<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://nvd.nist.gov/feeds/cve/1.2" nvd_xml_version="1.2" pub_date="2010-02-09" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd">
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-0095" seq="1999-0095" severity="High" type="CVE" published="1988-10-01" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-09">
        <desc>
            <descript source="cve">The debug command in Sendmail is enabled, allowing attackers to execute commands as root.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/1">1</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/195">195</ref>
        </refs>
        <vuln_soft>
            <prod vendor="eric_allman" name="sendmail">
                <vers num="5.58" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-0082" seq="1999-0082" severity="High" type="CVE" published="1988-11-11" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-09">
        <desc>
            <descript source="cve">CWD ~root command in ftpd allows root access.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="FarmerVenema" url="http://www.alw.nih.gov/Security/Docs/admin-guide-to-cracking.101.html">Improving the Security of Your Site by Breaking Into it</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ftp" name="ftp">
                <vers num="" />
            </prod>
            <prod vendor="ftpcd" name="ftpcd">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1471" seq="1999-1471" severity="High" type="CVE" published="1989-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in passwd in BSD based operating systems 4.3 and earlier allows local users to gain root privileges by specifying a long shell or GECOS field.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-1989-01.html" adv="1">CA-1989-01</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/4" adv="1">4</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/7152.php">bsd-passwd-bo(7152)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="bsd" name="bsd">
                <vers num="4.2" />
                <vers num="4.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-1999-1122" seq="1999-1122" severity="Medium" type="CVE" published="1989-07-26" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Vulnerability in restore in SunOS 4.0.3 and earlier allows local users to gain privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-1989-02.html" adv="1">CA-1989-02</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6695">sun-restore-gain-privileges(6695)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/3">3</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/ciac-08.shtml">CIAC-08</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="sunos">
                <vers num="4.0" />
                <vers num="4.0.1" />
                <vers num="4.0.3" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-1467" seq="1999-1467" severity="High" type="CVE" published="1989-10-26" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Vulnerability in rcp on SunOS 4.0.x allows remote attackers from trusted hosts to execute arbitrary commands as root, possibly related to the configuration of the nobody user.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-1989-07.html" adv="1">CA-1989-07</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/3165.php" adv="1">sun-rcp(3165)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/5" adv="1">5</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="sunos">
                <vers num="4.0" />
                <vers num="4.0.1" />
                <vers num="4.0.2" />
                <vers num="4.0.3" />
                <vers num="4.0.3c" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-1506" seq="1999-1506" severity="High" type="CVE" published="1990-01-29" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Vulnerability in SMI Sendmail 4.0 and earlier, on SunOS up to 4.0.3, allows remote attackers to access user bin.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" url="http://www.cert.org/advisories/CA-90.01.sun.sendmail.vulnerability" adv="1">CA-1990-01</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/6" adv="1">6</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="sunos">
                <vers num="3.5" />
                <vers num="4.0" />
                <vers num="4.0.1" />
                <vers num="4.0.2" />
                <vers num="4.0.3" />
                <vers num="4.0.3c" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0084" seq="1999-0084" severity="High" type="CVE" published="1990-05-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Certain NFS servers allow users to use mknod to gain privileges by creating a writable kmem device and setting the UID to 0.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/78">nfs-mknod(78)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="nfs">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2000-0388" seq="2000-0388" severity="High" type="CVE" published="1990-05-09" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Buffer overflow in FreeBSD libmytinfo library allows local users to execute commands via a long TERMCAP environmental variable.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/1185">1185</ref>
            <ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00%3A17.libmytinfo.asc">FreeBSD-SA-00:17</ref>
        </refs>
        <vuln_soft>
            <prod vendor="freebsd" name="freebsd">
                <vers num="3.0" />
                <vers num="3.1" />
                <vers num="3.2" />
                <vers num="3.3" />
                <vers num="3.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0209" seq="1999-0209" severity="Medium" type="CVE" published="1990-08-14" CVSS_version="2.0" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">The SunView (SunTools) selection_svc facility allows remote users to read files.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/8">8</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="sunos">
                <vers num="3.5" />
                <vers num="4.0" />
                <vers num="4.0.1" />
                <vers num="4.0.2" />
                <vers num="4.0.3" />
                <vers num="4.1" />
                <vers num="4.1.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1198" seq="1999-1198" severity="High" type="CVE" published="1990-10-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">BuildDisk program on NeXT systems before 2.0 does not prompt users for the root password, which allows local users to gain root privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-1990-06.html" adv="1">CA-1990-06</ref>
            <ref source="CIAC" patch="1" url="http://ciac.llnl.gov/ciac/bulletins/b-01.shtml" adv="1">B-01</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/11">11</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/7141.php">nextstep-builddisk-root-access(7141)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="next" name="next">
                <vers num="2.0" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1391" seq="1999-1391" severity="High" type="CVE" published="1990-10-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Vulnerability in NeXT 1.0a and 1.0 with publicly accessible printers allows local users to gain privileges via a combination of the npd program and weak directory permissions.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-1990-06.html" adv="1">CA-1990-06</ref>
            <ref source="CIAC" patch="1" url="http://ciac.llnl.gov/ciac/bulletins/b-01.shtml" adv="1">B-01</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/10">10</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/7143.php">nextstep-npd-root-access(7143)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="next" name="next">
                <vers num="1.0" />
                <vers num="1.0a" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1392" seq="1999-1392" severity="High" type="CVE" published="1990-10-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Vulnerability in restore0.9 installation script in NeXT 1.0a and 1.0 allows local users to gain root privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-1990-06.html" adv="1">CA-1990-06</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9" adv="1">9</ref>
            <ref source="CIAC" patch="1" url="http://ciac.llnl.gov/ciac/bulletins/b-01.shtml" adv="1">B-01</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/7144.php">nextstep-restore09-root-access(7144)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="next" name="nex">
                <vers num="1.0a" />
            </prod>
            <prod vendor="next" name="next">
                <vers num="1.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-1999-1057" seq="1999-1057" severity="Medium" type="CVE" published="1990-10-25" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">VMS 4.0 through 5.3 allows local users to gain privileges via the ANALYZE/PROCESS_DUMP dcl command.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-1990-07.html" adv="1">CA-1990-07</ref>
            <ref source="CIAC" patch="1" url="http://ciac.llnl.gov/ciac/bulletins/b-04.shtml" adv="1">B-04</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/12">12</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/7137.php">vms-analyze-processdump-privileges(7137)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="digital" name="vms">
                <vers num="5.3" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-1999-1554" seq="1999-1554" severity="Low" type="CVE" published="1990-10-31" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">/usr/sbin/Mail on SGI IRIX 3.3 and 3.3.1 does not properly set the group ID to the group ID of the user who started Mail, which allows local users to read the mail of other users.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-1990-08.html" adv="1">CA-1990-08</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/13" adv="1">13</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/3164.php">sgi-irix-reset(3164)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sgi" name="irix">
                <vers num="3.3" />
                <vers num="3.3.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1197" seq="1999-1197" severity="High" type="CVE" published="1990-12-20" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">TIOCCONS in SunOS 4.1.1 does not properly check the permissions of a user who tries to redirect console output and input, which could allow a local user to gain privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-1990-12.html" adv="1">CA-1990-12</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/14">14</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/7140.php">sunos-tioccons-console-redirection(7140)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="sunos">
                <vers num="4.1.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1115" seq="1999-1115" severity="High" type="CVE" published="1990-12-31" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Vulnerability in the /etc/suid_exec program in HP Apollo Domain/OS sr10.2 and sr10.3 beta, related to the Korn Shell (ksh).</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-1990-04.html" adv="1">CA-1990-04</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/7">7</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/6721.php">apollo-suidexec-unauthorized-access(6721)</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/a-30.shtml">A-30</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="apollo_domain_os">
                <vers num="sr10.2" />
