.6.25.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-3079" published="2008-07-08" seq="2008-3079" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Opera before 9.51 on Windows allows attackers to execute arbitrary code via unknown vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref source="" url="http://www.opera.com/docs/changelogs/windows/951/"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30937">30937</ref></refs><vuln_soft><prod name="opera" vendor="opera"><vers num="9.51" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-3080" published="2008-07-08" seq="2008-3080" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site request forgery (CSRF) vulnerability in admin.php in myWebland myBloggie 2.1.6 allows remote attackers to perform edit actions as administrators.  NOTE: this can be leveraged to execute SQL commands by also exploiting CVE-2007-1899.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5975">5975</ref><ref source="" url="http://www.netvigilance.com/advisory0040"></ref></refs><vuln_soft><prod name="myBloggie" vendor="myWebland"><vers num="2.1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-3083" published="2008-07-08" seq="2008-3083" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Brightcode Weblinks (com_brightweblinks) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5993">5993</ref><ref source="BID" url="http://www.securityfocus.com/bid/30060">30060</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/43535">weblinks-index-sql-injection(43535)</ref></refs><vuln_soft><prod name="brightcode_weblinks_module" vendor="brightcode"><vers num=""/></prod><prod name="com_brightweblinks" vendor="Joomla"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-3087" published="2008-07-09" seq="2008-3087" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Kasseler CMS 1.3.0 allows remote attackers to read arbitrary files via a ..  (dot dot) in the file parameter to index.php, possibly related to the phpManual module.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/6007">6007</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30946">30946</ref></refs><vuln_soft><prod name="kasseler_cms" vendor="kasseler-cms"><vers num="1.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-3088" published="2008-07-09" seq="2008-3088" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the Files module in Kasseler CMS 1.3.0 and 1.3.1 Lite allows remote attackers to inject arbitrary web script or HTML via the cid parameter in a Category action to index.php.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/6007">6007</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30946">30946</ref></refs><vuln_soft><prod name="kasseler_cms" vendor="kasseler-cms"><vers num="1.3.0"/><vers edition="unknown" num="1.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-09-03" name="CVE-2008-3101" published="2008-09-03" seq="2008-3101" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in vtiger CRM 5.0.4 allow remote attackers to inject arbitrary web script or HTML via (1) the parenttab parameter in an index action to the Products module, as reachable through index.php; (2) the user_password parameter in an Authenticate action to the Users module, as reachable through index.php; or (3) the query_string parameter in a UnifiedSearch action to the Home module, as reachable through index.php.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/495885/100/0/threaded">20080901 Multiple Cross Site Scripting (XSS) Vulnerabilities in vtigerCRM 5.0.4, CVE-2008-3101</ref><ref source="" url="http://www.datensalat.eu/~fabian/cve/CVE-2008-3101-vtigerCRM.html"></ref><ref source="" url="http://www.vtiger.de/vtiger-crm/downloads/patches.html?tx_abdownloads_pi1%5Baction%5D=getviewdetailsfordownload&amp;tx_abdownloads_pi1%5Buid%5D=128&amp;tx_abdownloads_pi1%5Bcategory_uid%5D=5&amp;cHash=e16be773a5"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/30951">30951</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/2471">ADV-2008-2471</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/31679">31679</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/44792">vtigercrm-index-xss(44792)</ref></refs><vuln_soft><prod name="vtiger_crm" vendor="vtiger"><vers num="5.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.9" CVSS_exploit_subscore="5.5" CVSS_impact_subscore="2.9" CVSS_score="2.9" CVSS_vector="(AV:A/AC:M/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-09-03" name="CVE-2008-3145" published="2008-07-16" seq="2008-3145" severity="Low" type="CVE"><desc><descript source="cve">The fragment_add_work function in epan/reassemble.c in Wireshark 0.8.19 through 1.0.1 allows remote attackers to cause a denial of service (crash) via a series of fragmented packets with non-sequential fragmentation offset values, which lead to a buffer over-read.</descript></desc><loss_types><avail/></loss_types><range><local_network/><user_init/></range><refs><ref source="" url="http://anonsvn.wireshark.org/viewvc/index.py?view=rev&amp;revision=25343"></ref><ref source="" url="http://www.wireshark.org/security/wnpa-sec-2008-04.html"></ref><ref source="" url="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=2470"></ref><ref source="" url="https://bugzilla.redhat.com/show_bug.cgi?id=454984"></ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00544.html">FEDORA-2008-6440</ref><ref source="BID" url="http://www.securityfocus.com/bid/30181">30181</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/2057/references">ADV-2008-2057</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1020471">1020471</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/31044">31044</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31085">31085</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/43719">wireshark-packets-dos(43719)</ref></refs><vuln_soft><prod name="Wireshark" vendor="Wireshark"><vers num="0.8.19"/><vers num="0.99.0"/><vers num="0.99.1"/><vers num="0.99.2"/><vers num="0.99.3"/><vers num="0.99.4"/><vers num="0.99.5"/><vers num="0.99.6"/><vers num="0.99.7"/><vers num="0.99.8"/><vers num="1.0"/><vers num="1.0.0"/><vers num="0.99.6a"/><vers num="1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="8.3" CVSS_exploit_subscore="6.5" CVSS_impact_subscore="10.0" CVSS_score="8.3" CVSS_vector="(AV:A/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-02" name="CVE-2008-3146" published="2008-09-02" seq="2008-3146" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Wireshark and Ethereal on SUSE Linux allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local_network/></range><refs><ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.html">SUSE-SR:2008:017</ref></refs><vuln_soft><prod name="Wireshark" vendor="Wireshark"><vers num=""/></prod><prod name="Ethereal" vendor="Ethereal Group"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-03" name="CVE-2008-3189" published="2008-07-16" seq="2008-3189" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in dreamnews-rss.php in DreamNews Manager allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://milw0rm.com/exploits/6035">6035</ref><ref source="BID" url="http://www.securityfocus.com/bid/30170">30170</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/2058/references">ADV-2008-2058</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31032">31032</ref></refs><vuln_soft><prod name="dreamnews_manager" vendor="DreamLevels"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-09-02" name="CVE-2008-3273" published="2008-08-10" seq="2008-3273" severity="Medium" type="CVE"><desc><descript source="cve">JBoss Enterprise Application Platform (aka JBossEAP or EAP) before 4.2.0.CP03, and 4.3.0 before 4.3.0.CP01, allows remote attackers to obtain sensitive information about &quot;deployed web contexts&quot; via a request to the status servlet, as demonstrated by a full=true query string.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref source="" url="http://www.redhat.com/docs/en-US/JBoss_Enterprise_Application_Platform/4.2.0.cp03/html-single/readme/index.html"></ref><ref source="" url="http://www.redhat.com/docs/en-US/JBoss_Enterprise_Application_Platform/4.3.0.cp01/html-single/readme/"></ref><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=457757"></ref><ref source="" url="https://jira.jboss.org/jira/browse/JBPAPP-544"></ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2008-0825.html">RHSA-2008:0825</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2008-0826.html">RHSA-2008:0826</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2008-0827.html">RHSA-2008:0827</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2008-0828.html">RHSA-2008:0828</ref><ref source="BID" url="http://www.securityfocus.com/bid/30540">30540</ref></refs><vuln_soft><prod name="enterprise_application_platform" vendor="JBoss"><vers num="4.2.0.CP01"/><vers num="4.2.0.CP02"/><vers num="4.2.0.CP03" prev="1"/><vers num="4.3.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-02" name="CVE-2008-3282" published="2008-08-29" seq="2008-3282" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in the memory allocator in OpenOffice.org (OOo) 2.4.1, on 64-bit platforms, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted document, related to a &quot;numeric truncation error,&quot; a different vulnerability than CVE-2008-2152.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://www.openoffice.org/issues/show_bug.cgi?id=92217"></ref><ref source="" url="https://bugzilla.redhat.com/show_bug.cgi?id=455867"></ref><ref source="" url="https://bugzilla.redhat.com/show_bug.cgi?id=458056"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0835.html">RHSA-2008:0835</ref><ref source="BID" url="http://www.securityfocus.com/bid/30866">30866</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1020764">1020764</ref></refs><vuln_soft><prod name="OpenOffice.org" vendor="OpenOffice"><vers edition="unknown" num="2.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-09-02" name="CVE-2008-3283" published="2008-08-29" seq="2008-3283" severity="High" type="CVE"><desc><descript source="cve">Multiple memory leaks in Red Hat Directory Server 7.1 before SP7, Red Hat Directory Server 8, and Fedora Directory Server 1.1.1 and earlier allow remote attackers to cause a denial of service (memory consumption) via vectors involving (1) the authentication / bind phase and (2) anonymous LDAP search requests.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.redhat.com/docs/manuals/dir-server/release-notes/7.1SP7/index.html"></ref><ref source="" url="https://bugzilla.redhat.com/show_bug.cgi?id=458977"></ref><ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2008-0596.html">RHSA-2008:0596</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/30872">30872</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1020774">1020774</ref></refs><vuln_soft><prod name="directory_server" vendor="Fedora"><vers num="1.1.1"/></prod><prod name="Directory Server" vendor="redhat"><vers edition="SP3" num="7.1"/><vers edition="SP1" num="7.1"/><vers edition="SP2" num="7.1"/><vers edition="SP4" num="7.1"/><vers edition="SP5" num="7.1"/><vers edition="sp6" num="7.1"/><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-02" name="CVE-2008-3480" published="2008-08-29" seq="2008-3480" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the Anzio Web Print Object (WePO) ActiveX control 3.2.19 and 3.2.24, as used in Anzio Print Wizard, allows remote attackers to execute arbitrary code via a long mainurl parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/6278">6278</ref><ref source="" url="http://www.coresecurity.com/content/anzio-web-print-object-buffer-overflow"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/30545">30545</ref></refs><vuln_soft><prod name="print_wizard" vendor="anzio"><vers edition="unknown" num="3.2.19"/><vers edition="unknown" num="3.2.19"/></prod><prod name="web_print_object" vendor="anzio"><vers num="3.2.19"/><vers num="3.2.24"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-03" name="CVE-2008-3525" published="2008-09-03" seq="2008-3525" severity="High" type="CVE"><desc><descript source="cve">The sbni_ioctl function in drivers/net/wan/sbni.c in the wan subsystem in the Linux kernel 2.6.26.3 does not check for the CAP_NET_ADMIN capability before processing a (1) SIOCDEVRESINSTATS, (2) SIOCDEVSHWSTATE, (3) SIOCDEVENSLAVE, or (4) SIOCDEVEMANSIPATE ioctl request, which allows local users to bypass intended capability restrictions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2008/08/29/2">[oss-security] 20080829 CVE-2008-3525 kernel: missing capability checks in sbni_ioctl()</ref><ref source="" url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=f2455eb176ac87081bbfc9a44b21c7cd2bc1967e"></ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.26.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-3530" published="2008-09-05" seq="2008-3530" severity="High" type="CVE"><desc><descript source="cve">sys/netinet6/icmp6.c in the kernel in FreeBSD 6.3 through 7.1 does not properly check the proposed new MTU in an ICMPv6 Packet Too Big Message, which allows remote attackers to cause a denial of service (panic) via a crafted Packet Too Big Message.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref patch="1" source="FREEBSD" url="http://security.freebsd.org/advisories/FreeBSD-SA-08:09.icmp6.asc">FreeBSD-SA-08:09</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/31004">31004</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31745">31745</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.3"/><vers num="7.0"/><vers num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="10.0" CVSS_score="6.9" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-3531" published="2008-09-05" seq="2008-3531" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in sys/kern/vfs_mount.c in the kernel in FreeBSD 7.0 and 7.1, when vfs.usermount is enabled, allows local users to gain privileges via a crafted (1) mount or (2) nmount system call, related to copying of &quot;user defined data&quot; in &quot;certain error conditions.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><local/></range><refs><ref source="FREEBSD" url="http://security.FreeBSD.org/advisories/FreeBSD-SA-08:08.nmount.asc">FreeBSD-SA-08:08</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/31002">31002</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="7.0"/><vers num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-09-03" name="CVE-2008-3536" published="2008-09-03" seq="2008-3536" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in ovalarmsrv in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to cause a denial of service via unknown vectors, a different vulnerability than CVE-2008-3537.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref patch="1" source="HP" url="http://marc.info/?l=bugtraq&amp;m=122037165310549&amp;w=2">HPSBMA02362</ref></refs><vuln_soft><prod name="OpenView Network Node Manager" vendor="HP"><vers num="7.01"/><vers num="7.51"/><vers num="7.53"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-09-03" name="CVE-2008-3537" published="2008-09-03" seq="2008-3537" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in ovalarmsrv in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to cause a denial of service via unknown vectors, a different vulnerability than CVE-2008-3536.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref patch="1" source="HP" url="http://marc.info/?l=bugtraq&amp;m=122037165310549&amp;w=2">HPSBMA02362</ref></refs><vuln_soft><prod name="OpenView Network Node Manager" vendor="HP"><vers num="7.01"/><vers num="7.51"/><vers num="7.53"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-09-02" name="CVE-2008-3538" published="2008-09-02" seq="2008-3538" severity="High" type="CVE"><desc><descript source="cve">libxml2, possibly before 2.5.0, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, aka the &quot;billion laughs attack.&quot;</descript></desc><loss_types><avail/></loss_types><range><network/><user_init/></range><refs><ref source="MLIST" url="http://mail.gnome.org/archives/xml/2008-August/msg00034.html">[xml] 20080820 Security fix for libxml2</ref><ref source="" url="http://www.reddit.com/r/programming/comments/65843/time_to_upgrade_libxml2"></ref><ref source="" url="http://xmlsoft.org/news.html"></ref></refs><vuln_soft><prod name="Libxml2" vendor="XMLSoft"><vers num="1.7.0"/><vers num="1.7.1"/><vers num="1.7.2"/><vers num="1.7.3"/><vers num="1.7.4"/><vers num="1.8.0"/><vers num="1.8.1"/><vers num="1.8.10"/><vers num="1.8.13"/><vers num="1.8.14"/><vers num="1.8.16"/><vers num="1.8.2"/><vers num="1.8.3"/><vers num="1.8.4"/><vers num="1.8.5"/><vers num="1.8.6"/><vers num="1.8.7"/><vers num="1.8.9"/><vers num="2.0.0"/><vers num="2.1.0"/><vers num="2.1.1"/><vers num="2.2.0"/><vers num="2.2.1"/><vers num="2.2.10"/><vers num="2.2.11"/><vers num="2.2.2"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.2.5"/><vers num="2.2.6"/><vers num="2.2.7"/><vers num="2.2.8"/><vers num="2.2.9"/><vers num="2.3.0"/><vers num="2.3.1"/><vers num="2.3.10"/><vers num="2.3.11"/><vers num="2.3.12"/><vers num="2.3.13"/><vers num="2.3.14"/><vers num="2.3.2"/><vers num="2.3.3"/><vers num="2.3.4"/><vers num="2.3.5"/><vers num="2.3.6"/><vers num="2.3.7"/><vers num="2.3.8"/><vers num="2.3.9"/><vers num="2.4.1"/><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18"/><vers num="2.4.19"/><vers num="2.4.2"/><vers num="2.4.20"/><vers num="2.4.21"/><vers num="2.4.22"/><vers num="2.4.23"/><vers num="2.4.24"/><vers num="2.4.25"/><vers num="2.4.26"/><vers num="2.4.27"/><vers num="2.4.28"/><vers num="2.4.29"/><vers num="2.4.3"/><vers num="2.4.30"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.5.0"/><vers edition="beta" num="2.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-3664" published="2008-09-05" seq="2008-3664" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in XRMS allow remote attackers to inject arbitrary web script or HTML via (1) the real name field, related to the user list; (2) the target parameter to login.php, (3) the title parameter to activities/some.php, (4) the company_name parameter to companies/some.php, (5) the last_name parameter to contacts/some.php, (6) the campaign_title parameter to campaigns/some.php, (7) the opportunity_title parameter to opportunities/some.php, (8) the case_title parameter to cases/some.php, (9) the file_id parameter to files/some.php, or (10) the starting parameter to reports/custom/mileage.php, a related issue to CVE-2008-1129.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/495981/100/0/threaded">20080904 Multiple Cross Site Scripting (XSS) and SQL injection Vulnerabilities in XRMS, CVE-2008-3664</ref><ref source="BID" url="http://www.securityfocus.com/bid/31008">31008</ref></refs><vuln_soft><prod name="xrms_crm" vendor="xrms"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-03" name="CVE-2008-3691" published="2008-09-03" seq="2008-3691" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 has unknown impact and remote attack vectors, a different vulnerability than CVE-2008-3692, CVE-2008-3693, CVE-2008-3694, CVE-2008-3695, and CVE-2008-3696.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/495869/100/0/threaded">20080830 VMSA-2008-0014 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX address information disclosure, privilege escalation and other security issues.</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-August/064118.html">20080830 VMSA-2008-0014 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX address information disclosure, privilege escalation and other security issues.</ref><ref source="" url="http://www.vmware.com/support/ace/doc/releasenotes_ace.html"></ref><ref source="" url="http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html"></ref><ref source="" url="http://www.vmware.com/support/player/doc/releasenotes_player.html"></ref><ref source="" url="http://www.vmware.com/support/player2/doc/releasenotes_player2.html"></ref><ref source="" url="http://www.vmware.com/support/server/doc/releasenotes_server.html"></ref><ref source="" url="http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html"></ref><ref source="" url="http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/30934">30934</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/2466">ADV-2008-2466</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/31707">31707</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/31708">31708</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/31709">31709</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/31710">31710</ref></refs><vuln_soft><prod name="VMWare Player" vendor="VMWare"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6"/><vers num="1.0.7" prev="1"/><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4" prev="1"/></prod><prod name="VMware Server" vendor="VMWare"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6" prev="1"/></prod><prod name="VMWare Workstation" vendor="VMWare"><vers num="5.5"/><vers num="5.5.1"/><vers num="5.5.2"/><vers num="5.5.3"/><vers num="5.5.4"/><vers num="5.5.5"/><vers num="5.5.6"/><vers num="5.5.7" prev="1"/><vers num="6.0"/><vers num="6.0.1"/><vers num="6.0.2"/><vers num="6.0.3"/><vers num="6.0.4" prev="1"/></prod><prod name="ACE" vendor="VMWare"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6" prev="1"/><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-03" name="CVE-2008-3692" published="2008-09-03" seq="2008-3692" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 has unknown impact and remote attack vectors, a different vulnerability than CVE-2008-3691, CVE-2008-3693, CVE-2008-3694, CVE-2008-3695, and CVE-2008-3696.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/495869/100/0/threaded">20080830 VMSA-2008-0014 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX address information disclosure, privilege escalation and other security issues.</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-August/064118.html">20080830 VMSA-2008-0014 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX address information disclosure, privilege escalation and other security issues.</ref><ref source="" url="http://www.vmware.com/support/ace/doc/releasenotes_ace.html"></ref><ref source="" url="http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html"></ref><ref source="" url="http://www.vmware.com/support/player/doc/releasenotes_player.html"></ref><ref source="" url="http://www.vmware.com/support/player2/doc/releasenotes_player2.html"></ref><ref source="" url="http://www.vmware.com/support/server/doc/releasenotes_server.html"></ref><ref source="" url="http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html"></ref><ref source="" url="http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/30934">30934</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/2466">ADV-2008-2466</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/31707">31707</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/31708">31708</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/31709">31709</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/31710">31710</ref></refs><vuln_soft><prod name="VMWare Player" vendor="VMWare"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6"/><vers num="1.0.7" prev="1"/><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4" prev="1"/></prod><prod name="VMware Server" vendor="VMWare"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6" prev="1"/></prod><prod name="VMWare Workstation" vendor="VMWare"><vers num="5.5"/><vers num="5.5.1"/><vers num="5.5.2"/><vers num="5.5.3"/><vers num="5.5.4"/><vers num="5.5.5"/><vers num="5.5.6"/><vers num="5.5.7" prev="1"/><vers num="6.0"/><vers num="6.0.1"/><vers num="6.0.2"/><vers num="6.0.3"/><vers num="6.0.4" prev="1"/></prod><prod name="ACE" vendor="VMWare"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6" prev="1"/><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-03" name="CVE-2008-3693" published="2008-09-03" seq="2008-3693" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 has unknown impact and remote attack vectors, a different vulnerability than CVE-2008-3691, CVE-2008-3692, CVE-2008-3694, CVE-2008-3695, and CVE-2008-3696.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/495869/100/0/threaded">20080830 VMSA-2008-0014 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX address information disclosure, privilege escalation and other security issues.</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-August/064118.html">20080830 VMSA-2008-0014 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX address information disclosure, privilege escalation and other security issues.</ref><ref source="" url="http://www.vmware.com/support/ace/doc/releasenotes_ace.html"></ref><ref source="" url="http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html"></ref><ref source="" url="http://www.vmware.com/support/player/doc/releasenotes_player.html"></ref><ref source="" url="http://www.vmware.com/support/player2/doc/releasenotes_player2.html"></ref><ref source="" url="http://www.vmware.com/support/server/doc/releasenotes_server.html"></ref><ref source="" url="http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html"></ref><ref source="" url="http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/30934">30934</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/2466">ADV-2008-2466</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/31707">31707</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/31708">31708</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/31709">31709</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/31710">31710</ref></refs><vuln_soft><prod name="VMWare Player" vendor="VMWare"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6"/><vers num="1.0.7" prev="1"/><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4" prev="1"/></prod><prod name="VMware Server" vendor="VMWare"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6" prev="1"/></prod><prod name="VMWare Workstation" vendor="VMWare"><vers num="5.5"/><vers num="5.5.1"/><vers num="5.5.2"/><vers num="5.5.3"/><vers num="5.5.4"/><vers num="5.5.5"/><vers num="5.5.6"/><vers num="5.5.7" prev="1"/><vers num="6.0"/><vers num="6.0.1"/><vers num="6.0.2"/><vers num="6.0.3"/><vers num="6.0.4" prev="1"/></prod><prod name="ACE" vendor="VMWare"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6" prev="1"/><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-03" name="CVE-2008-3694" published="2008-09-03" seq="2008-3694" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 has unknown impact and remote attack vectors, a different vulnerability than CVE-2008-3691, CVE-2008-3692, CVE-2008-3693, CVE-2008-3695, and CVE-2008-3696.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/495869/100/0/threaded">20080830 VMSA-2008-0014 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX address information disclosure, privilege escalation and other security issues.</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-August/064118.html">20080830 VMSA-2008-0014 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX address information disclosure, privilege escalation and other security issues.</ref><ref source="" url="http://www.vmware.com/support/ace/doc/releasenotes_ace.html"></ref><ref source="" url="http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html"></ref><ref source="" url="http://www.vmware.com/support/player/doc/releasenotes_player.html"></ref><ref source="" url="http://www.vmware.com/support/player2/doc/releasenotes_player2.html"></ref><ref source="" url="http://www.vmware.com/support/server/doc/releasenotes_server.html"></ref><ref source="" url="http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html"></ref><ref source="" url="http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/30934">30934</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/2466">ADV-2008-2466</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/31707">31707</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/31708">31708</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/31709">31709</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/31710">31710</ref></refs><vuln_soft><prod name="VMWare Player" vendor="VMWare"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6"/><vers num="1.0.7" prev="1"/><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4" prev="1"/></prod><prod name="VMware Server" vendor="VMWare"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6" prev="1"/></prod><prod name="VMWare Workstation" vendor="VMWare"><vers num="5.5"/><vers num="5.5.1"/><vers num="5.5.2"/><vers num="5.5.3"/><vers num="5.5.4"/><vers num="5.5.5"/><vers num="5.5.6"/><vers num="5.5.7" prev="1"/><vers num="6.0"/><vers num="6.0.1"/><vers num="6.0.2"/><vers num="6.0.3"/><vers num="6.0.4" prev="1"/></prod><prod name="ACE" vendor="VMWare"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6" prev="1"/><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-03" name="CVE-2008-3695" published="2008-09-03" seq="2008-3695" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 has unknown impact and remote attack vectors, a different vulnerability than CVE-2008-3691, CVE-2008-3692, CVE-2008-3693, CVE-2008-3694, and CVE-2008-3696.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/495869/100/0/threaded">20080830 VMSA-2008-0014 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX address information disclosure, privilege escalation and other security issues.</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-August/064118.html">20080830 VMSA-2008-0014 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX address information disclosure, privilege escalation and other security issues.</ref><ref source="" url="http://www.vmware.com/support/ace/doc/releasenotes_ace.html"></ref><ref source="" url="http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html"></ref><ref source="" url="http://www.vmware.com/support/player/doc/releasenotes_player.html"></ref><ref source="" url="http://www.vmware.com/support/player2/doc/releasenotes_player2.html"></ref><ref source="" url="http://www.vmware.com/support/server/doc/releasenotes_server.html"></ref><ref source="" url="http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html"></ref><ref source="" url="http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/30934">30934</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/2466">ADV-2008-2466</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/31707">31707</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/31708">31708</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/31709">31709</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/31710">31710</ref></refs><vuln_soft><prod name="VMWare Player" vendor="VMWare"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6"/><vers num="1.0.7" prev="1"/><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4" prev="1"/></prod><prod name="VMware Server" vendor="VMWare"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6" prev="1"/></prod><prod name="VMWare Workstation" vendor="VMWare"><vers num="5.5"/><vers num="5.5.1"/><vers num="5.5.2"/><vers num="5.5.3"/><vers num="5.5.4"/><vers num="5.5.5"/><vers num="5.5.6"/><vers num="5.5.7" prev="1"/><vers num="6.0"/><vers num="6.0.1"/><vers num="6.0.2"/><vers num="6.0.3"/><vers num="6.0.4" prev="1"/></prod><prod name="ACE" vendor="VMWare"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6" prev="1"/><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-03" name="CVE-2008-3696" published="2008-09-03" seq="2008-3696" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 has unknown impact and remote attack vectors, a different vulnerability than CVE-2008-3691, CVE-2008-3692, CVE-2008-3693, CVE-2008-3694, and CVE-2008-3695.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/495869/100/0/threaded">20080830 VMSA-2008-0014 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX address information disclosure, privilege escalation and other security issues.</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-August/064118.html">20080830 VMSA-2008-0014 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX address information disclosure, privilege escalation and other security issues.