                <vers edition="beta" num="sr10.3" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-1258" seq="1999-1258" severity="Medium" type="CVE" published="1991-01-15" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">rpc.pwdauthd in SunOS 4.1.1 and earlier does not properly prevent remote access to the daemon, which allows remote attackers to obtain sensitive system information.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/1782.php" adv="1">sun-pwdauthd(1782)</ref>
            <ref source="SUN" patch="1" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/102" adv="1">00102</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="sunos">
                <vers num="4.1" />
                <vers num="4.1.1" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1438" seq="1999-1438" severity="High" type="CVE" published="1991-02-22" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Vulnerability in /bin/mail in SunOS 4.1.1 and earlier allows local users to gain root privileges via certain command line arguments.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-91.01a.SunOS.mail.vulnerability" adv="1">CA-1991-01</ref>
            <ref source="SUN" patch="1" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/105" adv="1">00105</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/15">15</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="sunos">
                <vers num="4.0.3" />
                <vers num="4.1" />
                <vers num="4.1.1" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1211" seq="1999-1211" severity="High" type="CVE" published="1991-03-27" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Vulnerability in in.telnetd in SunOS 4.1.1 and earlier allows local users to gain root privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-1991-02.html" adv="1">CA-1991-02</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/574.php" adv="1">sun-intelnetd(574)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="sunos">
                <vers num="4.1.1" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1212" seq="1999-1212" severity="High" type="CVE" published="1991-03-27" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Vulnerability in in.rlogind in SunOS 4.0.3 and 4.0.3c allows local users to gain root privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-1991-02.html" adv="1">CA-1991-02</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/574.php" adv="1">sun-intelnetd(574)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="sunos">
                <vers num="4.0.3" />
                <vers num="4.0.3c" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1194" seq="1999-1194" severity="High" type="CVE" published="1991-05-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">chroot in Digital Ultrix 4.1 and 4.0 is insecurely installed, which allows local users to gain privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-1991-05.html" adv="1">CA-1991-05</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/577.php" adv="1">dec-chroot(577)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/17">17</ref>
        </refs>
        <vuln_soft>
            <prod vendor="digital" name="ultrix">
                <vers num="4.0" />
                <vers num="4.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-1193" seq="1999-1193" severity="High" type="CVE" published="1991-05-14" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">The "me" user in NeXT NeXTstep 2.1 and earlier has wheel group privileges, which could allow the me user to use the su command to become root.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-1991-06.html" adv="1">CA-1991-06</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/581.php" adv="1">next-me(581)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/20">20</ref>
        </refs>
        <vuln_soft>
            <prod vendor="next" name="next">
                <vers num="2.1" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1123" seq="1999-1123" severity="High" type="CVE" published="1991-05-20" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">The installation of Sun Source (sunsrc) tapes allows local users to gain root privileges via setuid root programs (1) makeinstall or (2) winstall.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-1991-07.html" adv="1">CA-1991-07</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/582.php" adv="1">sun-sourcetapes(582)</ref>
            <ref source="SUN" patch="1" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/107&amp;type=0&amp;nav=sec.sba" adv="1">00107</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/22">22</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/21">21</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="sunos">
                <vers num="4.0.3" />
                <vers num="4.1" />
                <vers num="4.1.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1034" seq="1999-1034" severity="High" type="CVE" published="1991-05-23" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Vulnerability in login in AT&amp;T System V Release 4 allows local users to gain privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-1991-08.html" adv="1">CA-1991-08</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/23" adv="1">23</ref>
            <ref source="XF" url="http://xforce.iss.net/static/583.php">sysv-login(583)</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/b-28.shtml">B-28</ref>
        </refs>
        <vuln_soft>
            <prod vendor="att" name="svr4">
                <vers num="4.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-1999-1415" seq="1999-1415" severity="Medium" type="CVE" published="1991-08-23" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Vulnerability in /usr/bin/mail in DEC ULTRIX before 4.2 allows local users to gain privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-91.13.Ultrix.mail.vulnerability" adv="1">CA-91.13</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/27">27</ref>
        </refs>
        <vuln_soft>
            <prod vendor="digital" name="ultrix">
                <vers num="4.2" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-1090" seq="1999-1090" severity="High" type="CVE" published="1991-09-10" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">The default configuration of NCSA Telnet package for Macintosh and PC enables FTP, even though it does not include an "ftp=yes" line, which allows remote attackers to read and modify arbitrary files.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-1991-15.html" adv="1">CA-1991-15</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/1844.php" adv="1">ftp-ncsa(1844)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ncsa" name="telnet">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-0498" seq="1999-0498" severity="High" type="CVE" published="1991-09-27" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-09">
        <desc>
            <descript source="cve">TFTP is not running in a restricted directory, allowing a remote attacker to access sensitive information such as password files.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" user="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
    </entry>
    <entry CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" name="CVE-1999-1468" seq="1999-1468" severity="Medium" type="CVE" published="1991-10-22" CVSS_version="2.0 incomplete approximation" CVSS_score="6.2" modified="2008-09-10">
        <desc>
            <descript source="cve">rdist in various UNIX systems uses popen to execute sendmail, which allows local users to gain root privileges by modifying the IFS (Internal Field Separator) variable.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <race />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-91.20.rdist.vulnerability" adv="1">CA-91.20</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/31" adv="1">31</ref>
            <ref source="MISC" url="http://www.alw.nih.gov/Security/8lgm/8lgm-Advisory-01.html">http://www.alw.nih.gov/Security/8lgm/8lgm-Advisory-01.html</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/8106">8106</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/7160.php">rdist-popen-gain-privileges(7160)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="next" name="next">
                <vers num="2.0" />
                <vers num="2.1" />
            </prod>
            <prod vendor="cray" name="unicos">
                <vers num="6.0" />
                <vers num="6.0e" />
                <vers num="6.1" />
            </prod>
            <prod vendor="sgi" name="irix">
                <vers num="3.3" />
                <vers num="3.3.1" />
                <vers num="3.3.2" />
                <vers num="3.3.3" />
                <vers num="4.0" />
            </prod>
            <prod vendor="sun" name="sunos">
                <vers num="4.0.3" />
                <vers num="4.0.3c" />
                <vers num="4.1" />
                <vers num="4.1.1" />
                <vers num="4.1psr_a" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-1999-0167" seq="1999-0167" severity="Medium" type="CVE" published="1991-12-06" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-09">
        <desc>
            <descript source="cve">In SunOS, NFS file handles could be guessed, giving unauthorized access to the exported file system.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="sun" name="sunos">
                <vers num="4.1.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-1493" seq="1999-1493" severity="High" type="CVE" published="1991-12-18" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Vulnerability in crp in Hewlett Packard Apollo Domain OS SR10 through SR10.3 allows remote attackers to gain root privileges via insecure system calls, (1) pad_$dm_cmd and (2) pad_$def_pfk().</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-1991-23.html" adv="1">CA-1991-23</ref>
            <ref source="XF" url="http://xforce.iss.net/static/7158.php">apollo-crp-root-access(7158)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/34">34</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="apollo_domain_os">
                <vers num="sr10.3" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-1032" seq="1999-1032" severity="High" type="CVE" published="1991-12-31" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Vulnerability in LAT/Telnet Gateway (lattelnet) on Ultrix 4.1 and 4.2 allows attackers to gain root privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <env />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-1991-11.html" adv="1">CA-1991-11</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/26" adv="1">26</ref>
            <ref source="XF" url="http://xforce.iss.net/static/584.php">ultrix-telnet(584)</ref>
            <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/b-36.shtml">B-36</ref>
        </refs>
        <vuln_soft>
            <prod vendor="digital" name="ultrix">
                <vers num="4.1" />
                <vers num="4.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-1059" seq="1999-1059" severity="High" type="CVE" published="1992-02-25" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Vulnerability in rexec daemon (rexecd) in AT&amp;T TCP/IP 4.0 for various SVR4 systems allows remote attackers to execute arbitrary commands.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-1992-04.html" adv="1">CA-1992-04</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36">36</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/3159.php">att-rexecd(3159)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="att" name="svr4">
                <vers num="4.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)" CVSS_base_score="0.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="0.0" name="CVE-1999-0627" seq="1999-0627" severity="Low" type="CVE" published="1992-03-01" CVSS_version="2.0" CVSS_score="0.0" modified="2008-09-09">
        <desc>
            <descript source="cve">The rexd service is running, which uses weak authentication that can allow an attacker to execute commands.</descript>
        </desc>
        <impacts>
            <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
        </impacts>
        <sols>
            <sol source="nvd">The rexd service is an unsecured protocol for Internet facing systems and should only be used on a trusted network segment, otherwise disabled.  The software should be patched and configured properly.</sol>
        </sols>
        <vuln_types>
            <other />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="ibm" name="aix">
                <vers num="3.1" />
                <vers num="3.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1121" seq="1999-1121" severity="High" type="CVE" published="1992-03-19" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">The default configuration for UUCP in AIX before 3.2 allows local users to gain root privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-1992-06.html" adv="1">CA-1992-06</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/554.php" adv="1">ibm-uucp(554)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/38">38</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/891">891</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ibm" name="aix">
                <vers num="3.2" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0117" seq="1999-0117" severity="High" type="CVE" published="1992-03-31" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">AIX passwd allows local users to gain root access.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="ibm" name="aix">
                <vers num="3.1" />
                <vers num="3.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-1119" seq="1999-1119" severity="High" type="CVE" published="1992-04-27" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">FTP installation script anon.ftp in AIX insecurely configures anonymous FTP, which allows remote attackers to execute arbitrary commands.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-1992-09.html" adv="1">CA-1992-09</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/3154.php" adv="1">aix-anon-ftp(3154)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/41">41</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ibm" name="aix">
                <vers edition=":32-bit" num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1142" seq="1999-1142" severity="High" type="CVE" published="1992-05-27" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">SunOS 4.1.2 and earlier allows local users to gain privileges via "LD_*" environmental variables to certain dynamically linked setuid or setgid programs such as (1) login, (2) su, or (3) sendmail, that change the real and effective user ids to the same user.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-1992-11.html" adv="1">CA-1992-11</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/3152.php" adv="1">sun-env(3152)</ref>
            <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/116">00116</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="sunos">
                <vers num="4.1.2" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0168" seq="1999-0168" severity="High" type="CVE" published="1992-06-04" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">The portmapper may act as a proxy and redirect service requests from an attacker, making the request appear to come from the local host, possibly bypassing authentication that would otherwise have taken place.  For example, NFS file systems could be mounted through the portmapper despite export restrictions.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="sun" name="sunos">
                <vers num="4.1.3" />
                <vers num="4.1.3c" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-0214" seq="1999-0214" severity="High" type="CVE" published="1992-07-21" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Denial of service by sending forged ICMP unreachable packets.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="sun" name="sunos">
                <vers num="4.1" />
                <vers num="4.1.1" />
                <vers num="4.1.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1396" seq="1999-1396" severity="High" type="CVE" published="1992-07-21" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Vulnerability in integer multiplication emulation code on SPARC architectures for SunOS 4.1 through 4.1.2 allows local users to gain root access or cause a denial of service (crash).</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-1992-15.html" adv="1">CA-1992-15</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/49">49</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/7150.php">sun-integer-multiplication-access(7150)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="sunos">
                <vers num="4.1" />
                <vers num="4.1.1" />
                <vers num="4.1.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1395" seq="1999-1395" severity="High" type="CVE" published="1992-11-17" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2009-10-31">
        <desc>
            <descript source="cve">Vulnerability in Monitor utility (SYS$SHARE:SPISHR.EXE) in VMS 5.0 through 5.4-2 allows local users to gain privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-92.16.VMS.Monitor.vulnerability" adv="1">CA-92.16</ref>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-1992-18.html" adv="1">CA-1992-18</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/51">51</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/7136.php">vms-monitor-gain-privileges(7136)</ref>
            <ref source="OSVDB" url="http://osvdb.org/59332">59332</ref>
        </refs>
        <vuln_soft>
            <prod vendor="dec" name="dec_openvms">
                <vers num="5.0" />
                <vers num="5.0.1" />
                <vers num="5.0.2" />
                <vers num="5.1" />
                <vers num="5.1.1" />
                <vers num="5.1.2" />
                <vers num="5.1b" />
                <vers num="5.2" />
                <vers num="5.2.1" />
                <vers num="5.3" />
                <vers num="5.3.1" />
                <vers num="5.3.2" />
                <vers num="5.4" />
                <vers num="5.4.1" />
                <vers num="5.4.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-1306" seq="1999-1306" severity="High" type="CVE" published="1992-12-10" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Cisco IOS 9.1 and earlier does not properly handle extended IP access lists when the IP route cache is enabled and the "established" keyword is set, which could allow attackers to bypass filters.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-1992-20.html" adv="1">CA-1992-20</ref>
        </refs>
        <vuln_soft>
            <prod vendor="cisco" name="ios">
                <vers num="9.1" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-1466" seq="1999-1466" severity="High" type="CVE" published="1992-12-10" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Vulnerability in Cisco routers versions 8.2 through 9.1 allows remote attackers to bypass access control lists when extended IP access lists are used on certain interfaces, the IP route cache is enabled, and the access list uses the "established" keyword.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-1992-20.html" adv="1">CA-1992-20</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/53" adv="1">53</ref>
        </refs>
        <vuln_soft>
            <prod vendor="cisco" name="ios">
                <vers num="8.2" />
                <vers num="8.3" />
                <vers num="9.0" />
                <vers num="9.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1021" seq="1999-1021" severity="High" type="CVE" published="1992-12-30" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">NFS on SunOS 4.1 through 4.1.2 ignores the high order 16 bits in a 32 bit UID, which allows a local user to gain root access if the lower 16 bits are set to 0, as fixed by the NFS jumbo patch upgrade.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-1992-15.html" adv="1">CA-1992-15</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/47" adv="1">47</ref>
            <ref source="SUN" patch="1" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/117&amp;type=0&amp;nav=sec.sba">00117</ref>
            <ref source="XF" url="http://xforce.iss.net/static/82.php">nfs-uid(82)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="sunos">
                <vers num="4.1" />
                <vers num="4.1.1" />
                <vers num="4.1.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry reject="1" name="CVE-1999-1056" seq="1999-1056" type="CVE" published="1992-12-31" modified="2008-09-09">
        <desc>
            <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-1395.  Reason: This candidate is a duplicate of CVE-1999-1395.  Notes: All CVE users should reference CVE-1999-1395 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
        </desc>
        <refs />
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0312" seq="1999-0312" severity="Medium" type="CVE" published="1993-01-13" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">HP ypbind allows attackers with root privileges to modify NIS data.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1507" seq="1999-1507" severity="High" type="CVE" published="1993-02-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Sun SunOS 4.1 through 4.1.3 allows local attackers to gain root access via insecure permissions on files and directories such as crash.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-1993-03.html" adv="1">CA-1993-03</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/59" adv="1">59</ref>
            <ref source="XF" url="http://xforce.iss.net/static/521.php">sun-dir(521)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="sunos">
                <vers num="4.1" />
                <vers num="4.1.1" />
                <vers num="4.1.2" />
                <vers num="4.1.3" />
                <vers num="4.1.3c" />
                <vers num="4.1.3u1" />
                <vers num="4.1psr_a" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-1999-1218" seq="1999-1218" severity="Low" type="CVE" published="1993-02-18" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">Vulnerability in finger in Commodore Amiga UNIX 2.1p2a and earlier allows local users to read arbitrary files.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-1993-04.html" adv="1">CA-1993-04</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/522.php" adv="1">amiga-finger(522)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="commodore" name="amiga_unix">
                <vers num="2.1p2a" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1312" seq="1999-1312" severity="High" type="CVE" published="1993-02-24" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Vulnerability in DEC OpenVMS VAX 5.5-2 through 5.0, and OpenVMS AXP 1.0, allows local users to gain system privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-1993-05.html" adv="1">CA-1993-05</ref>
            <ref source="XF" url="http://xforce.iss.net/static/7142.php">openvms-local-privilege-elevation(7142)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="dec" name="dec_openvms_axp">
                <vers num="1.0" />
            </prod>
            <prod vendor="dec" name="dec_openvms_vax">