</ref><ref source="" url="http://www.vmware.com/support/ace/doc/releasenotes_ace.html"></ref><ref source="" url="http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html"></ref><ref source="" url="http://www.vmware.com/support/player/doc/releasenotes_player.html"></ref><ref source="" url="http://www.vmware.com/support/player2/doc/releasenotes_player2.html"></ref><ref source="" url="http://www.vmware.com/support/server/doc/releasenotes_server.html"></ref><ref source="" url="http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html"></ref><ref source="" url="http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/30934">30934</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/2466">ADV-2008-2466</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/31707">31707</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/31708">31708</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/31709">31709</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/31710">31710</ref></refs><vuln_soft><prod name="VMWare Player" vendor="VMWare"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6"/><vers num="1.0.7" prev="1"/><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4" prev="1"/></prod><prod name="VMware Server" vendor="VMWare"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6" prev="1"/></prod><prod name="VMWare Workstation" vendor="VMWare"><vers num="5.5"/><vers num="5.5.1"/><vers num="5.5.2"/><vers num="5.5.3"/><vers num="5.5.4"/><vers num="5.5.5"/><vers num="5.5.6"/><vers num="5.5.7" prev="1"/><vers num="6.0"/><vers num="6.0.1"/><vers num="6.0.2"/><vers num="6.0.3"/><vers num="6.0.4" prev="1"/></prod><prod name="ACE" vendor="VMWare"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6" prev="1"/><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-09-03" name="CVE-2008-3697" published="2008-09-03" seq="2008-3697" severity="Medium" type="CVE"><desc><descript source="cve">An unspecified ISAPI extension in VMware Server before 1.0.7 build 108231 allows remote attackers to cause a denial of service (IIS crash) via a malformed request.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/495869/100/0/threaded">20080830 VMSA-2008-0014 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX address information disclosure, privilege escalation and other security issues.</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-August/064118.html">20080830 VMSA-2008-0014 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX address information disclosure, privilege escalation and other security issues.</ref><ref source="" url="http://www.vmware.com/support/server/doc/releasenotes_server.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/30935">30935</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/2466">ADV-2008-2466</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31708">31708</ref></refs><vuln_soft><prod name="VMware Server" vendor="VMWare"><vers num="1.0"/><vers num="1.0.0"/><vers num="1.0.1"/><vers num="1.0.1.29996"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.4.56528"/><vers num="1.0.5"/><vers num="1.0.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-03" name="CVE-2008-3698" published="2008-09-03" seq="2008-3698" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the OpenProcess function in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 on Windows allows local host OS users to gain privileges on the host OS via unknown vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/495869/100/0/threaded">20080830 VMSA-2008-0014 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX address information disclosure, privilege escalation and other security issues.</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-August/064118.html">20080830 VMSA-2008-0014 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX address information disclosure, privilege escalation and other security issues.</ref><ref source="" url="http://www.vmware.com/support/ace/doc/releasenotes_ace.html"></ref><ref source="" url="http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html"></ref><ref source="" url="http://www.vmware.com/support/player/doc/releasenotes_player.html"></ref><ref source="" url="http://www.vmware.com/support/player2/doc/releasenotes_player2.html"></ref><ref source="" url="http://www.vmware.com/support/server/doc/releasenotes_server.html"></ref><ref source="" url="http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html"></ref><ref source="" url="http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/30936">30936</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/2466">ADV-2008-2466</ref><ref source="SECUNIA" url="http://secunia.com/advisories/31707">31707</ref></refs><vuln_soft><prod name="VMWare Player" vendor="VMWare"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6"/><vers num="1.0.7" prev="1"/><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4" prev="1"/></prod><prod name="VMware Server" vendor="VMWare"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6" prev="1"/></prod><prod name="VMWare Workstation" vendor="VMWare"><vers num="5.5"/><vers num="5.5.1"/><vers num="5.5.2"/><vers num="5.5.3"/><vers num="5.5.4"/><vers num="5.5.5"/><vers num="5.5.6"/><vers num="5.5.7" prev="1"/><vers num="6.0"/><vers num="6.0.1"/><vers num="6.0.2"/><vers num="6.0.3"/><vers num="6.0.4" prev="1"/></prod><prod name="ACE" vendor="VMWare"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6" prev="1"/><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-03" name="CVE-2008-3791" published="2008-09-03" seq="2008-3791" severity="Medium" type="CVE"><desc><descript source="cve">src/main-win.c in GPicView 0.1.9 in Lightweight X11 Desktop Environment (LXDE) allows local users to overwrite arbitrary files via a symlink attack on the /tmp/rot.jpg temporary file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><local/></range><refs><ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2008/08/25/3">[oss-security] 20080825 CVE Request (gpicview)</ref><ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2008/08/26/5">[oss-security] 20080826 Re: CVE Request (gpicview)</ref><ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2008/08/26/10">[oss-security] 20080826 Re: CVE Request (gpicview)</ref><ref source="" url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=2019481&amp;group_id=180858&amp;atid=894869"></ref></refs><vuln_soft><prod name="lightweight_x11_desktop_environment" vendor="lxde"><vers num="0.1.9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-09-03" name="CVE-2008-3792" published="2008-09-03" seq="2008-3792" severity="High" type="CVE"><desc><descript source="cve">net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel 2.6.26.3 does not verify that the SCTP-AUTH extension is enabled before proceeding with SCTP-AUTH API functions, which allows attackers to cause a denial of service (panic) via vectors that result in calls to (1) sctp_setsockopt_auth_chunk, (2) sctp_setsockopt_hmac_ident, (3) sctp_setsockopt_auth_key, (4) sctp_setsockopt_active_key, (5) sctp_setsockopt_del_key, (6) sctp_getsockopt_maxburst, (7) sctp_getsockopt_active_key, (8) sctp_getsockopt_peer_auth_chunks, or (9) sctp_getsockopt_local_auth_chunks.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="MLIST" url="http://lkml.org/lkml/2008/8/23/49">[linux-kernel] 20080823 [GIT]: Networking</ref><ref source="MLIST" url="http://marc.info/?l=linux-netdev&amp;m=121928747903176&amp;w=2">[linux-netdev] 20080821 [PATCH] sctp: fix potential panics in the SCTP-AUTH API.</ref><ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2008/08/25/1">[oss-security] 20080825 CVE request: kernel: sctp: fix potential panics in the SCTP-AUTH API</ref><ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2008/08/26/6">[oss-security] 20080826 Re: CVE request: kernel: sctp: fix potential panics in the SCTP-AUTH API</ref><ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2008/08/26/8">[oss-security] 20080826 Re: CVE request: kernel: sctp: fix potential panics in the SCTP-AUTH API</ref><ref source="" url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=5e739d1752aca4e8f3e794d431503bfca3162df4"></ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.23.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-3838" published="2008-08-27" seq="2008-3838" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the NFS Remote Procedure Calls (RPC) zones implementation in Sun Solaris 10 and OpenSolaris before snv_88 allows local administrators of non-global zones to read and modify NFS traffic for arbitrary non-global zones, possibly leading to file modifications or a denial of service.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><local/></range><refs><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-240866-1">240866</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/30853">30853</ref></refs><vuln_soft><prod name="opensolaris" vendor="Sun"><vers edition="unknown" num="unknown"/><vers edition="unknown" num="unknown"/><vers num="snv_01"/><vers num="snv_02"/><vers num="snv_03"/><vers num="snv_04"/><vers num="snv_05"/><vers num="snv_06"/><vers num="snv_07"/><vers num="snv_08"/><vers num="snv_09"/><vers num="snv_10"/><vers num="snv_11"/><vers num="snv_12"/><vers num="snv_13"/><vers num="snv_14"/><vers num="snv_15"/><vers num="snv_16"/><vers num="snv_17"/><vers num="snv_18"/><vers num="snv_19"/><vers num="snv_20"/><vers num="snv_21"/><vers num="snv_22"/><vers num="snv_23"/><vers num="snv_24"/><vers num="snv_25"/><vers num="snv_26"/><vers num="snv_27"/><vers num="snv_28"/><vers num="snv_29"/><vers num="snv_30"/><vers num="snv_31"/><vers num="snv_32"/><vers num="snv_33"/><vers num="snv_34"/><vers num="snv_35"/><vers num="snv_36"/><vers num="snv_37"/><vers num="snv_38"/><vers num="snv_39"/><vers num="snv_40"/><vers num="snv_41"/><vers num="snv_42"/><vers num="snv_43"/><vers num="snv_44"/><vers num="snv_45"/><vers num="snv_46"/><vers num="snv_47"/><vers num="snv_48"/><vers num="snv_49"/><vers num="snv_50"/><vers num="snv_51"/><vers num="snv_52"/><vers num="snv_53"/><vers num="snv_54"/><vers num="snv_55"/><vers num="snv_56"/><vers num="snv_57"/><vers num="snv_58"/><vers num="snv_59"/><vers num="snv_60"/><vers num="snv_61"/><vers num="snv_62"/><vers num="snv_63"/><vers num="snv_64"/><vers num="snv_65"/><vers num="snv_66"/><vers num="snv_67"/><vers num="snv_68"/><vers num="snv_69"/><vers num="snv_70"/><vers num="snv_71"/><vers num="snv_72"/><vers num="snv_73"/><vers num="snv_74"/><vers num="snv_75"/><vers num="snv_76"/><vers num="snv_77"/><vers num="snv_78"/><vers num="snv_79"/><vers num="snv_80"/><vers num="snv_81"/><vers num="snv_82"/><vers num="snv_83"/><vers num="snv_84"/><vers num="snv_85"/><vers num="snv_86"/><vers num="snv_87" prev="1"/><vers edition="unknown" num="snv_01"/><vers edition="unknown" num="snv_01"/><vers edition="unknown" num="snv_02"/><vers edition="unknown" num="snv_02"/><vers edition="unknown" num="snv_03"/><vers edition="unknown" num="snv_03"/><vers edition="unknown" num="snv_04"/><vers edition="unknown" num="snv_04"/><vers edition="unknown" num="snv_05"/><vers edition="unknown" num="snv_05"/><vers edition="unknown" num="snv_06"/><vers edition="unknown" num="snv_06"/><vers edition="unknown" num="snv_07"/><vers edition="unknown" num="snv_07"/><vers edition="unknown" num="snv_08"/><vers edition="unknown" num="snv_08"/><vers edition="unknown" num="snv_09"/><vers edition="unknown" num="snv_09"/><vers edition="unknown" num="snv_10"/><vers edition="unknown" num="snv_10"/><vers edition="unknown" num="snv_11"/><vers edition="unknown" num="snv_11"/><vers edition="unknown" num="snv_12"/><vers edition="unknown" num="snv_12"/><vers edition="unknown" num="snv_13"/><vers edition="unknown" num="snv_13"/><vers edition="unknown" num="snv_14"/><vers edition="unknown" num="snv_14"/><vers edition="unknown" num="snv_15"/><vers edition="unknown" num="snv_15"/><vers edition="unknown" num="snv_16"/><vers edition="unknown" num="snv_16"/><vers edition="unknown" num="snv_17"/><vers edition="unknown" num="snv_17"/><vers edition="unknown" num="snv_18"/><vers edition="unknown" num="snv_18"/><vers edition="unknown" num="snv_19"/><vers edition="unknown" num="snv_19"/><vers edition="unknown" num="snv_20"/><vers edition="unknown" num="snv_20"/><vers edition="unknown" num="snv_21"/><vers edition="unknown" num="snv_21"/><vers edition="unknown" num="snv_22"/><vers edition="unknown" num="snv_22"/><vers edition="unknown" num="snv_23"/><vers edition="unknown" num="snv_23"/><vers edition="unknown" num="snv_24"/><vers edition="unknown" num="snv_24"/><vers edition="unknown" num="snv_25"/><vers edition="unknown" num="snv_25"/><vers edition="unknown" num="snv_26"/><vers edition="unknown" num="snv_26"/><vers edition="unknown" num="snv_27"/><vers edition="unknown" num="snv_27"/><vers edition="unknown" num="snv_28"/><vers edition="unknown" num="snv_28"/><vers edition="unknown" num="snv_29"/><vers edition="unknown" num="snv_29"/><vers edition="unknown" num="snv_30"/><vers edition="unknown" num="snv_30"/><vers edition="unknown" num="snv_31"/><vers edition="unknown" num="snv_31"/><vers edition="unknown" num="snv_32"/><vers edition="unknown" num="snv_32"/><vers edition="unknown" num="snv_33"/><vers edition="unknown" num="snv_33"/><vers edition="unknown" num="snv_34"/><vers edition="unknown" num="snv_34"/><vers edition="unknown" num="snv_35"/><vers edition="unknown" num="snv_35"/><vers edition="unknown" num="snv_36"/><vers edition="unknown" num="snv_36"/><vers edition="unknown" num="snv_37"/><vers edition="unknown" num="snv_37"/><vers edition="unknown" num="snv_38"/><vers edition="unknown" num="snv_38"/><vers edition="unknown" num="snv_39"/><vers edition="unknown" num="snv_39"/><vers edition="unknown" num="snv_40"/><vers edition="unknown" num="snv_40"/><vers edition="unknown" num="snv_41"/><vers edition="unknown" num="snv_41"/><vers edition="unknown" num="snv_42"/><vers edition="unknown" num="snv_42"/><vers edition="unknown" num="snv_43"/><vers edition="unknown" num="snv_43"/><vers edition="unknown" num="snv_44"/><vers edition="unknown" num="snv_44"/><vers edition="unknown" num="snv_45"/><vers edition="unknown" num="snv_45"/><vers edition="unknown" num="snv_46"/><vers edition="unknown" num="snv_46"/><vers edition="unknown" num="snv_47"/><vers edition="unknown" num="snv_47"/><vers edition="unknown" num="snv_48"/><vers edition="unknown" num="snv_48"/><vers edition="unknown" num="snv_49"/><vers edition="unknown" num="snv_49"/><vers edition="unknown" num="snv_50"/><vers edition="unknown" num="snv_50"/><vers edition="unknown" num="snv_51"/><vers edition="unknown" num="snv_51"/><vers edition="unknown" num="snv_52"/><vers edition="unknown" num="snv_52"/><vers edition="unknown" num="snv_53"/><vers edition="unknown" num="snv_53"/><vers edition="unknown" num="snv_54"/><vers edition="unknown" num="snv_54"/><vers edition="unknown" num="snv_55"/><vers edition="unknown" num="snv_55"/><vers edition="unknown" num="snv_56"/><vers edition="unknown" num="snv_56"/><vers edition="unknown" num="snv_57"/><vers edition="unknown" num="snv_57"/><vers edition="unknown" num="snv_58"/><vers edition="unknown" num="snv_58"/><vers edition="unknown" num="snv_59"/><vers edition="unknown" num="snv_59"/><vers edition="unknown" num="snv_60"/><vers edition="unknown" num="snv_60"/><vers edition="unknown" num="snv_61"/><vers edition="unknown" num="snv_61"/><vers edition="unknown" num="snv_62"/><vers edition="unknown" num="snv_62"/><vers edition="unknown" num="snv_63"/><vers edition="unknown" num="snv_63"/><vers edition="unknown" num="snv_64"/><vers edition="unknown" num="snv_64"/><vers edition="unknown" num="snv_65"/><vers edition="unknown" num="snv_65"/><vers edition="unknown" num="snv_66"/><vers edition="unknown" num="snv_66"/><vers edition="unknown" num="snv_67"/><vers edition="unknown" num="snv_67"/><vers edition="unknown" num="snv_68"/><vers edition="unknown" num="snv_68"/><vers edition="unknown" num="snv_69"/><vers edition="unknown" num="snv_69"/><vers edition="unknown" num="snv_70"/><vers edition="unknown" num="snv_70"/><vers edition="unknown" num="snv_71"/><vers edition="unknown" num="snv_71"/><vers edition="unknown" num="snv_72"/><vers edition="unknown" num="snv_72"/><vers edition="unknown" num="snv_73"/><vers edition="unknown" num="snv_73"/><vers edition="unknown" num="snv_74"/><vers edition="unknown" num="snv_74"/><vers edition="unknown" num="snv_75"/><vers edition="unknown" num="snv_75"/><vers edition="unknown" num="snv_76"/><vers edition="unknown" num="snv_76"/><vers edition="unknown" num="snv_77"/><vers edition="unknown" num="snv_77"/><vers edition="unknown" num="snv_78"/><vers edition="unknown" num="snv_78"/><vers edition="unknown" num="snv_79"/><vers edition="unknown" num="snv_79"/><vers edition="unknown" num="snv_80"/><vers edition="unknown" num="snv_80"/><vers edition="unknown" num="snv_81"/><vers edition="unknown" num="snv_81"/><vers edition="unknown" num="snv_82"/><vers edition="unknown" num="snv_82"/><vers edition="unknown" num="snv_83"/><vers edition="unknown" num="snv_83"/><vers edition="unknown" num="snv_84"/><vers edition="unknown" num="snv_84"/><vers edition="unknown" num="snv_85"/><vers edition="unknown" num="snv_85"/><vers edition="unknown" num="snv_86"/><vers edition="unknown" num="snv_86"/><vers edition="unknown, x86" num="snv_87" prev="1"/><vers edition="unknown, sparc" num="snv_87" prev="1"/></prod><prod name="Solaris" vendor="Sun"><vers edition="unknown" num="10"/><vers edition="unknown" num="10"/></prod></vuln_soft></entry><entry CVSS_base_score="4.7" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="6.9" CVSS_score="4.7" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-3839" published="2008-08-27" seq="2008-3839" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the NFS module in the kernel in Sun Solaris 10 and OpenSolaris snv_59 through snv_87, when configured as an NFS server without the nodevices option, allows local users to cause a denial of service (panic) via unspecified vectors.