                <vers num="5.5.2" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-1216" seq="1999-1216" severity="High" type="CVE" published="1993-04-22" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Cisco routers 9.17 and earlier allow remote attackers to bypass security restrictions via certain IP source routed packets that should normally be denied using the "no ip source-route" command.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-1993-07.html" adv="1">CA-1993-07</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/541.php" adv="1">cisco-sourceroute(541)</ref>
            <ref source="CIAC" patch="1" url="http://ciac.llnl.gov/ciac/bulletins/d-15.shtml" adv="1">D-15</ref>
        </refs>
        <vuln_soft>
            <prod vendor="cisco" name="router">
                <vers num="8.2" />
                <vers num="8.3" />
                <vers num="9.0" />
                <vers num="9.1" />
                <vers num="9.17" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" name="CVE-1999-1162" seq="1999-1162" severity="Medium" type="CVE" published="1993-05-24" CVSS_version="2.0 incomplete approximation" CVSS_score="6.4" modified="2008-09-05">
        <desc>
            <descript source="cve">Vulnerability in passwd in SCO UNIX 4.0 and earlier allows attackers to cause a denial of service by preventing users from being able to log into the system.</descript>
        </desc>
        <loss_types>
            <avail />
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-1993-08.html" adv="1">CA-1993-08</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/542.php">sco-passwd-deny(542)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sco" name="open_desktop">
                <vers num="1.1" />
                <vers num="2.0" />
            </prod>
            <prod vendor="sco" name="unix">
                <vers num="4.0" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-0124" seq="1999-0124" severity="High" type="CVE" published="1993-08-09" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Vulnerabilities in UMN gopher and gopher+ versions 1.12 and 2.0x allow an intruder to read any files that can be accessed by the gopher daemon.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" user="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="university_of_minnesota" name="gopherd">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-1999-1215" seq="1999-1215" severity="Medium" type="CVE" published="1993-09-16" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">LOGIN.EXE program in Novell Netware 4.0 and 4.01 temporarily writes user name and password information to disk, which could allow local users to gain privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-1993-12.html" adv="1">CA-1993-12</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/545.php" adv="1">novell-login(545)</ref>
            <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/d-21.shtml">D-21</ref>
        </refs>
        <vuln_soft>
            <prod vendor="novell" name="netware">
                <vers num="4.0" />
                <vers num="4.01" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-1138" seq="1999-1138" severity="High" type="CVE" published="1993-09-17" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">SCO UNIX System V/386 Release 3.2, and other SCO products, installs the home directories (1) /tmp for the dos user, and (2) /usr/tmp for the asg user, which allows other users to gain access to those accounts since /tmp and /usr/tmp are world-writable.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" url="http://www.cert.org/advisories/CA-1993-13.html">CA-1993-13</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/546.php" adv="1">sco-homedir(546)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sco" name="open_desktop">
                <vers num="1.0" />
                <vers num="2.0" />
                <vers num="3.0" />
            </prod>
            <prod vendor="sco" name="open_desktop_lite">
                <vers num="3.0" />
            </prod>
            <prod vendor="sco" name="openserver">
                <vers num="3.0" />
            </prod>
            <prod vendor="sco" name="unix">
                <vers num="system_v386_3.2_operating_system" />
                <vers num="system_v386_3.2_operating_system_2.0" />
                <vers num="system_v386_3.2_operating_system_4.0" />
                <vers num="system_v386_3.2_operating_system_4.x" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1318" seq="1999-1318" severity="High" type="CVE" published="1993-09-17" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-10">
        <desc>
            <descript source="cve">/usr/5bin/su in SunOS 4.1.3 and earlier uses a search path that includes the current working directory (.), which allows local users to gain privileges via Trojan horse programs.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="SUNBUG" patch="1" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fpatches%2F100630&amp;zone_32=112193%2A%20" adv="1">1121935</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/7480.php">sun-su-path(7480)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers num="1.0" />
                <vers num="1.0.1" />
                <vers num="1.1" />
                <vers num="1.1c" />
            </prod>
            <prod vendor="sun" name="sunos">
                <vers num="4.1.1" />
                <vers num="4.1.2" />
                <vers num="4.1.3" prev="1" />
                <vers num="4.1.3c" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0145" seq="1999-0145" severity="High" type="CVE" published="1993-09-30" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">Sendmail WIZ command enabled, allowing root access.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT" url="http://www.cert.org/advisories/CA-1993-14.html">CA-1993-14</ref>
            <ref source="CERT" url="http://www.cert.org/advisories/CA-1990-11.html">CA-1990-11</ref>
            <ref source="BUGTRAQ" url="http://www2.dataguard.no/bugtraq/1995_1/0332.html">19950206 sendmail wizard thing...</ref>
            <ref source="FarmerVenema" url="http://www.alw.nih.gov/Security/Docs/admin-guide-to-cracking.101.html">Improving the Security of Your Site by Breaking Into it</ref>
        </refs>
        <vuln_soft>
            <prod vendor="eric_allman" name="sendmail">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-1999-1137" seq="1999-1137" severity="Low" type="CVE" published="1993-10-01" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">The permissions for the /dev/audio device on Solaris 2.2 and earlier, and SunOS 4.1.x, allow any local user to read from the device, which could be used by an attacker to monitor conversations happening near a machine that has a microphone.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/549.php" adv="1">sun-audio(549)</ref>
            <ref source="CIAC" patch="1" url="http://www.ciac.org/ciac/bulletins/e-01.shtml" adv="1">E-01</ref>
            <ref source="SUN" patch="1" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/122&amp;type=0&amp;nav=sec.sba" adv="1">00122</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/6436">6436</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers num="2.2" prev="1" />
            </prod>
            <prod vendor="sun" name="sunos">
                <vers num="4.1" />
                <vers num="5.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0334" seq="1999-0334" severity="High" type="CVE" published="1993-12-16" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">In Solaris 2.2 and 2.3, when fsck fails on startup, it allows a local user with physical access to obtain root access.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers edition=":x86" num="" />
                <vers num="2.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" name="CVE-1999-0181" seq="1999-0181" severity="Medium" type="CVE" published="1994-01-01" CVSS_version="2.0" CVSS_score="6.8" modified="2008-09-09">
        <desc>
            <descript source="cve">The wall daemon can be used for denial of service, social engineering attacks, or to execute remote commands.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="rpc.walld" name="rpc.walld">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-1999-1242" seq="1999-1242" severity="Medium" type="CVE" published="1994-02-07" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Vulnerability in subnetconfig in HP-UX 9.01 and 9.0 allows local users to gain privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/2162.php" adv="1">hp-subnet-config(2162)</ref>
            <ref source="HP" patch="1" url="http://packetstormsecurity.org/advisories/hpalert/003" adv="1">HPSBUX9402-003</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="9.00" />
                <vers num="9.01" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0211" seq="1999-0211" severity="Medium" type="CVE" published="1994-02-14" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Extra long export lists over 256 characters in some mount daemons allows NFS directories to be mounted by anyone.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/24">24</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers num="2.0" />
            </prod>
            <prod vendor="sun" name="sunos">
                <vers num="4.1.1" />
                <vers num="4.1.2" />
                <vers num="4.1.3" />
                <vers num="4.1.3c" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0338" seq="1999-0338" severity="High" type="CVE" published="1994-02-24" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">AIX Licensed Program Product performance tools allow local users to gain root access.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="ibm" name="aix">
                <vers num="3.2.4" />
                <vers num="3.2.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0120" seq="1999-0120" severity="High" type="CVE" published="1994-03-21" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">Sun/Solaris utmp file allows local users to gain root access if it is writable by users other than root.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/126">00126</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers num="1.1.1a" />
            </prod>
            <prod vendor="sun" name="sunos">
                <vers num="4.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1135" seq="1999-1135" severity="High" type="CVE" published="1994-04-20" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-10">
        <desc>
            <descript source="cve">Vulnerability in VUE 3.0 in HP 9.x allows local users to gain root privileges, as fixed by PHSS_4994 and PHSS_5438.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/2284.php" adv="1">hp-vue(2284)</ref>
            <ref source="HP" url="http://packetstorm.securify.com/advisories/hpalert/027">HPSBUX9504-027</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1146" seq="1999-1146" severity="High" type="CVE" published="1994-05-04" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Vulnerability in Glance and gpm programs in GlancePlus for HP-UX 9.x and earlier allows local users to access arbitrary files and gain privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/2060.php" adv="1">hp-glanceplus-gpm(2060)</ref>
            <ref source="HP" patch="1" url="http://www.securityfocus.com/advisories/1555" adv="1">HPSBUX9405-011</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="8" />
                <vers num="9" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" name="CVE-1999-1388" seq="1999-1388" severity="Medium" type="CVE" published="1994-05-13" CVSS_version="2.0 incomplete approximation" CVSS_score="6.2" modified="2008-09-05">
        <desc>
            <descript source="cve">passwd in SunOS 4.1.x allows local users to overwrite arbitrary files via a symlink attack and the -F command line argument.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <race />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BUGTRAQ" patch="1" url="http://www2.dataguard.no/bugtraq/1994_2/0207.html">19940514 [8lgm]-Advisory-7.UNIX.passwd.11-May-1994.NEWFIX</ref>
            <ref source="BUGTRAQ" patch="1" url="http://www2.dataguard.no/bugtraq/1994_2/0197.html" adv="1">19940513 [8lgm]-Advisory-7.UNIX.passwd.11-May-1994</ref>
            <ref source="BUGTRAQ" patch="1" url="http://www.dataguard.no/bugtraq/1994_4/0755.html" adv="1">19941218 Sun Patch Id #102060-01</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="sunos">
                <vers num="4.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1134" seq="1999-1134" severity="High" type="CVE" published="1994-05-18" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-10">
        <desc>
            <descript source="cve">Vulnerability in Vue 3.0 in HP 9.x allows local users to gain root privileges, as fixed by PHSS_4038, PHSS_4055, and PHSS_4066.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CIAC" patch="1" url="http://ciac.llnl.gov/ciac/bulletins/e-23.shtml" adv="1">E-23</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/2284.php">hp-vue(2284)</ref>
            <ref source="HP" url="http://packetstorm.securify.com/advisories/hpalert/008">HPSBUX9404-008</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-0113" seq="1999-0113" severity="High" type="CVE" published="1994-05-23" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Some implementations of rlogin allow root access if given a -froot parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/458">458</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ibm" name="aix">
                <vers num="3.1" />
                <vers num="3.2" />
                <vers num="3.2.4" />
                <vers num="3.2.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-1999-0423" seq="1999-0423" severity="Medium" type="CVE" published="1994-06-01" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-09">
        <desc>
            <descript source="cve">Vulnerability in hpterm on HP-UX 10.20 allows local users to gain additional privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <env />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-093">HPSBUX9903-093</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0337" seq="1999-0337" severity="High" type="CVE" published="1994-06-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">AIX batch queue (bsh) allows local and remote users to gain additional privileges when network printing is enabled.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="ibm" name="aix">
                <vers num="1.2.1" />
                <vers num="1.3" />
                <vers num="2.2.1" />
                <vers num="3.1" />
                <vers num="3.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0207" seq="1999-0207" severity="High" type="CVE" published="1994-06-09" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">Remote attacker can execute commands through Majordomo using the Reply-To field and a "lists" command.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="great_circle_associates" name="majordomo">
                <vers num="1.90" />
                <vers num="1.91" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-1999-1239" seq="1999-1239" severity="Medium" type="CVE" published="1994-07-13" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">HP-UX 9.x does not properly enable the Xauthority mechanism in certain conditions, which could allow local users to access the X display even when they have not explicitly been authorized to do so.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/2261.php" adv="1">hp-xauthority(2261)</ref>
            <ref source="HP" patch="1" url="http://www.securityfocus.com/advisories/1559" adv="1">HPSBUX9407-015</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1552" seq="1999-1552" severity="High" type="CVE" published="1994-07-20" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-10">
        <desc>
            <descript source="cve">dpsexec (DPS Server) when running under XDM in IBM AIX 3.2.5 and earlier does not properly check privileges, which allows local users to overwrite arbitrary files and gain privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" admin="1" />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/358" adv="1">358</ref>
            <ref source="BUGTRAQ" url="http://lists.insecure.org/lists/bugtraq/1994/Jul/0038.html">19940720 xnews and XDM</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ibm" name="aix">
                <vers num="3.1" />
                <vers num="3.2" />
                <vers num="3.2.4" />
                <vers num="3.2.5" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-1999-1494" seq="1999-1494" severity="Low" type="CVE" published="1994-08-09" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">colorview in Silicon Graphics IRIX 5.1, 5.2, and 6.0 allows local attackers to read arbitrary files via the -text argument.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/2112.php" adv="1">sgi-colorview(2112)</ref>
            <ref source="BUGTRAQ" patch="1" url="http://www.tryc.on.ca/archives/bugtraq/1995_1/0614.html" adv="1">19950307 sigh. another Irix 5.2 hole.</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/336" adv="1">336</ref>
            <ref source="SGI" patch="1" url="ftp://patches.sgi.com/support/free/security/advisories/19950209-01-P" adv="1">19950209-00-P</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/675" adv="1">19940809 Re: IRIX 5.2 Security Advisory</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sgi" name="irix">
                <vers num="5.1" />
                <vers num="5.1.1" />
                <vers num="5.2" />
                <vers num="6.0" />
                <vers num="6.0.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1219" seq="1999-1219" severity="High" type="CVE" published="1994-08-11" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Vulnerability in sgihelp in the SGI help system and print manager in IRIX 5.2 and earlier allows local users to gain root privileges, possibly through the clogin command.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <env />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-1994-13.html" adv="1">CA-1994-13</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/511.php" adv="1">sgi-prn-mgr(511)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/468" adv="1">468</ref>
            <ref source="CIAC" patch="1" url="http://ciac.llnl.gov/ciac/bulletins/e-33.shtml" adv="1">E-33</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sgi" name="irix">
                <vers num="5.1" />
                <vers num="5.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-1999-1238" seq="1999-1238" severity="Medium" type="CVE" published="1994-09-21" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Vulnerability in CORE-DIAG fileset in HP message catalog in HP-UX 9.05 and earlier allows local users to gain privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/2262.php" adv="1">hp-core-diag-fileset(2262)</ref>
            <ref source="HP" patch="1" url="http://www.securityfocus.com/advisories/1531" adv="1">HPSBUX9409-017</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="8" />
                <vers num="9" />
                <vers num="9.05" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" name="CVE-1999-1022" seq="1999-1022" severity="Medium" type="CVE" published="1994-10-02" CVSS_version="2.0 incomplete approximation" CVSS_score="6.2" modified="2008-09-05">
        <desc>
            <descript source="cve">serial_ports administrative program in IRIX 4.x and 5.x trusts the user's PATH environmental variable to find and execute the ls program, which allows local users to gain root privileges via a Trojan horse ls program.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <race />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/2111.php" adv="1">sgi-serialports(2111)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/464" adv="1">464</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/930" adv="1">19941002</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sgi" name="irix">
                <vers num="4" />
                <vers num="5.2" />
                <vers num="5.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry reject="1" name="CVE-1999-1310" seq="1999-1310" type="CVE" published="1994-11-04" modified="2008-09-10">
        <desc>
            <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-1022.  Reason: This candidate is a duplicate of CVE-1999-1022.  Notes: All CVE users should reference CVE-1999-1022 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
        </desc>
        <refs />
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1302" seq="1999-1302" severity="High" type="CVE" published="1994-11-30" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-10">
        <desc>
            <descript source="cve">Unspecified vulnerability in pt_chmod in SCO UNIX 4.2 and earlier allows local users to gain root access.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="SCO" patch="1" url="http://ciac.llnl.gov/ciac/bulletins/f-05.shtml" adv="1">94:001</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/7586">sco-pt_chmod(7586)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/8797">8797</ref>
            <ref source="CERT" url="http://ftp.cerias.purdue.edu/pub/advisories/cert/cert_bulletins/VB-94:01.sco">VB-94:01</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sco" name="open_desktop">
                <vers num="2.0" />
                <vers num="3.0" />
            </prod>
            <prod vendor="sco" name="open_desktop_lite">
                <vers num="3.0" />
            </prod>
            <prod vendor="sco" name="openserver_enterprise_system">
                <vers num="3.0" />
            </prod>
            <prod vendor="sco" name="openserver_network_system">
                <vers num="3.0" />
            </prod>
            <prod vendor="sco" name="unix">
                <vers num="3.2" />
                <vers num="4.0" />
                <vers num="4.1" />
                <vers num="4.2" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1303" seq="1999-1303" severity="High" type="CVE" published="1994-11-30" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-10">
        <desc>
            <descript source="cve">Vulnerability in prwarn in SCO UNIX 4.2 and earlier allows local users to gain root access.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CIAC" patch="1" url="http://ciac.llnl.gov/ciac/bulletins/f-05.shtml" adv="1">F-05</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sco" name="open_desktop">
                <vers num="2.0" />
                <vers num="3.0" />
            </prod>
            <prod vendor="sco" name="open_desktop_lite">
                <vers num="3.0" />
            </prod>
            <prod vendor="sco" name="openserver_enterprise_system">
                <vers num="3.0" />
            </prod>
            <prod vendor="sco" name="openserver_network_system">
                <vers num="3.0" />
            </prod>
            <prod vendor="sco" name="unix">
                <vers num="3.2" />
                <vers num="4.0" />
                <vers num="4.1" />
                <vers num="4.2" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1304" seq="1999-1304" severity="High" type="CVE" published="1994-11-30" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-10">
        <desc>