</descript></desc><loss_types><avail/></loss_types><range><local/></range><refs><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-241066-1">241066</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/2425">ADV-2008-2425</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31598">31598</ref></refs><vuln_soft><prod name="opensolaris" vendor="Sun"><vers edition="unknown" num="unknown"/><vers edition="unknown" num="unknown"/><vers num="snv_59"/><vers num="snv_60"/><vers num="snv_61"/><vers num="snv_62"/><vers num="snv_63"/><vers num="snv_64"/><vers num="snv_65"/><vers num="snv_66"/><vers num="snv_67"/><vers num="snv_68"/><vers num="snv_69"/><vers num="snv_70"/><vers num="snv_71"/><vers num="snv_72"/><vers num="snv_73"/><vers num="snv_74"/><vers num="snv_75"/><vers num="snv_76"/><vers num="snv_77"/><vers num="snv_78"/><vers num="snv_79"/><vers num="snv_80"/><vers num="snv_81"/><vers num="snv_82"/><vers num="snv_83"/><vers num="snv_84"/><vers num="snv_85"/><vers num="snv_86"/><vers num="snv_87"/><vers edition="unknown" num="snv_59"/><vers edition="unknown" num="snv_59"/><vers edition="unknown" num="snv_60"/><vers edition="unknown" num="snv_60"/><vers edition="unknown" num="snv_61"/><vers edition="unknown" num="snv_61"/><vers edition="unknown" num="snv_62"/><vers edition="unknown" num="snv_62"/><vers edition="unknown" num="snv_63"/><vers edition="unknown" num="snv_63"/><vers edition="unknown" num="snv_64"/><vers edition="unknown" num="snv_64"/><vers edition="unknown" num="snv_65"/><vers edition="unknown" num="snv_65"/><vers edition="unknown" num="snv_66"/><vers edition="unknown" num="snv_66"/><vers edition="unknown" num="snv_67"/><vers edition="unknown" num="snv_67"/><vers edition="unknown" num="snv_68"/><vers edition="unknown" num="snv_68"/><vers edition="unknown" num="snv_69"/><vers edition="unknown" num="snv_69"/><vers edition="unknown" num="snv_70"/><vers edition="unknown" num="snv_70"/><vers edition="unknown" num="snv_71"/><vers edition="unknown" num="snv_71"/><vers edition="unknown" num="snv_72"/><vers edition="unknown" num="snv_72"/><vers edition="unknown" num="snv_73"/><vers edition="unknown" num="snv_73"/><vers edition="unknown" num="snv_74"/><vers edition="unknown" num="snv_74"/><vers edition="unknown" num="snv_75"/><vers edition="unknown" num="snv_75"/><vers edition="unknown" num="snv_76"/><vers edition="unknown" num="snv_76"/><vers edition="unknown" num="snv_77"/><vers edition="unknown" num="snv_77"/><vers edition="unknown" num="snv_78"/><vers edition="unknown" num="snv_78"/><vers edition="unknown" num="snv_79"/><vers edition="unknown" num="snv_79"/><vers edition="unknown" num="snv_80"/><vers edition="unknown" num="snv_80"/><vers edition="unknown" num="snv_81"/><vers edition="unknown" num="snv_81"/><vers edition="unknown" num="snv_82"/><vers edition="unknown" num="snv_82"/><vers edition="unknown" num="snv_83"/><vers edition="unknown" num="snv_83"/><vers edition="unknown" num="snv_84"/><vers edition="unknown" num="snv_84"/><vers edition="unknown" num="snv_85"/><vers edition="unknown" num="snv_85"/><vers edition="unknown" num="snv_86"/><vers edition="unknown" num="snv_86"/><vers edition="unknown, x86" num="snv_87" prev="1"/><vers edition="unknown, sparc" num="snv_87" prev="1"/></prod><prod name="Solaris" vendor="Sun"><vers edition="unknown" num="10"/><vers edition="unknown" num="10"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-08-29" name="CVE-2008-3842" published="2008-08-27" seq="2008-3842" severity="Medium" type="CVE"><desc><descript source="cve">Request Validation (aka the ValidateRequest filters) in ASP.NET in Microsoft .NET Framework without the MS07-040 update does not properly detect dangerous client input, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by a query string containing a &quot;&lt;/&quot; (less-than slash) sequence.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/495667/100/0/threaded">20080821 PR08-20: Bypassing ASP .NET </ref><ref source="" url="http://www.procheckup.com/PDFs/bypassing-dot-NET-ValidateRequest.pdf"></ref></refs><vuln_soft><prod name=".net_framework" vendor="Microsoft"><vers edition="sp3" num="1.0"/><vers edition="sp1" num="1.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-08-29" name="CVE-2008-3852" published="2008-08-28" seq="2008-3852" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the CLR stored procedure deployment from IBM Database Add-Ins for Visual Studio in the Visual Studio Net component in IBM DB2 9.1 before Fixpak 5 has unknown impact and attack vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="" url="http://www-1.ibm.com/support/docview.wss?uid=swg21255607"></ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=swg1JR28432">JR28432</ref><ref source="BID" url="http://www.securityfocus.com/bid/29601">29601</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1769">ADV-2008-1769</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30558">30558</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/42927">ibm-db2-clr-unspecified(42927)</ref></refs><vuln_soft><prod name="DB2 Universal Database" vendor="IBM"><vers edition="fp4a" num="9.1"/><vers edition="fp4" num="9.1"/><vers edition="fp3" num="9.1"/><vers edition="fp2" num="9.1"/><vers edition="unknown" num="9.1"/><vers edition="fp4a" num="9.1"/><vers edition="fp4" num="9.1"/><vers edition="fp3" num="9.1"/><vers edition="fp2" num="9.1"/><vers edition="unknown" num="9.1"/><vers edition="fp4a" num="9.1"/><vers edition="fp4" num="9.1"/><vers edition="fp3" num="9.1"/><vers edition="fp2" num="9.1"/><vers edition="unknown" num="9.1"/><vers edition="fp4a" num="9.1"/><vers edition="fp4" num="9.1"/><vers edition="fp3" num="9.1"/><vers edition="fp2" num="9.1"/><vers edition="HP_UX" num="9.1"/><vers edition="fp4a" num="9.1"/><vers edition="fp4" num="9.1"/><vers edition="fp3" num="9.1"/><vers edition="fp2" num="9.1"/><vers edition="unknown" num="9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-08-29" name="CVE-2008-3853" published="2008-08-28" seq="2008-3853" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the DAS server program in the Core DAS function component in IBM DB2 9.1 before Fixpak 4a allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via unspecified vectors.  NOTE: this might be related to CVE-2008-0698.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www-1.ibm.com/support/docview.wss?uid=swg21255607"></ref><ref patch="1" source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=swg1IZ12379">IZ12379</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/29601">29601</ref></refs><vuln_soft><prod name="DB2 Universal Database" vendor="IBM"><vers edition="fp4" num="9.1"/><vers edition="fp3" num="9.1"/><vers edition="fp2" num="9.1"/><vers edition="unknown" num="9.1"/><vers edition="fp4" num="9.1"/><vers edition="fp3" num="9.1"/><vers edition="fp2" num="9.1"/><vers edition="unknown" num="9.1"/><vers edition="fp4" num="9.1"/><vers edition="fp3" num="9.1"/><vers edition="fp2" num="9.1"/><vers edition="HP_UX" num="9.1"/><vers edition="fp4" num="9.1"/><vers edition="fp3" num="9.1"/><vers edition="fp2" num="9.1"/><vers edition="unknown" num="9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-08-29" name="CVE-2008-3854" published="2008-08-28" seq="2008-3854" severity="High" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in IBM DB2 9.1 before Fixpak 5 allow remote attackers to cause a denial of service (system outage) via vectors related to (1) use of XQuery to issue statements; the (2) XMLQUERY, (3) XMLEXISTS, and (4) XMLTABLE statements; and the (5) sqlrlaka function.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www-1.ibm.com/support/docview.wss?uid=swg21255607"></ref><ref patch="1" source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=swg1IZ16346">IZ16346</ref><ref patch="1" source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=swg1IZ18434">IZ18434</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/29601">29601</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1769">ADV-2008-1769</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/30558">30558</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/42935">ibm-db2-multiple-bo(42935)</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/42930">ibm-db2-sqlrlaka-bo(42930)</ref></refs><vuln_soft><prod name="DB2 Universal Database" vendor="IBM"><vers edition="fp4a" num="9.1"/><vers edition="fp4" num="9.1"/><vers edition="fp3" num="9.1"/><vers edition="fp2" num="9.1"/><vers edition="unknown" num="9.1"/><vers edition="fp4a" num="9.1"/><vers edition="fp4" num="9.1"/><vers edition="fp3" num="9.1"/><vers edition="fp2" num="9.1"/><vers edition="unknown" num="9.1"/><vers edition="fp4a" num="9.1"/><vers edition="fp4" num="9.1"/><vers edition="fp3" num="9.1"/><vers edition="fp2" num="9.1"/><vers edition="unknown" num="9.1"/><vers edition="fp4a" num="9.1"/><vers edition="fp4" num="9.1"/><vers edition="fp3" num="9.1"/><vers edition="fp2" num="9.1"/><vers edition="HP_UX" num="9.1"/><vers edition="fp4a" num="9.1"/><vers edition="fp4" num="9.1"/><vers edition="fp3" num="9.1"/><vers edition="fp2" num="9.1"/><vers edition="unknown" num="9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-08-29" name="CVE-2008-3855" published="2008-08-28" seq="2008-3855" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the DB2 Administration Server (DAS) in the Core DAS function component in IBM DB2 9.1 before Fixpak 5 allows local users to gain privileges, aka a &quot;FILE CREATION VULNERABILITY.&quot; NOTE: this may be the same as CVE-2007-5664.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><local/></range><refs><ref patch="1" source="" url="http://www-1.ibm.com/support/docview.wss?uid=swg21255607"></ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=swg1IZ12735">IZ12735</ref><ref source="BID" url="http://www.securityfocus.com/bid/29601">29601</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1769">ADV-2008-1769</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30558">30558</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/42932">ibm-db2-adminserver-privilege-escalation(42932)</ref></refs><vuln_soft><prod name="DB2 Universal Database" vendor="IBM"><vers edition="fp4a" num="9.1"/><vers edition="fp4" num="9.1"/><vers edition="fp3" num="9.1"/><vers edition="fp2" num="9.1"/><vers edition="unknown" num="9.1"/><vers edition="fp4a" num="9.1"/><vers edition="fp4" num="9.1"/><vers edition="fp3" num="9.1"/><vers edition="fp2" num="9.1"/><vers edition="unknown" num="9.1"/><vers edition="fp4a" num="9.1"/><vers edition="fp4" num="9.1"/><vers edition="fp3" num="9.1"/><vers edition="fp2" num="9.1"/><vers edition="unknown" num="9.1"/><vers edition="fp4a" num="9.1"/><vers edition="fp4" num="9.1"/><vers edition="fp3" num="9.1"/><vers edition="fp2" num="9.1"/><vers edition="HP_UX" num="9.1"/><vers edition="fp4a" num="9.1"/><vers edition="fp4" num="9.1"/><vers edition="fp3" num="9.1"/><vers edition="fp2" num="9.1"/><vers edition="unknown" num="9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-08-29" name="CVE-2008-3856" published="2008-08-28" seq="2008-3856" severity="High" type="CVE"><desc><descript source="cve">The routine infrastructure component in IBM DB2 9.1 before Fixpak 5 on Unix and Linux does not change the ownership of the db2fmp process, which has unknown impact and attack vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www-1.ibm.com/support/docview.wss?uid=swg21255607"></ref><ref patch="1" source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=swg1IZ20352">IZ20352</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/29601">29601</ref></refs><vuln_soft><prod name="DB2 Universal Database" vendor="IBM"><vers edition="fp4a" num="9.1"/><vers edition="fp4" num="9.1"/><vers edition="fp3" num="9.1"/><vers edition="fp2" num="9.1"/><vers edition="unknown" num="9.1"/><vers edition="fp4a" num="9.1"/><vers edition="fp4" num="9.1"/><vers edition="fp3" num="9.1"/><vers edition="fp2" num="9.1"/><vers edition="unknown" num="9.1"/><vers edition="fp4a" num="9.1"/><vers edition="fp4" num="9.1"/><vers edition="fp3" num="9.1"/><vers edition="fp2" num="9.1"/><vers edition="HP_UX" num="9.1"/><vers edition="fp4a" num="9.1"/><vers edition="fp4" num="9.1"/><vers edition="fp3" num="9.1"/><vers edition="fp2" num="9.1"/><vers edition="unknown" num="9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-08-29" name="CVE-2008-3857" published="2008-08-28" seq="2008-3857" severity="Medium" type="CVE"><desc><descript source="cve">The Base Service Utilities component in IBM DB2 9.1 before Fixpak 5 retains a cleartext password in memory after the database connection that sent the password is fully established, which might allow local users to obtain sensitive information by reading a memory dump.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><local/></range><refs><ref patch="1" source="" url="http://www-1.ibm.com/support/docview.wss?uid=swg21255607"></ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=swg1JR27422">JR27422</ref><ref source="BID" url="http://www.securityfocus.com/bid/29601">29601</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1769">ADV-2008-1769</ref></refs><vuln_soft><prod name="DB2 Universal Database" vendor="IBM"><vers edition="fp4a" num="9.1"/><vers edition="fp4" num="9.1"/><vers edition="fp3" num="9.1"/><vers edition="fp2" num="9.1"/><vers edition="unknown" num="9.1"/><vers edition="fp4a" num="9.1"/><vers edition="fp4" num="9.1"/><vers edition="fp3" num="9.1"/><vers edition="fp2" num="9.1"/><vers edition="unknown" num="9.1"/><vers edition="fp4a" num="9.1"/><vers edition="fp3" num="9.1"/><vers edition="fp2" num="9.1"/><vers edition="unknown" num="9.1"/><vers edition="fp4a" num="9.1"/><vers edition="fp4" num="9.1"/><vers edition="fp3" num="9.1"/><vers edition="fp2" num="9.1"/><vers edition="unknown" num="9.1"/><vers edition="unknown" num="9.1"/><vers edition="fp4a" num="9.1"/><vers edition="fp3" num="9.1"/><vers edition="fp2" num="9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-08-29" name="CVE-2008-3858" published="2008-08-28" seq="2008-3858" severity="Medium" type="CVE"><desc><descript source="cve">The Downlevel DB2RA Support component in IBM DB2 9.1 before Fixpak 4a allows remote attackers to cause a denial of service (instance crash) via a crafted CONNECT data stream that simulates a V7 client connect request.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www-1.ibm.com/support/docview.wss?uid=swg21255607"></ref><ref patch="1" source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=swg1IZ07299">IZ07299</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/29601">29601</ref></refs><vuln_soft><prod name="DB2 Universal Database" vendor="IBM"><vers edition="fp4" num="9.1"/><vers edition="fp3" num="9.1"/><vers edition="fp2" num="9.1"/><vers edition="unknown" num="9.1"/><vers edition="fp4" num="9.1"/><vers edition="fp3" num="9.1"/><vers edition="fp2" num="9.1"/><vers edition="unknown" num="9.1"/><vers edition="fp4" num="9.1"/><vers edition="fp3" num="9.1"/><vers edition="fp2" num="9.1"/><vers edition="unknown" num="9.1"/><vers edition="fp4" num="9.1"/><vers edition="fp3" num="9.1"/><vers edition="fp2" num="9.1"/><vers edition="HP_UX" num="9.1"/><vers edition="fp4a" num="9.1"/><vers edition="fp4" num="9.1"/><vers edition="fp3" num="9.1"/><vers edition="fp2" num="9.1"/><vers edition="unknown" num="9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-09-02" name="CVE-2008-3859" published="2008-08-29" seq="2008-3859" severity="Medium" type="CVE"><desc><descript source="cve">Davlin Thickbox Gallery 2 allows remote attackers to obtain the administrative username and MD5 password hash via a direct request to conf/admins.php.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/6314">6314</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/44682">thickboxgallery-admins-info-disclosure(44682)</ref></refs><vuln_soft><prod name="thickbox_gallery" vendor="davlin"><vers num="2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-09-02" name="CVE-2008-3860" published="2008-08-29" seq="2008-3860" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities (1) in the WYSIWYG editors, (2) during local group creation, (3) during HTML redirects, (4) in the HTML import, (5) in the Rich text editor, and (6) in link-page in IBM Lotus Quickr 8.1 services for Lotus Domino before Hotfix 15 allow remote attackers to inject arbitrary web script or HTML via unknown vectors, including (7) the Imported Page.  NOTE: the vulnerability in the WYSIWYG editors may exist because of an incomplete fix for CVE-2008-2163.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://www-01.ibm.com/support/docview.wss?uid=swg27013341"></ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1020762">1020762</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31634">31634</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/44694">ibm-lotus-quickr-multiple-xss(44694)</ref></refs><vuln_soft><prod name="Lotus Quickr" vendor="IBM"><vers num="8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-02" name="CVE-2008-3861" published="2008-08-29" seq="2008-3861" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in phpMyRealty (PMR) 1.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in pages.php and (2) the price_max parameter in search.php.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/6320">6320</ref><ref source="BID" url="http://www.securityfocus.com/bid/30862">30862</ref></refs><vuln_soft><prod name="phpMyRealty" vendor="phpMyRealty"><vers num="1.0.9" prev="1"/><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6"/><vers num="1.0.7"/><vers num="1.0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-09-02" name="CVE-2008-3873" published="2008-08-29" seq="2008-3873" severity="Medium" type="CVE"><desc><descript source="cve">The System.setClipboard method in Adobe Flash Player allows remote attackers to populate the clipboard with a URL that is difficult to delete, as exploited in the wild in August 2008.</descript></desc><loss_types><avail/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://blogs.zdnet.com/security/?p=1733"></ref><ref source="" url="http://blogs.zdnet.com/security/?p=1759"></ref><ref source="" url="http://blogs.adobe.com/psirt/2008/08/clipboard_attack.html"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1020724">1020724</ref></refs><vuln_soft><prod name="Flash Player" vendor="Adobe"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="3.5" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="2.9" CVSS_score="3.5" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-09-02" name="CVE-2008-3874" published="2008-08-29" seq="2008-3874" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in account.php in Lussumo Vanilla 1.1.5-rc1, 1.1.4, and earlier allows remote authenticated users to inject arbitrary web script or HTML via the Value field (aka Label ==&gt; Value pairs).  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/495577/100/0/threaded">20080819 Vanilla &lt;= 1.1.4 Script Injection/ XSS</ref><ref source="" url="http://lussumo.com/community/discussion/8559/vanilla-115-release-candidate-1/"></ref><ref source="" url="http://lussumo.com/docs/doku.php?id=vanilla:releasenotes"></ref><ref source="" url="http://www.gulftech.org/?node=research&amp;article_id=00126-08192008"></ref><ref source="BID" url="http://www.securityfocus.com/bid/30748">30748</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31527">31527</ref></refs><vuln_soft><prod name="Vanilla" vendor="Lussumo"><vers num="0.9.2"/><vers num="1"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.1"/><vers num="1.1.1"/><vers num="1.1.2"/><vers num="1.1.3"/><vers num="1.1.4"/><vers num="1.1.5-rc1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-02" name="CVE-2008-3875" published="2008-09-02" seq="2008-3875" severity="High" type="CVE"><desc><descript source="cve">The kernel in Sun Solaris 8 through 10 and OpenSolaris before snv_90 allows local users to bypass chroot, zones, and the Solaris Trusted Extensions multi-level security policy, and establish a covert communication channel, via unspecified vectors involving system calls.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-240706-1">240706</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/30880">30880</ref></refs><vuln_soft><prod name="opensolaris" vendor="Sun"><vers num="build_snv_01"/><vers num="build_snv_02"/><vers num="build_snv_13"/><vers num="build_snv_19"/><vers num="build_snv_22"/><vers num="build_snv_39"/><vers num="build_snv_47"/><vers num="build_snv_59"/><vers num="build_snv_64"/><vers num="build_snv_79b"/><vers num="build_snv_87"/><vers num="build_snv_88"/><vers num="build_snv_89" prev="1"/></prod><prod name="Solaris" vendor="Sun"><vers edition="unknown" num="10"/><vers edition="unknown" num="8"/><vers edition="unknown" num="9"/><vers edition="unknown" num="10"/><vers edition="unknown" num="8"/><vers edition="unknown" num="9"/></prod></vuln_soft></entry><entry CVSS_base_score="1.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="2.9" CVSS_score="1.9" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-09-03" name="CVE-2008-3876" published="2008-09-02" seq="2008-3876" severity="Low" type="CVE"><desc><descript source="cve">Apple iPhone 2.0.2, in some configurations, allows physically proximate attackers to bypass intended access restrictions, and obtain sensitive information or make arbitrary use of the device, via an Emergency Call tap and a Home double-tap, followed by a tap of any contact&apos;s blue arrow.</descript></desc><loss_types><conf/></loss_types><range><local/></range><refs><ref source="" url="http://forums.macrumors.com/showthread.php?t=551617"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1020763">1020763</ref></refs><vuln_soft><prod name="iPhone" vendor="Apple"><vers num="2.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-02" name="CVE-2008-3877" published="2008-09-02" seq="2008-3877" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Acoustica Mixcraft 4.1 Build 96 and 4.2 Build 98 allows user-assisted attackers to execute arbitrary code via a crafted .mx4 file.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/6322">6322</ref><ref source="BID" url="http://www.securityfocus.com/bid/30879">30879</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31595">31595</ref></refs><vuln_soft><prod name="mixcraft" vendor="Acoustica"><vers edition="build_96" num="4.1"/><vers edition="build_98" num="4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-02" name="CVE-2008-3878" published="2008-09-02" seq="2008-3878" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 in Ultra Shareware Ultra Office Control allows remote attackers to execute arbitrary code via long strUrl, strFile, and strPostData parameters to the HttpUpload method.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/6318">6318</ref><ref source="" url="http://www.shinnai.net/index.php?mod=02_Forum&amp;group=Security&amp;argument=Remote_performed_exploits&amp;topic=1219826651.ff.php"></ref><ref source="" url="http://www.shinnai.net/xplits/TXT_RvfuIrwypWLMaiVn33Iy.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/30861">30861</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31632">31632</ref></refs><vuln_soft><prod name="ultra_office_control" vendor="ultrashareware"><vers num="2.0.2008.801"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-02" name="CVE-2008-3879" published="2008-09-02" seq="2008-3879" severity="High" type="CVE"><desc><descript source="cve">The Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 and earlier in Ultra Shareware Ultra Office Control allows remote attackers to force the download of arbitrary files onto a client system via a URL in the first argument to the Open method, in conjunction with a full destination pathname in the first argument (SaveAsDocument argument) to the Save method.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/6319">6319</ref><ref source="" url="http://www.shinnai.net/index.php?mod=02_Forum&amp;group=Security&amp;argument=Remote_performed_exploits&amp;topic=1219827906.ff.php"></ref><ref source="" url="http://www.shinnai.net/xplits/TXT_NPku7jFjRufaz85U6Lxn.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/30863">30863</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31632">31632</ref></refs><vuln_soft><prod name="ultra_office_control" vendor="ultrashareware"><vers num="2.0.2008.801" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-02" name="CVE-2008-3880" published="2008-09-02" seq="2008-3880" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in zm_html_view_event.php in ZoneMinder 1.23.3 and earlier allows remote attackers to execute arbitrary SQL commands via the filter array parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/495745/100/0/threaded">20080826 ZoneMinder Multiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/30843">30843</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/44726">zoneminder-zmhtmlviewevent-sql-injection(44726)</ref></refs><vuln_soft><prod name="zoneminder" vendor="zoneminder"><vers num="0.0.1"/><vers num="0.9.10"/><vers num="0.9.11"/><vers num="0.9.12"/><vers num="0.9.13"/><vers num="0.9.14"/><vers num="0.9.15"/><vers num="0.9.16"/><vers num="0.9.7"/><vers num="0.9.8"/><vers num="0.9.9"/><vers num="1.17.0"/><vers num="1.17.1"/><vers num="1.17.2"/><vers num="1.18.0"/><vers num="1.18.1"/><vers num="1.19.0"/><vers num="1.19.1"/><vers num="1.19.2"/><vers num="1.19.3"/><vers num="1.19.4"/><vers num="1.19.5"/><vers num="1.20.0"/><vers num="1.20.1"/><vers num="1.21.0"/><vers num="1.21.1"/><vers num="1.21.2"/><vers num="1.21.3"/><vers num="1.21.4"/><vers num="1.22.0"/><vers num="1.22.1"/><vers num="1.22.2"/><vers num="1.22.3"/><vers num="1.23.0"/><vers num="1.23.1"/><vers num="1.23.2"/><vers num="1.23.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-09-02" name="CVE-2008-3881" published="2008-09-02" seq="2008-3881" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in ZoneMinder 1.23.3 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to unspecified &quot;zm_html_view_*.php&quot; files.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/495745/100/0/threaded">20080826 ZoneMinder Multiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/30843">30843</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/44725">zoneminder-multiple-scripts-xss(44725)</ref></refs><vuln_soft><prod name="zoneminder" vendor="zoneminder"><vers num="0.0.1"/><vers num="0.9.10"/><vers num="0.9.11"/><vers num="0.9.12"/><vers num="0.9.13"/><vers num="0.9.14"/><vers num="0.9.15"/><vers num="0.9.16"/><vers num="0.9.7"/><vers num="0.9.8"/><vers num="0.9.9"/><vers num="1.17.0"/><vers num="1.17.1"/><vers num="1.17.2"/><vers num="1.18.0"/><vers num="1.18.1"/><vers num="1.19.0"/><vers num="1.19.1"/><vers num="1.19.2"/><vers num="1.19.3"/><vers num="1.19.4"/><vers num="1.19.5"/><vers num="1.20.0"/><vers num="1.20.1"/><vers num="1.21.0"/><vers num="1.21.1"/><vers num="1.21.2"/><vers num="1.21.3"/><vers num="1.21.4"/><vers num="1.22.0"/><vers num="1.22.1"/><vers num="1.22.2"/><vers num="1.22.3"/><vers num="1.23.0"/><vers num="1.23.1"/><vers num="1.23.2"/><vers num="1.23.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-02" name="CVE-2008-3882" published="2008-09-02" seq="2008-3882" severity="High" type="CVE"><desc><descript source="cve">ZoneMinder 1.23.3 and earlier allows remote attackers to execute arbitrary commands (aka &quot;Command Injection&quot;) via (1) the executeFilter function in zm_html_view_events.php and (2) the run_state parameter to zm_html_view_state.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/495745/100/0/threaded">20080826 ZoneMinder Multiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/30843">30843</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/44728">zoneminder-htmlviewevents-command-execution(44728)</ref></refs><vuln_soft><prod name="zoneminder" vendor="zoneminder"><vers num="0.0.1"/><vers num="0.9.10"/><vers num="0.9.11"/><vers num="0.9.12"/><vers num="0.9.13"/><vers num="0.9.14"/><vers num="0.9.15"/><vers num="0.9.16"/><vers num="0.9.7"/><vers num="0.9.8"/><vers num="0.9.9"/><vers num="1.17.0"/><vers num="1.17.1"/><vers num="1.17.2"/><vers num="1.18.0"/><vers num="1.18.1"/><vers num="1.19.0"/><vers num="1.19.1"/><vers num="1.19.2"/><vers num="1.19.3"/><vers num="1.19.4"/><vers num="1.19.5"/><vers num="1.20.0"/><vers num="1.20.1"/><vers num="1.21.0"/><vers num="1.21.1"/><vers num="1.21.2"/><vers num="1.21.3"/><vers num="1.21.4"/><vers num="1.22.0"/><vers num="1.22.1"/><vers num="1.22.2"/><vers num="1.22.3"/><vers num="1.23.0"/><vers num="1.23.1"/><vers num="1.23.2"/><vers num="1.23.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-02" name="CVE-2008-3883" published="2008-09-02" seq="2008-3883" severity="High" type="CVE"><desc><descript source="cve">configvar in Caudium 1.4.12 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/roken#####.pike temporary file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=496404"></ref><ref source="" url="http://uvw.ru/report.lenny.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/30897">30897</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31656">31656</ref></refs><vuln_soft><prod name="caudium" vendor="caudium"><vers num="1.4.12"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-09-02" name="CVE-2008-3884" published="2008-09-02" seq="2008-3884" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Blogn (BURO GUN) 1.9.7 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2006-6176.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://www.blogn.org/index.php?e=172"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31662">31662</ref></refs><vuln_soft><prod name="Blogn" vendor="Blogn"><vers num="1.9.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-02" name="CVE-2008-3885" published="2008-09-02" seq="2008-3885" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site request forgery (CSRF) vulnerability in Blogn (BURO GUN) 1.9.7 and earlier allows remote attackers to make content modifications as arbitrary users via unspecified vectors.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://www.blogn.org/index.php?e=172"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31662">31662</ref><ref source="IPA-JPCERT" url="http://jvn.jp/en/jp/JVN84125369/index.html">JVN#84125369</ref></refs><vuln_soft><prod name="Blogn" vendor="Blogn"><vers num="1.9.3"/><vers num="1.9.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-09-02" name="CVE-2008-3886" published="2008-09-02" seq="2008-3886" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.php in dotProject 2.