            <descript source="cve">Vulnerability in login in SCO UNIX 4.2 and earlier allows local users to gain root access.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="SCO" patch="1" url="http://ciac.llnl.gov/ciac/bulletins/f-05.shtml" adv="1">94:001</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sco" name="open_desktop">
                <vers num="2.0" />
                <vers num="3.0" />
            </prod>
            <prod vendor="sco" name="open_desktop_lite">
                <vers num="3.0" />
            </prod>
            <prod vendor="sco" name="openserver_enterprise_system">
                <vers num="3.0" />
            </prod>
            <prod vendor="sco" name="openserver_network_system">
                <vers num="3.0" />
            </prod>
            <prod vendor="sco" name="unix">
                <vers num="3.2" />
                <vers num="4.0" />
                <vers num="4.1" />
                <vers num="4.2" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1305" seq="1999-1305" severity="High" type="CVE" published="1994-11-30" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-10">
        <desc>
            <descript source="cve">Vulnerability in "at" program in SCO UNIX 4.2 and earlier allows local users to gain root access.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="SCO" patch="1" url="http://ciac.llnl.gov/ciac/bulletins/f-05.shtml" adv="1">94:001</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sco" name="open_desktop">
                <vers num="2.0" />
                <vers num="3.0" />
            </prod>
            <prod vendor="sco" name="open_desktop_lite">
                <vers num="3.0" />
            </prod>
            <prod vendor="sco" name="openserver_enterprise_system">
                <vers num="3.0" />
            </prod>
            <prod vendor="sco" name="openserver_network_system">
                <vers num="3.0" />
            </prod>
            <prod vendor="sco" name="unix">
                <vers num="3.2" />
                <vers num="4.0" />
                <vers num="4.1" />
                <vers num="4.2" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-1999-1248" seq="1999-1248" severity="Medium" type="CVE" published="1994-11-30" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Vulnerability in Support Watch (aka SupportWatch) in HP-UX 8.0 through 9.0 allows local users to gain privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/2058.php" adv="1">hp-supportwatch(2058)</ref>
            <ref source="HP" patch="1" url="http://packetstormsecurity.org/advisories/hpalert/019" adv="1">HPSBUX9411-019</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="8.00" />
                <vers num="8.02" />
                <vers num="8.06" />
                <vers num="9.00" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2000-0508" seq="2000-0508" severity="Medium" type="CVE" published="1994-12-19" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">rpc.lockd in Red Hat Linux 6.1 and 6.2 allows remote attackers to cause a denial of service via a malformed request.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/1372" adv="1">1372</ref>
            <ref source="BUGTRAQ" patch="1" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0073.html" adv="1">20000608 Remote DOS in linux rpc.lockd</ref>
            <ref source="XF" url="http://xforce.iss.net/static/5050.php">linux-lockd-remote-dos</ref>
        </refs>
        <vuln_soft>
            <prod vendor="debian" name="debian_linux">
                <vers num="2.1" />
                <vers num="2.2" />
            </prod>
            <prod vendor="mandrakesoft" name="mandrake_linux">
                <vers num="6.0" />
                <vers num="6.1" />
                <vers num="7.0" />
            </prod>
            <prod vendor="redhat" name="linux">
                <vers num="6.0" />
                <vers num="6.1" />
                <vers num="6.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0077" seq="1999-0077" severity="Medium" type="CVE" published="1995-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Predictable TCP sequence numbers allow spoofing.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/139.php" adv="1">tcp-seq-predict(139)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="windows_nt">
                <vers num="4.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-0232" seq="1999-0232" severity="High" type="CVE" published="1995-02-01" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow in NCSA WebServer (version 1.5c) gives remote access.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-0235" seq="1999-0235" severity="High" type="CVE" published="1995-02-17" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow in NCSA WebServer (1.4.1 and below) gives remote access.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="ncsa" name="ncsa_web_server">
                <vers num="1.3" />
                <vers num="1.4" />
                <vers num="1.4.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0242" seq="1999-0242" severity="High" type="CVE" published="1995-03-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">Remote attackers can access mail files via POP3 in some Linux systems that are using shadow passwords.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="slackware" name="slackware_linux">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-1098" seq="1999-1098" severity="Medium" type="CVE" published="1995-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Vulnerability in BSD Telnet client with encryption and Kerberos 4 authentication allows remote attackers to decrypt the session via sniffing.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-1995-03.html" adv="1">CA-1995-03</ref>
            <ref source="CIAC" patch="1" url="http://www.ciac.org/ciac/bulletins/f-12.shtml" adv="1">F-12</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4881">4881</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/516.php">bsd-telnet(516)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="bsd" name="bsd">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-1999-1243" seq="1999-1243" severity="Medium" type="CVE" published="1995-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">SGI Desktop Permissions Tool in IRIX 6.0.1 and earlier allows local users to modify permissions for arbitrary files and gain privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/2113.php" adv="1">sgi-permissions(2113)</ref>
            <ref source="CIAC" patch="1" url="http://ciac.llnl.gov/ciac/bulletins/f-16.shtml" adv="1">F-16</ref>
            <ref source="SGI" patch="1" url="ftp://patches.sgi.com/support/free/security/advisories/19950301-01-P373" adv="1">19950301-01-P373</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sgi" name="irix">
                <vers num="5.2" />
                <vers num="6.0" />
                <vers num="6.0.1" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" name="CVE-1999-0151" seq="1999-0151" severity="High" type="CVE" published="1995-04-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.6" modified="2008-09-09">
        <desc>
            <descript source="cve">The SATAN session key may be disclosed if the user points the web browser to other sites, possibly allowing root access.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="satan" name="satan">
                <vers num="1.0" />
                <vers num="1.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1080" seq="1999-1080" severity="High" type="CVE" published="1995-05-10" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">rmmount in SunOS 5.7 may mount file systems without the nosuid flag set, contrary to the documentation and its use in previous versions of SunOS, which could allow local users with physical access to gain root privileges by mounting a floppy or CD-ROM that contains a setuid program and running volcheck, when the file systems do not have the nosuid option specified in rmmount.conf.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92633694100270&amp;w=2" adv="1">19990510 SunOS 5.7 rmmount, no nosuid.</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93971288323395&amp;w=2" adv="1">19991011</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/8350">solaris-rmmount-gain-root(8350)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/250">250</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="sunos">
                <vers num="5.7" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0161" seq="1999-0161" severity="High" type="CVE" published="1995-07-31" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">In Cisco IOS 10.3, with the tacacs-ds or tacacs keyword, an extended IP access control list could bypass filtering.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="OSVDB" url="http://www.osvdb.org/797">797</ref>
        </refs>
        <vuln_soft>
            <prod vendor="cisco" name="ios">
                <vers num="10.3(3.4)" />
                <vers num="10.3(4.2)" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0066" seq="1999-0066" severity="High" type="CVE" published="1995-07-31" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">AnyForm CGI remote execution.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/719">719</ref>
        </refs>
        <vuln_soft>
            <prod vendor="john_s._roberts" name="anyform">
                <vers num="1.0" />
                <vers num="2.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0172" seq="1999-0172" severity="High" type="CVE" published="1995-08-02" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">FormMail CGI program allows remote execution of commands.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="matt_wright" name="formmail">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-0203" seq="1999-0203" severity="High" type="CVE" published="1995-08-17" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-09">
        <desc>
            <descript source="cve">In Sendmail, attackers can gain root privileges via SMTP by specifying an improper "mail from" address and an invalid "rcpt to" address that would cause the mail to bounce to a program.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="eric_allman" name="sendmail">
                <vers num="8.6.10" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1580" seq="1999-1580" severity="High" type="CVE" published="1995-08-23" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">SunOS sendmail 5.59 through 5.65 uses popen to process a forwarding host argument, which allows local users to gain root privileges by modifying the IFS (Internal Field Separator) variable and passing crafted values to the -oR option.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-95.11.sun.sendmail-oR.vul" adv="1">CA-1995-11</ref>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/3278" adv="1">VU#3278</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/7829">7829</ref>
            <ref source="AUSCERT" url="http://www.auscert.org.au/render.html?it=1853&amp;cid=1978" adv="1">AA-95.09</ref>
            <ref source="MISC" url="http://www.alw.nih.gov/Security/8lgm/8lgm-Advisory-21.html">http://www.alw.nih.gov/Security/8lgm/8lgm-Advisory-21.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sendmail" name="sendmail">
                <vers num="5.59" />
                <vers num="5.61" />
                <vers num="5.65" />
            </prod>
            <prod vendor="sun" name="sunos">
                <vers num="4.1.1" />
                <vers num="4.1.2" />
                <vers num="4.1.3" />
                <vers num="4.1.3c" />
                <vers num="4.1.3u1" />
                <vers num="4.1.4" />
                <vers num="4.1.4jl" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" name="CVE-1999-0164" seq="1999-0164" severity="Medium" type="CVE" published="1995-08-29" CVSS_version="2.0 incomplete approximation" CVSS_score="6.2" modified="2008-09-09">