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) the inactive parameter in a tasks action, (2) the date parameter in a calendar day_view action, (3) the callback parameter in a public calendar action, or (4) the type parameter in a ticketsmith action.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://packetstorm.linuxsecurity.com/0808-exploits/dotproject-sqlxss.txt"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31681">31681</ref></refs><vuln_soft><prod name="dotProject" vendor="dotProject"><vers num="2.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.0" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="6.4" CVSS_score="6.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-02" name="CVE-2008-3887" published="2008-09-02" seq="2008-3887" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in index.php in dotProject 2.1.2 allow (1) remote authenticated users to execute arbitrary SQL commands via the tab parameter in a projects action, and (2) remote authenticated administrators to execute arbitrary SQL commands via the user_id parameter in a viewuser action.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="" url="http://packetstorm.linuxsecurity.com/0808-exploits/dotproject-sqlxss.txt"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31681">31681</ref></refs><vuln_soft><prod name="dotProject" vendor="dotProject"><vers num="2.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-02" name="CVE-2008-3888" published="2008-09-02" seq="2008-3888" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in members.asp in Mini-NUKE Freehost 2.3 allows remote attackers to execute arbitrary SQL commands via the uid parameter in a member_details action.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/495743/100/0/threaded">20080825 Mini-NUKE v2.3 Freehost (tr) Multiple Remote SQL Injection Vulnerabilities</ref></refs><vuln_soft><prod name="mini_nuke_freehost" vendor="Aspindir"><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-3890" published="2008-09-05" seq="2008-3890" severity="High" type="CVE"><desc><descript source="cve">The kernel in FreeBSD 6.3 through 7.0 on amd64 platforms can make an extra swapgs call after a General Protection Fault (GPF), which allows local users to gain privileges by triggering a GPF during the kernel&apos;s return from (1) an interrupt, (2) a trap, or (3) a system call.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><local/></range><refs><ref source="FREEBSD" url="http://security.freebsd.org/advisories/FreeBSD-SA-08:07.amd64.asc">FreeBSD-SA-08:07</ref><ref source="BID" url="http://www.securityfocus.com/bid/31003">31003</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31743">31743</ref></refs></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-03" name="CVE-2008-3891" published="2008-09-03" seq="2008-3891" severity="High" type="CVE"><desc><descript source="cve">The SAML Single Sign-On (SSO) Service for Google Apps allows remote service providers to impersonate users at arbitrary service providers via vectors related to authentication responses that lack a request identifier and recipient field.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="" url="http://www.kb.cert.org/vuls/id/MIMG-7FQGWU"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/612636">VU#612636</ref></refs><vuln_soft><prod name="google_apps" vendor="Google"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-03" name="CVE-2008-3892" published="2008-09-03" seq="2008-3892" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in a certain ActiveX control in the COM API in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a call to the GuestInfo method in which there is a long string argument, and an assignment of a long string value to the result of this call.  NOTE: this may overlap CVE-2008-3691, CVE-2008-3692, CVE-2008-3693, CVE-2008-3694, CVE-2008-3695, or CVE-2008-3696.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/495869/100/0/threaded">20080830 VMSA-2008-0014 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX address information disclosure, privilege escalation and other security issues.</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-August/064118.html">20080830 VMSA-2008-0014 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX address information disclosure, privilege escalation and other security issues.</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/6345">6345</ref><ref source="" url="http://www.vmware.com/support/ace/doc/releasenotes_ace.html"></ref><ref source="" url="http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html"></ref><ref source="" url="http://www.vmware.com/support/player/doc/releasenotes_player.html"></ref><ref source="" url="http://www.vmware.com/support/player2/doc/releasenotes_player2.html"></ref><ref source="" url="http://www.vmware.com/support/server/doc/releasenotes_server.html"></ref><ref source="" url="http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html"></ref><ref source="" url="http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/30934">30934</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/2466">ADV-2008-2466</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/31707">31707</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/31708">31708</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/31709">31709</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/31710">31710</ref></refs><vuln_soft><prod name="VMWare Player" vendor="VMWare"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6"/><vers num="1.0.7" prev="1"/><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4" prev="1"/></prod><prod name="VMware Server" vendor="VMWare"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6" prev="1"/></prod><prod name="VMWare Workstation" vendor="VMWare"><vers num="5.5"/><vers num="5.5.1"/><vers num="5.5.2"/><vers num="5.5.3"/><vers num="5.5.4"/><vers num="5.5.5"/><vers num="5.5.6"/><vers num="5.5.7" prev="1"/><vers num="6.0"/><vers num="6.0.1"/><vers num="6.0.2"/><vers num="6.0.3"/><vers num="6.0.4" prev="1"/></prod><prod name="ACE" vendor="VMWare"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6" prev="1"/><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="1.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="2.9" CVSS_score="1.9" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-09-03" name="CVE-2008-3893" published="2008-09-03" seq="2008-3893" severity="Low" type="CVE"><desc><descript source="cve">Microsoft Bitlocker in Windows Vista before SP1 stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer during boot, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.</descript></desc><sols><sol source="nvd">Upgrade to Vista Service Pack 1</sol></sols><loss_types><conf/></loss_types><range><local/></range><refs><ref source="" url="http://www.ivizsecurity.com/security-advisory-iviz-sr-0801.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/31619">31619</ref></refs><vuln_soft><prod name="windows-nt" vendor="Microsoft"><vers edition="unknown" num="vista"/><vers edition="unknown" num="vista"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-09-03" name="CVE-2008-3894" published="2008-09-03" seq="2008-3894" severity="Low" type="CVE"><desc><descript source="cve">IBM Lenovo firmware 7CETB5WW 2.05 stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.</descript></desc><loss_types><conf/></loss_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/495808/100/0/threaded">20080825 [IVIZ-08-005] IBM Lenovo BIOS Plain Text Password Disclosure</ref><ref source="" url="http://www.ivizsecurity.com/preboot-patch.html"></ref><ref source="" url="http://www.ivizsecurity.com/research/preboot/preboot_whitepaper.pdf"></ref></refs><vuln_soft><prod name="lenovo_7cetb5ww" vendor="IBM"><vers num="2.05"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-09-03" name="CVE-2008-3895" published="2008-09-03" seq="2008-3895" severity="Low" type="CVE"><desc><descript source="cve">LILO 22.6.1 and earlier stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer before and after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.</descript></desc><loss_types><conf/></loss_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/495801/100/0/threaded">20080825 [IVIZ-08-008] LILO Security Model bypass exploiting wrong BIOS API usage</ref><ref source="" url="http://www.ivizsecurity.com/preboot-patch.html"></ref><ref source="" url="http://www.ivizsecurity.com/research/preboot/preboot_whitepaper.pdf"></ref></refs><vuln_soft><prod name="lilo" vendor="lilo"><vers num="22.6.1" prev="1"/><vers num="22.6"/><vers num="0"/><vers num="1"/><vers num="10"/><vers num="11"/><vers num="12"/><vers num="13"/><vers num="14"/><vers num="15"/><vers num="16"/><vers num="17"/><vers num="18"/><vers num="19"/><vers num="2"/><vers num="20"/><vers num="21"/><vers num="21-3"/><vers num="21.4.2"/><vers num="21.4.3"/><vers num="21.4.4"/><vers num="21.5"/><vers num="21.5.1"/><vers num="21.6"/><vers num="21.6.1"/><vers num="21.7"/><vers num="21.7.1"/><vers num="21.7.2"/><vers num="21.7.3"/><vers num="21.7.4"/><vers num="21.7.5"/><vers num="22.0"/><vers num="22.0.1"/><vers num="22.0.2"/><vers num="22.1"/><vers num="22.2"/><vers num="22.3"/><vers num="22.3.1"/><vers num="22.3.2"/><vers num="22.3.3"/><vers num="22.3.4"/><vers num="22.4"/><vers num="22.4.1"/><vers num="22.5"/><vers num="22.5.1"/><vers num="22.5.2"/><vers num="22.5.3"/><vers num="22.5.3.1"/><vers num="22.5.4"/><vers num="22.5.5"/><vers num="22.5.6"/><vers num="22.5.7"/><vers num="22.5.7.2"/><vers num="22.5.8"/><vers num="22.5.9"/><vers num="3"/><vers num="4"/><vers num="5"/><vers num="6"/><vers num="7"/><vers num="8"/><vers num="9"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-09-03" name="CVE-2008-3896" published="2008-09-03" seq="2008-3896" severity="Low" type="CVE"><desc><descript source="cve">Grub Legacy 0.97 and earlier stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer before and after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.</descript></desc><loss_types><conf/></loss_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/495726/100/0/threaded">20080825 [IVIZ-08-009] Grub Legacy Security Model bypass exploiting wrong BIOS API usage</ref><ref source="" url="http://www.ivizsecurity.com/preboot-patch.html"></ref><ref source="" url="http://www.ivizsecurity.com/research/preboot/preboot_whitepaper.pdf"></ref></refs><vuln_soft><prod name="grub_legacy" vendor="GNU"><vers num="0.94"/><vers num="0.95"/><vers num="0.96"/><vers num="0.94-i386-pc"/><vers num="0.92"/><vers num="0.93"/><vers num="0.95-i386-pc"/><vers num="0.96-i386-pc"/><vers num="0.97" prev="1"/><vers num="0.97-i386-pc"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-09-03" name="CVE-2008-3897" published="2008-09-03" seq="2008-3897" severity="Low" type="CVE"><desc><descript source="cve">DiskCryptor 0.2.6 on Windows stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer before and after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.</descript></desc><loss_types><conf/></loss_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/495725/100/0/threaded">20080825 [IVIZ-08-006] DiskCryptor Security Model bypass exploiting wrong BIOS API usage</ref><ref source="" url="http://www.ivizsecurity.com/preboot-patch.html"></ref><ref source="" url="http://www.ivizsecurity.com/research/preboot/preboot_whitepaper.pdf"></ref></refs><vuln_soft><prod name="disckcryptor" vendor="freed0m"><vers num="0.2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-09-03" name="CVE-2008-3898" published="2008-09-03" seq="2008-3898" severity="Low" type="CVE"><desc><descript source="cve">Secu Star DriveCrypt Plus Pack 3.9 stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer before and after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.</descript></desc><loss_types><conf/></loss_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/495803/100/0/threaded">20080825 [IVIZ-08-007] DriveCrypt Security Model bypass exploiting wrong BIOS API usage</ref><ref source="" url="http://www.ivizsecurity.com/preboot-patch.html"></ref><ref source="" url="http://www.ivizsecurity.com/research/preboot/preboot_whitepaper.pdf"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31605">31605</ref></refs><vuln_soft><prod name="drivecrypt_plus_pack" vendor="secustar"><vers num="3.9"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-09-03" name="CVE-2008-3899" published="2008-09-03" seq="2008-3899" severity="Low" type="CVE"><desc><descript source="cve">TrueCrypt 5.0 stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer before and after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.  NOTE: the researcher mentions a response from the vendor denying the vulnerability.</descript></desc><loss_types><conf/></loss_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/495805/100/0/threaded">20080825 [IVIZ-08-003] TrueCrypt Security Model bypass exploiting wrong BIOS API usage</ref><ref source="" url="http://www.ivizsecurity.com/preboot-patch.html"></ref><ref source="" url="http://www.ivizsecurity.com/research/preboot/preboot_whitepaper.pdf"></ref></refs><vuln_soft><prod name="TrueCrypt" vendor="TrueCrypt Foundation"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-09-03" name="CVE-2008-3900" published="2008-09-03" seq="2008-3900" severity="Low" type="CVE"><desc><descript source="cve">Intel firmware PE94510M.86A.0050.2007.0710.1559 stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.</descript></desc><loss_types><conf/></loss_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/495804/100/0/threaded">20080825 [IVIZ-08-004] Intel BIOS Plain Text Password Disclosure</ref><ref source="" url="http://www.ivizsecurity.com/preboot-patch.html"></ref><ref source="" url="http://www.ivizsecurity.com/research/preboot/preboot_whitepaper.pdf"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1020738">1020738</ref></refs><vuln_soft><prod name="bios" vendor="Intel"><vers num="PE94510M.86A.0050.2007.0710.1559"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-09-03" name="CVE-2008-3901" published="2008-09-03" seq="2008-3901" severity="Low" type="CVE"><desc><descript source="cve">Software suspend 2 2-2.2.1, when used with the Linux kernel 2.6.16, stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.</descript></desc><loss_types><conf/></loss_types><range><local/></range><refs><ref source="" url="http://www.ivizsecurity.com/research/preboot/preboot_whitepaper.pdf"></ref></refs><vuln_soft><prod name="software_suspend_2" vendor="suspend2"><vers num="2-2.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-09-03" name="CVE-2008-3902" published="2008-09-03" seq="2008-3902" severity="Low" type="CVE"><desc><descript source="cve">HP firmware 68DTT F.0D stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer, aka SSRT080104.</descript></desc><loss_types><conf/></loss_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/495800/100/0/threaded">20080825 [IVIZ-08-002] Hewlett-Packard BIOS Plain Text Password Disclosure</ref><ref source="" url="http://www.ivizsecurity.com/preboot-patch.html"></ref><ref source="" url="http://www.ivizsecurity.com/research/preboot/preboot_whitepaper.pdf"></ref></refs><vuln_soft><prod name="68dtt" vendor="HP"><vers num="f.0d"/></prod></vuln_soft></entry><entry CVSS_base_score="3.5" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="2.9" CVSS_score="3.5" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-3903" published="2008-09-04" seq="2008-3903" severity="Low" type="CVE"><desc><descript source="cve">Asterisk PBX 1.2 through 1.6 and Trixbox PBX 2.6.1, when running with Digest authentication and authalwaysreject enabled, generates different responses depending on whether or not a SIP username is valid, which allows remote attackers to enumerate valid usernames.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref source="" url="http://misel.com/?p=52"></ref></refs><vuln_soft><prod name="p_b_x" vendor="Asterisk"><vers num="1.2"/><vers num="1.2.22"/><vers num="1.4.21.1"/><vers num="1.6"/></prod><prod name="pbx" vendor="trixbox"><vers num="2.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-3904" published="2008-09-04" seq="2008-3904" severity="High" type="CVE"><desc><descript source="cve">src/main-win.c in GPicView 0.1.9 in Lightweight X11 Desktop Environment (LXDE) allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2008/08/30/1">[oss-security] 20080831 Re: CVE Request (gpicview)</ref><ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2008/09/03/1">[oss-security] 20080903 Re: CVE Request (gpicview)</ref></refs><vuln_soft><prod name="gpicview" vendor="lxde"><vers num="0.1.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-3905" published="2008-09-04" seq="2008-3905" severity="Medium" type="CVE"><desc><descript source="cve">resolv.rb in Ruby 1.8.5 and earlier, 1.8.6 before 1.8.6-p287, 1.8.7 before 1.8.7-p72, and 1.9 r18423 and earlier uses sequential transaction IDs and constant source ports for DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447.</descript></desc><loss_types><avail/><int/></loss_types><range><network/></range><refs><ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2008/09/03/3">[oss-security] 20080903 CVE Request (ruby -- DNS spoofing vulnerability in resolv.rb)</ref><ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2008/09/04/9">[oss-security] 20080904 Re: CVE Request (ruby -- DNS spoofing vulnerability</ref><ref patch="1" source="" url="http://www.ruby-lang.org/en/news/2008/08/08/multiple-vulnerabilities-in-ruby/"></ref></refs><vuln_soft><prod name="Ruby" vendor="ruby-lang"><vers num="1.6"/><vers num="1.6.8"/><vers num="1.8.0"/><vers num="1.8.1"/><vers num="1.8.2"/><vers num="1.8.3"/><vers num="1.8.4"/><vers num="1.8.5" prev="1"/><vers edition="p110" num="1.8.6"/><vers edition="p111" num="1.8.6"/><vers edition="p114" num="1.8.6"/><vers edition="p230" num="1.8.6"/><vers edition="p286" num="1.8.6" prev="1"/><vers edition="p71" num="1.8.7" prev="1"/><vers edition="p22" num="1.8.7"/><vers edition="p17" num="1.8.7"/><vers edition="preview1" num="1.8.7"/><vers edition="preview2" num="1.8.7"/><vers edition="preview3" num="1.8.7"/><vers edition="preview4" num="1.8.7"/><vers num="1.8.7"/><vers num="1.8.6"/><vers edition="p36" num="1.8.6"/><vers edition="preview1" num="1.8.6"/><vers edition="preview2" num="1.8.6"/><vers edition="preview3" num="1.8.6"/><vers edition="r18423" num="1.9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-3906" published="2008-09-04" seq="2008-3906" severity="Medium" type="CVE"><desc><descript source="cve">CRLF injection vulnerability in Sys.Web in Mono 2.0 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the query string.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2008/08/27/6">[oss-security] 20080827 CVE request: mono Sys.Web header injection</ref><ref source="" url="https://bugzilla.novell.com/show_bug.cgi?id=418620"></ref><ref source="BID" url="http://www.securityfocus.com/bid/30867">30867</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/2443">ADV-2008-2443</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31643">31643</ref></refs><vuln_soft><prod name="Mono" vendor="Mono Project"><vers num="1.0"/><vers num="1.0.5"/><vers num="1.1.13"/><vers num="1.1.13.4"/><vers num="1.1.13.6"/><vers num="1.1.13.7"/><vers num="1.1.17"/><vers num="1.1.17.1"/><vers num="1.1.18"/><vers num="1.1.4"/><vers num="1.1.8.3"/><vers num="1.2.1"/><vers num="1.2.2"/><vers num="1.2.3"/><vers num="1.2.4"/><vers num="1.2.5"/><vers num="1.2.5.1"/><vers num="1.2.6"/><vers num="1.9"/><vers num="2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-3907" published="2008-09-04" seq="2008-3907" severity="Medium" type="CVE"><desc><descript source="cve">The open-in-browser command in newsbeuter before 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in a feed URL.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2008/09/01/4">[oss-security] 20080901 CVE id request: newsbeuter</ref><ref source="" url="http://www.newsbeuter.org/downloads/CHANGES"></ref><ref source="BID" url="http://www.securityfocus.com/bid/30964">30964</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31676">31676</ref></refs><vuln_soft><prod name="newsbeuter" vendor="newsbeuter"><vers num="0.1.1"/><vers num="0.2"/><vers num="0.3"/><vers num="0.4"/><vers num="0.5"/><vers num="0.6"/><vers num="0.7"/><vers num="0.8"/><vers num="0.8.1"/><vers num="0.8.2"/><vers num="0.9"/><vers num="0.9.1"/><vers num="1.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-3908" published="2008-09-04" seq="2008-3908" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Princeton WordNet (wn) 3.0 allow context-dependent attackers to execute arbitrary code via (1) a long argument on the command line; a long (2) WNSEARCHDIR, (3) WNHOME, or (4) WNDBVERSION environment variable; or (5) a user-supplied dictionary (aka data file).  NOTE: since WordNet itself does not run with special privileges, this issue only crosses privilege boundaries when WordNet is invoked as a third party component.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/495883/100/0/threaded">20080901 [oCERT-2008-014] WordNet stack and heap overflows</ref><ref patch="1" source="" url="http://http://www.ocert.org/analysis/2008-014/analysis.txt"></ref><ref source="" url="http://www.ocert.org/analysis/2008-014/wordnet.patch"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/30958">30958</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/44851">wordnet-binsrch-search-bo(44851)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/44848">wordnet-morph-search-bo(44848)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/44849">wordnet-morphinit-bo(44849)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/44850">wordnet-wninit-bo(44850)</ref></refs><vuln_soft><prod name="wordnet" vendor="princeton_university"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-3909" published="2008-09-04" seq="2008-3909" severity="Medium" type="CVE"><desc><descript source="cve">The administration application in Django 0.91, 0.95, and 0.96 stores unauthenticated HTTP POST requests and processes them after successful authentication occurs, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and delete or modify data via unspecified requests.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2008/09/03/4">[oss-security] 20080903 django CSRF vuln</ref><ref patch="1" source="" url="http://www.djangoproject.com/weblog/2008/sep/02/security/"></ref></refs><vuln_soft><prod name="Django" vendor="Django Project"><vers num="0.91"/><vers num="0.95"/><vers num="0.96"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-3910" published="2008-09-04" seq="2008-3910" severity="High" type="CVE"><desc><descript source="cve">dns2tcp before 0.4.1 does not properly handle negative values in a certain length field in the input argument to the (1) dns_simple_decode or (2) dns_decode function, which allows remote attackers to overwrite a buffer and have unspecified other impact.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2008/09/03/5">[oss-security] 20080904 CVE id request: dns2tcp</ref><ref source="" url="http://www.hsc.fr/ressources/outils/dns2tcp/index.html.en"></ref></refs><vuln_soft><prod name="dns2tcp" vendor="hsc"><vers num="0.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-3911" published="2008-09-04" seq="2008-3911" severity="High" type="CVE"><desc><descript source="cve">The proc_do_xprt function in net/sunrpc/sysctl.c in the Linux kernel 2.6.26.3 does not check the length of a certain buffer obtained from userspace, which allows local users to overflow a stack-based buffer and have unspecified other impact via a crafted read system call for the /proc/sys/sunrpc/transports file.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><local/></range><refs><ref source="MLIST" url="http://lkml.org/lkml/2008/8/30/184">[linux-kernel] 20080830 Re: buffer overflow in /proc/sys/sunrpc/transports</ref><ref source="MLIST" url="http://lkml.org/lkml/2008/8/30/140">[linux-kernel] 20080830 buffer overflow in /proc/sys/sunrpc/transports</ref><ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2008/09/04/2">[oss-security] 20080904 CVE request: kernel: sunrpc: fix possible overrun on read of /proc/sys/sunrpc/transports</ref><ref source="" url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=27df6f25ff218072e0e879a96beeb398a79cdbc8"></ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.26.3"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2008-3916" published="2008-09-04" seq="2008-3916" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the strip_escapes function in signal.c in GNU ed before 1.0 allows context-dependent or user-assisted attackers to execute arbitrary code via a long filename.  NOTE: since ed itself does not typically run with special privileges, this issue only crosses privilege boundaries when ed is invoked as a third-party component.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref source="MLIST" url="http://lists.gnu.org/archive/html/bug-ed/2008-08/msg00000.html">[bug-ed] 20080821 Version 1.0 of GNU ed released</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1020734">1020734</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/44643">gnued-stripescapes-bo(44643)</ref></refs><vuln_soft><prod name="Ed" vendor="GNU"><vers num="0.2"/><vers num="0.3"/><vers num="0.4"/><vers num="0.5"/><vers num="0.6"/><vers num="0.7"/><vers num="0.8"/><vers num="0.9"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-3917" published="2008-09-04" seq="2008-3917" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Ovidentia 6.6.5 allows remote attackers to inject arbitrary web script or HTML via the field parameter in a search action.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/495562/100/0/threaded">20080818 Ovidentia 6.6.5 XSS (index.php)?</ref><ref source="BID" url="http://www.securityfocus.com/bid/30735">30735</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31425">31425</ref></refs><vuln_soft><prod name="ovidentia" vendor="ovidentia"><vers num="6.6.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-3918" published="2008-09-04" seq="2008-3918" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in Ovidentia 6.6.5 allows remote attackers to execute arbitrary SQL commands via the field parameter in a search action.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31425">31425</ref></refs><vuln_soft><prod name="ovidentia" vendor="ovidentia"><vers num="6.6.5"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-3919" published="2008-09-04" seq="2008-3919" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in multiple JustSystems Ichitaro products allows remote attackers to execute arbitrary code via a crafted JTD document, as exploited in the wild in August 2008.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://www.justsystems.com/jp/info/pd8002.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/2447">ADV-2008-2447</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1020748">1020748</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31603">31603</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/44681">ichitaro-jtd-code-execution(44681)</ref></refs><vuln_soft><prod name="ichitaro" vendor="justsystems"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-3920" published="2008-09-04" seq="2008-3920" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in BitlBee before 1.2.2 allows remote attackers to &quot;recreate&quot; and &quot;hijack&quot; existing accounts via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="" url="http://bitlbee.org/main.php/changelog.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/30858">30858</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31633">31633</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/44699">bitlbee-unspecified-security-bypass(44699)</ref></refs><vuln_soft><prod name="bitlbee" vendor="bitlbee"><vers num="0.71"/><vers num="0.72"/><vers num="0.73"/><vers num="0.74"/><vers num="0.80"/><vers num="0.81"/><vers num="0.82"/><vers num="0.83"/><vers num="0.84"/><vers num="0.85"/><vers num="0.90"/><vers num="0.91"/><vers num="0.92"/><vers num="0.93"/><vers num="0.99"/><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers edition="dev" num="1.1"/><vers edition="dev" num="1.1.1"/><vers num="1.2"/><vers num="1.2.1" prev="1"/><vers edition="a" num="0.93"/><vers edition="a" num="0.90"/><vers edition="a" num="0.85"/><vers edition="a" num="0.81"/><vers edition="a" num="0.74"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-3921" published="2008-09-04" seq="2008-3921" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in AWStats Totals 1.0 through 1.14 allow remote attackers to inject arbitrary web script or HTML via the (1) month and (2) year parameter.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/495770/100/0/threaded">20080826 Multiple Vulnerabilities in AWStats Totals</ref><ref source="" url="http://userwww.service.emory.edu/~ekenda2/EMORY-2008-01.txt"></ref><ref patch="1" source="" url="http://www.telartis.nl/xcms/awstats/"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/2442">ADV-2008-2442</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31630">31630</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/44706">awstatstotals-unspecified-xss(44706)</ref></refs><vuln_soft><prod name="awstats_totals" vendor="telartis_bv"><vers num="1.0"/><vers num="1.1"/><vers num="1.11"/><vers num="1.13"/><vers num="1.14"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-3922" published="2008-09-04" seq="2008-3922" severity="High" type="CVE"><desc><descript source="cve">awstatstotals.php in AWStats Totals 1.0 through 1.14 allows remote attackers to execute arbitrary code via PHP sequences in the sort parameter, which is used by the multisort function when dynamically creating an anonymous PHP function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/495770/100/0/threaded">20080826 Multiple Vulnerabilities in AWStats Totals</ref><ref source="" url="http://userwww.service.emory.edu/~ekenda2/EMORY-2008-01.txt"></ref><ref patch="1" source="" url="http://www.telartis.nl/xcms/awstats/"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/2442">ADV-2008-2442</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31630">31630</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/44712">awstatstotals-multisort-command-execution(44712)</ref></refs><vuln_soft><prod name="awstats_totals" vendor="telartis_bv"><vers num="1.0"/><vers num="1.1"/><vers num="1.11"/><vers num="1.13"/><vers num="1.14"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-3923" published="2008-09-04" seq="2008-3923" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in statistics.php in Content Management Made Easy (CMME) 1.12 allow remote attackers to inject arbitrary web script or HTML via the (1) page and (2) year parameters in an hstat_year action.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/6313">6313</ref><ref source="BID" url="http://www.securityfocus.com/bid/30854">30854</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31599">31599</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/44685">cmme-statistics-xss(44685)</ref></refs><vuln_soft><prod name="cmme" vendor="hans_oesterholt"><vers num="1.12"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-3924" published="2008-09-04" seq="2008-3924" severity="Medium" type="CVE"><desc><descript source="cve">The &quot;Make a backup&quot; functionality in Content Management Made Easy (CMME) 1.12 stores sensitive information under the web root with insufficient access control, which allows remote attackers to discover (1) account names and (2) password hashes via a direct request for (a) backup/cmme_data.zip or (b) backup/cmme_cmme.zip.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/6313">6313</ref><ref source="BID" url="http://www.securityfocus.com/bid/30854">30854</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31599">31599</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/44684">cmme-backup-info-disclosure(44684)</ref></refs><vuln_soft><prod name="cmme" vendor="hans_oesterholt"><vers num="1.12"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-3925" published="2008-09-04" seq="2008-3925" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site request forgery (CSRF) vulnerability in admin.php in Content Management Made Easy (CMME) 1.12 allows remote attackers to trigger the logout of an administrative user via a logout action.