        <desc>
            <descript source="cve">A race condition in the Solaris ps command allows an attacker to overwrite critical files.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <race />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="OSVDB" url="http://www.osvdb.org/8346">8346</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="sunos">
                <vers num="5.3" />
                <vers edition="" num="5.4" />
                <vers edition=":x86" num="5.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0155" seq="1999-0155" severity="High" type="CVE" published="1995-08-31" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">The ghostscript command with the -dSAFER option allows remote attackers to execute commands.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="aladdin_enterprises" name="ghostscript">
                <vers num="2.6" />
                <vers num="3.22" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-1999-0245" seq="1999-0245" severity="Medium" type="CVE" published="1995-09-07" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-09">
        <desc>
            <descript source="cve">Some configurations of NIS+ in Linux allowed attackers to log in as the user "+".</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
            <config />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="linux" name="linux_kernel">
                <vers num="2.6.20.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0218" seq="1999-0218" severity="Medium" type="CVE" published="1995-10-01" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Livingston portmaster machines could be rebooted via a series of commands.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="livingston_portmaster" name="portmaster">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-0073" seq="1999-0073" severity="High" type="CVE" published="1995-10-13" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Telnet allows a remote client to specify environment variables including LD_LIBRARY_PATH, allowing an attacker to bypass the normal system libraries and gain root access.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="digital" name="osf_1">
                <vers num="1.2" />
                <vers num="1.3" />
                <vers num="2.0" />
                <vers num="3.0" />
                <vers num="3.2" />
            </prod>
            <prod vendor="digital" name="unix">
                <vers num="3.2g" />
                <vers num="4.0" />
            </prod>
            <prod vendor="sgi" name="irix">
                <vers num="5.0" />
                <vers num="5.0.1" />
                <vers num="5.1" />
                <vers num="5.1.1" />
                <vers num="5.2" />
                <vers edition="" num="5.3" />
                <vers edition=":xfs" num="5.3" />
                <vers num="6.0" />
                <vers edition="" num="6.0.1" />
                <vers edition=":xfs" num="6.0.1" />
                <vers num="6.1" />
                <vers num="6.2" />
                <vers num="6.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-0099" seq="1999-0099" severity="High" type="CVE" published="1995-10-19" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow in syslog utility allows local or remote attackers to gain root privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="bsdi" name="bsd_os">
                <vers num="2.0" />
                <vers num="2.0.1" />
            </prod>
            <prod vendor="convex" name="convexos">
                <vers num="10.1" />
                <vers num="10.2" />
                <vers num="11.0" />
                <vers num="11.1" />
            </prod>
            <prod vendor="convex" name="spp-ux">
                <vers num="3" />
            </prod>
            <prod vendor="cray" name="unicos">
                <vers num="8.0" />
                <vers num="8.3" />
                <vers num="9.0" />
            </prod>
            <prod vendor="ibm" name="aix">
                <vers num="3.2" />
                <vers num="4.1" />
            </prod>
            <prod vendor="sun" name="solaris">
                <vers num="2.3" />
                <vers edition="" num="2.4" />
                <vers edition=":x86" num="2.4" />
            </prod>
            <prod vendor="sun" name="sunos">
                <vers num="4.1.3" />
                <vers num="4.1.3u1" />
                <vers num="4.1.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-0241" seq="1999-0241" severity="High" type="CVE" published="1995-11-01" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="xfree86_project" name="x11r6">
                <vers num="" />
            </prod>
            <prod vendor="sgi" name="irix">
                <vers num="" />
            </prod>
            <prod vendor="sun" name="solaris">
                <vers edition="" num="2.5" />
                <vers edition=":x86" num="2.5" />
                <vers edition="" num="2.5.1" />
                <vers edition=":x86" num="2.5.1" />
                <vers edition="" num="2.6" />
                <vers edition=":x86" num="2.6" />
                <vers edition="" num="7.0" />
                <vers edition=":x86" num="7.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-0080" seq="1999-0080" severity="High" type="CVE" published="1995-11-30" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Certain configurations of wu-ftp FTP server 2.4 use a _PATH_EXECPATH setting to a directory with dangerous commands, such as /bin, which allows remote authenticated users to gain root access via the "site exec" command.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="washington_university" name="wu-ftpd">
                <vers num="2.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" name="CVE-1999-0123" seq="1999-0123" severity="Low" type="CVE" published="1995-12-01" CVSS_version="2.0 incomplete approximation" CVSS_score="3.7" modified="2008-09-05">
        <desc>
            <descript source="cve">Race condition in Linux mailx command allows local users to read user files.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <race />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="slackware" name="slackware_linux">
                <vers num="3.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0325" seq="1999-0325" severity="High" type="CVE" published="1995-12-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">vhe_u_mnt program in HP-UX allows local users to create root files through symlinks.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9406-013">HPSBUX9406-013</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="8" />
                <vers num="9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0316" seq="1999-0316" severity="High" type="CVE" published="1995-12-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow in Linux splitvt command gives root access to local users.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="sam_lantinga" name="splitvt">
                <vers num="1.6.3" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-0208" seq="1999-0208" severity="High" type="CVE" published="1995-12-12" CVSS_version="2.0" CVSS_score="10.0" modified="2008-09-09">
        <desc>
            <descript source="cve">rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="ibm" name="aix">
                <vers num="3.2" />
                <vers num="4.1" />
            </prod>
            <prod vendor="nec" name="asl_ux_4800">
                <vers num="" />
            </prod>
            <prod vendor="nec" name="ews-ux_v">
                <vers num="" />
            </prod>
            <prod vendor="nec" name="up-ux_v">
                <vers num="" />
            </prod>
            <prod vendor="sgi" name="irix">
                <vers num="3" />
                <vers num="4" />
                <vers num="5.0" />
                <vers num="5.1" />
                <vers num="5.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1186" seq="1999-1186" severity="High" type="CVE" published="1996-01-02" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">rxvt, when compiled with the PRINT_PIPE option in various Linux operating systems including Linux Slackware 3.0 and RedHat 2.1, allows local users to gain root privileges by specifying a malicious program using the -print-pipe command line parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167418966&amp;w=2" adv="1">19960102 rxvt security hole</ref>
        </refs>
        <vuln_soft>
            <prod vendor="rxvt" name="rxvt">
                <vers num="" />
            </prod>
            <prod vendor="redhat" name="linux">
                <vers num="2.1" />
            </prod>
            <prod vendor="slackware" name="slackware_linux">
                <vers num="3.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-1319" seq="1999-1319" severity="High" type="CVE" published="1996-01-03" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Vulnerability in object server program in SGI IRIX 5.2 through 6.1 allows remote attackers to gain root privileges in certain configurations.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SGI" patch="1" url="ftp://patches.sgi.com/support/free/security/advisories/19960101-01-PX" adv="1">19960101-01-PX</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/7430.php">irix-object-server(7430)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sgi" name="irix">
                <vers num="5" />
                <vers num="5.2" />
                <vers num="6.0" />
                <vers num="6.1" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1491" seq="1999-1491" severity="High" type="CVE" published="1996-02-02" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">abuse.console in Red Hat 2.1 uses relative pathnames to find and execute the undrv program, which allows local users to execute arbitrary commands via a path that points to a Trojan horse program.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <access />
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/354" adv="1">354</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167418994&amp;w=2" adv="1">19960202 abuse Red Hat 2.1 security hole</ref>
        </refs>
        <vuln_soft>
            <prod vendor="redhat" name="linux">
                <vers num="2.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0103" seq="1999-0103" severity="Medium" type="CVE" published="1996-02-08" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Echo and chargen, or other combinations of UDP services, can be used in tandem to flood the server, a.k.a. UDP bomb or UDP packet storm.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-1999-0143" seq="1999-0143" severity="Medium" type="CVE" published="1996-02-21" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-09">
        <desc>
            <descript source="cve">Kerberos 4 key servers allow a user to masquerade as another by breaking and generating session keys.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="mit" name="kerberos">
                <vers num="4.0" />
                <vers num="5" />
            </prod>
            <prod vendor="process_software" name="multinet">
                <vers num="3.4" />
                <vers num="3.5" />
            </prod>
            <prod vendor="sun" name="solaris">
                <vers num="2.3" />
                <vers num="2.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-0233" seq="1999-0233" severity="High" type="CVE" published="1996-02-25" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-09">
        <desc>
            <descript source="cve">IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <access />