</descript></desc><loss_types><avail/></loss_types><range><network/><user_init/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/6313">6313</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/44686">cmme-admin-csrf(44686)</ref></refs><vuln_soft><prod name="cmme" vendor="hans_oesterholt"><vers num="1.12"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-3926" published="2008-09-04" seq="2008-3926" severity="Medium" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in Content Management Made Easy (CMME) 1.12 allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the env parameter in a weblog action to index.php, or (2) create arbitrary directories via a .. (dot dot) in the env parameter in a login action to admin.php.</descript></desc><loss_types><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/6313">6313</ref><ref source="BID" url="http://www.securityfocus.com/bid/30854">30854</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31599">31599</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/44683">cmme-env-file-include(44683)</ref></refs><vuln_soft><prod name="cmme" vendor="hans_oesterholt"><vers num="1.12"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-3927" published="2008-09-04" seq="2008-3927" severity="High" type="CVE"><desc><descript source="cve">genmsgidx in Tiger 3.2.2 allows local users to overwrite or delete arbitrary files via a symlink attack on temporary files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=496415"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31659">31659</ref></refs><vuln_soft><prod name="tiger" vendor="tiger"><vers num="3.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="10.0" CVSS_score="6.9" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-3928" published="2008-09-04" seq="2008-3928" severity="Medium" type="CVE"><desc><descript source="cve">test.sh in Honeyd 1.5c might allow local users to overwrite arbitrary files via a symlink attack on temporary files.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><local/></range><refs><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=496365"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31658">31658</ref></refs><vuln_soft><prod name="honeyd_common" vendor="Debian"><vers edition="c_5" num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-3929" published="2008-09-04" seq="2008-3929" severity="High" type="CVE"><desc><descript source="cve">gather-messages.sh in Ampache 3.4.1 allows local users to overwrite arbitrary files via a symlink attack on temporary files.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><local/></range><refs><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=496369"></ref><ref source="BID" url="http://www.securityfocus.com/bid/30875">30875</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31657">31657</ref></refs><vuln_soft><prod name="Ampache" vendor="Ampache"><vers num="3.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="10.0" CVSS_score="6.9" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-3930" published="2008-09-04" seq="2008-3930" severity="Medium" type="CVE"><desc><descript source="cve">migrate_aliases.sh in Citadel Server 7.37 allows local users to overwrite arbitrary files via a symlink attack on temporary files.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><local/></range><refs><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=496359"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31648">31648</ref></refs><vuln_soft><prod name="citadel_server" vendor="Debian"><vers edition="3" num="7.37"/></prod></vuln_soft></entry><entry CVSS_base_score="6.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="10.0" CVSS_score="6.9" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-3931" published="2008-09-04" seq="2008-3931" severity="Medium" type="CVE"><desc><descript source="cve">javareconf in R 2.7.2 allows local users to overwrite arbitrary files via a symlink attack on temporary files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=496363"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31647">31647</ref></refs><vuln_soft><prod name="r" vendor="r_foundation"><vers num="2.7.2"/></prod></vuln_soft></entry><entry CVSS_base_score="3.3" CVSS_exploit_subscore="6.5" CVSS_impact_subscore="2.9" CVSS_score="3.3" CVSS_vector="(AV:A/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-3932" published="2008-09-04" seq="2008-3932" severity="Low" type="CVE"><desc><descript source="cve">Wireshark (formerly Ethereal) 0.9.7 through 1.0.2 allows attackers to cause a denial of service (hang) via a crafted NCP packet that triggers an infinite loop.</descript></desc><loss_types><avail/></loss_types><range><local_network/></range><refs><ref source="" url="http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=2675"></ref><ref patch="1" source="" url="http://www.wireshark.org/security/wnpa-sec-2008-05.html"></ref></refs><vuln_soft><prod name="Wireshark" vendor="Wireshark"><vers num="0.99.8"/><vers num="1.0.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="0.10.1"/><vers num="0.10.10"/><vers num="0.10.11"/><vers num="0.10.12"/><vers num="0.10.13"/><vers num="0.10.14"/><vers num="0.10.2"/><vers num="0.10.3"/><vers num="0.10.4"/><vers num="0.10.5"/><vers num="0.10.6"/><vers num="0.10.7"/><vers num="0.10.8"/><vers num="0.10.9"/><vers num="0.9.7"/><vers num="0.9.8"/><vers num="0.99.0"/><vers num="0.99.1"/><vers num="0.99.2"/><vers num="0.99.3"/><vers num="0.99.4"/><vers num="0.99.5"/><vers num="0.99.6"/><vers num="0.99.6a"/><vers num="0.99.7"/></prod></vuln_soft></entry><entry CVSS_base_score="3.3" CVSS_exploit_subscore="6.5" CVSS_impact_subscore="2.9" CVSS_score="3.3" CVSS_vector="(AV:A/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-3933" published="2008-09-04" seq="2008-3933" severity="Low" type="CVE"><desc><descript source="cve">Wireshark (formerly Ethereal) 0.10.14 through 1.0.2 allows attackers to cause a denial of service (crash) via a packet with crafted zlib-compressed data that triggers an invalid read in the tvb_uncompress function.</descript></desc><loss_types><avail/></loss_types><range><local_network/></range><refs><ref source="" url="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=2682"></ref><ref source="" url="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=2649"></ref><ref patch="1" source="" url="http://www.wireshark.org/security/wnpa-sec-2008-05.html"></ref></refs><vuln_soft><prod name="Wireshark" vendor="Wireshark"><vers num="0.10.14"/><vers num="0.10.2"/><vers num="0.10.3"/><vers num="0.10.4"/><vers num="0.10.5"/><vers num="0.10.6"/><vers num="0.10.7"/><vers num="0.10.8"/><vers num="0.10.9"/><vers num="0.99.0"/><vers num="0.99.1"/><vers num="0.99.2"/><vers num="0.99.3"/><vers num="0.99.4"/><vers num="0.99.5"/><vers num="0.99.6"/><vers num="0.99.6a"/><vers num="0.99.7"/><vers num="0.99.8"/><vers num="1.0.0"/><vers num="1.0.1"/><vers num="1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="3.3" CVSS_exploit_subscore="6.5" CVSS_impact_subscore="2.9" CVSS_score="3.3" CVSS_vector="(AV:A/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-3934" published="2008-09-04" seq="2008-3934" severity="Low" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Wireshark (formerly Ethereal) 0.99.6 through 1.0.2 allows attackers to cause a denial of service (crash) via a crafted Tektronix .rf5 file.</descript></desc><loss_types><avail/></loss_types><range><local_network/></range><refs><ref patch="1" source="" url="http://www.wireshark.org/security/wnpa-sec-2008-05.html"></ref></refs><vuln_soft><prod name="Wireshark" vendor="Wireshark"><vers num="0.99.6"/><vers num="0.99.6a"/><vers num="0.99.7"/><vers num="0.99.8"/><vers num="1.0.0"/><vers num="1.0.1"/><vers num="1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-3935" published="2008-09-05" seq="2008-3935" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in DIC shop_v50 3.0 and earlier and shop_v52 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="" url="http://www.d-ic.com/free/05/shop_v50.html"></ref><ref patch="1" source="" url="http://www.d-ic.com/free/05/shop_v52.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/31006">31006</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31652">31652</ref><ref source="IPA-JPCERT" url="http://jvn.jp/en/jp/JVN79914432/index.html">JVN#79914432</ref></refs><vuln_soft><prod name="shop_v52" vendor="d-ic"><vers num="2.0" prev="1"/></prod><prod name="shop_v50" vendor="d-ic"><vers num="3.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-3936" published="2008-09-05" seq="2008-3936" severity="Medium" type="CVE"><desc><descript source="cve">The web interface in Dreambox DM500C allows remote attackers to cause a denial of service (application hang) via a long URI.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/495837/100/0/threaded">20080829 [scip_Advisory 3807] Dreambox DM500 webserver long URL request denial of service</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-August/064115.html">20080829 [scip_Advisory 3807] Dreambox DM500 webserver long URL request denial of service</ref><ref source="" url="http://www.scip.ch/cgi-bin/smss/showadvf.pl?id=3807"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/2472">ADV-2008-2472</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1020784">1020784</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31650">31650</ref></refs><vuln_soft><prod name="DM500C" vendor="Dreambox"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-3937" published="2008-09-05" seq="2008-3937" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Open Media Collectors Database (OpenDb) 1.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) user_id parameter in an edit action to user_admin.php, the (2) title parameter to listings.php, and the (3) redirect_url parameter to user_profile.php.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://packetstorm.linuxsecurity.com/0808-exploits/omcd-xssxsrf.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/30989">30989</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31719">31719</ref></refs><vuln_soft><prod name="OpenDb" vendor="opendb"><vers num="1.0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-3938" published="2008-09-05" seq="2008-3938" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site request forgery (CSRF) vulnerability in user_admin.php in Open Media Collectors Database (OpenDb) 1.0.6 allows remote attackers to change arbitrary passwords via an update_password action.</descript></desc><loss_types><avail/><int/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://packetstorm.linuxsecurity.com/0808-exploits/omcd-xssxsrf.txt"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31719">31719</ref></refs><vuln_soft><prod name="OpenDb" vendor="opendb"><vers num="1.0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-3939" published="2008-09-05" seq="2008-3939" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the web interface in AVTECH PageR Enterprise before 5.0.7 allows remote attackers to read arbitrary files via directory traversal sequences in the URI.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-September/064227.html">20080902 DDIVRT-2008-13 AVTECH PageR Enterprise Directory Traversal</ref><ref source="BID" url="http://www.securityfocus.com/bid/30987">30987</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31693">31693</ref></refs><vuln_soft><prod name="pager_enterprise" vendor="avtech"><vers num="4.3.7"/><vers num="4.4.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.4" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="6.4" CVSS_score="4.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-3940" published="2008-09-05" seq="2008-3940" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in the finger client in HP TCP/IP Services for OpenVMS 5.x allows local users to gain privileges via format string specifiers in a (1) .plan or (2) .project file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><local/><user_init/></range><refs><ref source="" url="http://deathrow.vistech.net/DEFCON16/VMS.PDF"></ref><ref source="BID" url="http://www.securityfocus.com/bid/30948">30948</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/2463">ADV-2008-2463</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31587">31587</ref></refs><vuln_soft><prod name="OpenVMS" vendor="HP"><vers num="5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-3941" published="2008-09-05" seq="2008-3941" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in BizDirectory 2.04 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter in a search action to the default URI.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=122039853426550&amp;w=2">20080902 Exploit</ref><ref source="BID" url="http://www.securityfocus.com/bid/30980">30980</ref></refs><vuln_soft><prod name="bizdirectory" vendor="bizdirectory"><vers num="1.9"/><vers num="2.0"/><vers num="2.04" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-3942" published="2008-09-05" seq="2008-3942" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in landsee.php in Full PHP Emlak Script allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="" url="http://packetstormsecurity.org/0808-exploits/phpemlak-sql.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/30962">30962</ref></refs><vuln_soft><prod name="full_php_emlak_script" vendor="ozsari"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-3943" published="2008-09-05" seq="2008-3943" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in listtest.php in eZoneScripts Living Local 1.1 allows remote attackers to execute arbitrary SQL commands via the r parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/6361">6361</ref><ref source="BID" url="http://www.securityfocus.com/bid/31001">31001</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31696">31696</ref></refs><vuln_soft><prod name="living_local" vendor="ezonescripts"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-3944" published="2008-09-05" seq="2008-3944" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in ACG-PTP 1.0.6 allows remote attackers to execute arbitrary SQL commands via the adid parameter in an adorder action.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/6362">6362</ref><ref source="BID" url="http://www.securityfocus.com/bid/31005">31005</ref></refs><vuln_soft><prod name="acg_ptp" vendor="discountedscripts"><vers num="1.0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-05" name="CVE-2008-3945" published="2008-09-05" seq="2008-3945" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in Words tag 1.2 allows remote attackers to execute arbitrary SQL commands via the word parameter in a claim action.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/6336">6336</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31653">31653</ref></refs><vuln_soft><prod name="words_tag_script" vendor="Source Workshop"><vers num="1.2"/></prod></vuln_soft></entry><entry name="CVE-2008-3946" published="2008-09-05" seq="2008-3946" type="CVE"><desc><descript source="cve">The finger client in HP TCP/IP Services for OpenVMS 5.x allows local users to read arbitrary files via a link corresponding to a (1) .plan or (2) .project file.</descript></desc><loss_types/><refs><ref source="" url="http://deathrow.vistech.net/DEFCON16/VMS.PDF"></ref></refs></entry><entry name="CVE-2008-3947" published="2008-09-05" seq="2008-3947" type="CVE"><desc><descript source="cve">DCL (aka the CLI) in OpenVMS Alpha 8.3 allows local users to gain privileges via a long command line.</descript></desc><loss_types/><refs><ref source="" url="http://deathrow.vistech.net/DEFCON16/VMS.PDF"></ref></refs></entry><entry name="CVE-2008-3948" published="2008-09-05" seq="2008-3948" type="CVE"><desc><descript source="cve">SQL injection vulnerability in admin/users/self-2.php in XRMS allows remote attackers to execute arbitrary SQL commands and modify name and email fields via unspecified vectors.</descript></desc><loss_types/><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/495981/100/0/threaded">20080904 Multiple Cross Site Scripting (XSS) and SQL injection Vulnerabilities in XRMS, CVE-2008-3664</ref><ref source="BID" url="http://www.securityfocus.com/bid/31008">31008</ref></refs></entry></nvd>