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q155056">Q155056</ref>
            <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q148188">Q148188</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="internet_information_server">
                <vers num="1.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0142" seq="1999-0142" severity="High" type="CVE" published="1996-03-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">The Java Applet Security Manager implementation in Netscape Navigator 2.0 and Java Developer's Kit 1.0 allows an applet to connect to arbitrary hosts.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="netscape" name="navigator">
                <vers num="" />
            </prod>
            <prod vendor="sun" name="java">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-0067" seq="1999-0067" severity="High" type="CVE" published="1996-03-20" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-09">
        <desc>
            <descript source="cve">phf CGI program allows remote command execution through shell metacharacters.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" url="http://www.cert.org/advisories/CA-1996-06.html">CA-1996-06</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/629">629</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/136">136</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apache" name="http_server">
                <vers num="1.0.3" />
            </prod>
            <prod vendor="ncsa" name="ncsa_httpd">
                <vers edition="" num="1.5a" />
                <vers edition=":export" num="1.5a" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" name="CVE-1999-0141" seq="1999-0141" severity="Low" type="CVE" published="1996-03-29" CVSS_version="2.0 incomplete approximation" CVSS_score="3.7" modified="2008-09-09">
        <desc>
            <descript source="cve">Java Bytecode Verifier allows malicious applets to execute arbitrary commands as the user of the applet.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <local />
            <user_init />
        </range>
        <refs>
            <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/134">00134</ref>
        </refs>
        <vuln_soft>
            <prod vendor="netscape" name="navigator">
                <vers num="2.02" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0070" seq="1999-0070" severity="Medium" type="CVE" published="1996-04-01" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">test-cgi program allows an attacker to list files on the server.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="apache" name="http_server">
                <vers num="" />
            </prod>
            <prod vendor="ncsa" name="ncsa_web_server">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-1999-1103" seq="1999-1103" severity="Medium" type="CVE" published="1996-04-03" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">dxconsole in DEC OSF/1 3.2C and earlier allows local users to read arbitrary files by specifying the file with the -file parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/vendor_bulletins/VB-96.05.dec" adv="1">VB-96.05</ref>
            <ref source="CIAC" patch="1" url="http://ciac.llnl.gov/ciac/bulletins/g-18.shtml" adv="1">G-18</ref>
            <ref source="MISC" url="http://www.tao.ca/fire/bos/0209.html">http://www.tao.ca/fire/bos/0209.html</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/7138.php">osf-dxconsole-gain-privileges(7138)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="digital" name="osf_1">
                <vers num="3.2c" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)" CVSS_base_score="1.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="2.9" name="CVE-1999-0078" seq="1999-0078" severity="Low" type="CVE" published="1996-04-18" CVSS_version="2.0" CVSS_score="1.9" modified="2008-09-09">
        <desc>
            <descript source="cve">pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="ncr" name="mp-ras">
                <vers num="2.03" />
                <vers num="3.0" />
                <vers num="3.01" />
            </prod>
            <prod vendor="bsdi" name="bsd_os">
                <vers num="" />
            </prod>
            <prod vendor="freebsd" name="freebsd">
                <vers edition="stable" num="6.2" />
            </prod>
            <prod vendor="hp" name="hp-ux">
                <vers num="" />
            </prod>
            <prod vendor="ibm" name="aix">
                <vers num="3.2" />
                <vers num="4.1" />
                <vers num="4.2" />
            </prod>
            <prod vendor="nec" name="up-ux_v">
                <vers num="" />
            </prod>
            <prod vendor="next" name="nextstep">
                <vers num="" />
            </prod>
            <prod vendor="sco" name="openserver">
                <vers num="5" />
            </prod>
            <prod vendor="sco" name="unixware">
                <vers num="2.1" />
            </prod>
            <prod vendor="sgi" name="irix">
                <vers num="5.3" />
            </prod>
            <prod vendor="sun" name="solaris">
                <vers num="2.4" />
                <vers num="2.5" />
            </prod>
            <prod vendor="sun" name="sunos">
                <vers num="4.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0019" seq="1999-0019" severity="Medium" type="CVE" published="1996-04-24" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Delete or create a file via rpc.statd, due to invalid information.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/135">00135</ref>
        </refs>
        <vuln_soft>
            <prod vendor="data_general" name="dg_ux">
                <vers num="4.11" />
            </prod>
            <prod vendor="ncr" name="mp-ras">
                <vers num="2.03" />
                <vers num="3.0" />
            </prod>
            <prod vendor="ibm" name="aix">
                <vers num="3.2" />
                <vers num="4.1" />
            </prod>
            <prod vendor="nighthawk" name="cx_ux">
                <vers num="" />
            </prod>
            <prod vendor="nighthawk" name="powerux">
                <vers num="" />
            </prod>
            <prod vendor="sco" name="open_desktop">
                <vers num="2" />
                <vers num="3" />
            </prod>
            <prod vendor="sco" name="openserver">
                <vers num="3.0" />
                <vers num="5.0" />
            </prod>
            <prod vendor="sco" name="unixware">
                <vers num="2" />
            </prod>
            <prod vendor="sgi" name="irix">
                <vers num="6.1" />
            </prod>
            <prod vendor="sun" name="sunos">
                <vers num="4.1.3" />
                <vers num="4.1.4" />
                <vers num="5.3" />
                <vers edition="" num="5.4" />
                <vers edition=":x86" num="5.4" />
                <vers edition="" num="5.5" />
                <vers edition=":x86" num="5.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-1999-1314" seq="1999-1314" severity="Low" type="CVE" published="1996-05-17" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-10">
        <desc>
            <descript source="cve">Vulnerability in union file system in FreeBSD 2.2 and earlier, and possibly other operating systems, allows local users to cause a denial of service (system reload) via a series of certain mount_union commands.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="FREEBSD" patch="1" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-96:10.mount_union.asc" adv="1">FreeBSD-SA-96:10</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/7429.php">unionfs-mount-ordering(7429)</ref>
            <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/g-24.shtml">G-24</ref>
        </refs>
        <vuln_soft>
            <prod vendor="freebsd" name="freebsd">
                <vers num="2.0" />
                <vers num="2.0.5" />
                <vers edition="stable" num="2.1" />
                <vers num="2.1.0" />
                <vers edition="current" num="2.2" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-1999-1313" seq="1999-1313" severity="Medium" type="CVE" published="1996-05-23" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Manual page reader (man) in FreeBSD 2.2 and earlier allows local users to gain privileges via a sequence of commands.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CIAC" patch="1" url="http://ciac.llnl.gov/ciac/bulletins/g-24.shtml" adv="1">G-24</ref>
            <ref source="FREEBSD" patch="1" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-96:11.man.asc" adv="1">FreeBSD-SA-96:11</ref>
            <ref source="XF" url="http://xforce.iss.net/static/7348.php">bsd-man-command-sequence(7348)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="freebsd" name="freebsd">
                <vers num="2.0" />
                <vers num="2.0.5" />
                <vers num="2.1.0" />
                <vers num="2.2" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0522" seq="1999-0522" severity="High" type="CVE" published="1996-05-28" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">The permissions for a system-critical NIS+ table (e.g. passwd) are inappropriate.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" user="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-0509" seq="1999-0509" severity="High" type="CVE" published="1996-05-29" CVSS_version="2.0" CVSS_score="10.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Perl, sh, csh, or other shell interpreters are installed in the cgi-bin directory on a WWW site, which allows remote attackers to execute arbitrary commands.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1253" seq="1999-1253" severity="High" type="CVE" published="1996-06-07" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Vulnerability in a kernel error handling routine in SCO OpenServer 5.0.2 and earlier, and SCO Internet FastStart 1.0, allows local users to gain root privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/vendor_bulletins/VB-96.10.sco" adv="1">VB-96.10</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/1965.php" adv="1">sco-kernel(1965)</ref>
            <ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB.96:01a">96:001</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sco" name="internet_faststart">
                <vers num="1.0" />
            </prod>
            <prod vendor="sco" name="openserver">
                <vers num="5.0" />
                <vers num="5.0.2" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-1999-1205" seq="1999-1205" severity="Low" type="CVE" published="1996-06-07" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">nettune in HP-UX 10.01 and 10.00 is installed setuid root, which allows local users to cause a denial of service by modifying critical networking configuration information.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="HP" patch="1" url="http://packetstormsecurity.org/advisories/ibm-ers/96-08" adv="1">HPSBUX9607-035</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167419195&amp;w=2" adv="1">19960607 HP-UX B.10.01 vulnerability</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/414">hp-nettune(414)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="10.00" />
                <vers num="10.01" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0138" seq="1999-0138" severity="High" type="CVE" published="1996-06-26" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="apple" name="a_ux">
                <vers num="3.1.1" />
            </prod>
            <prod vendor="digital" name="osf_1">
                <vers num="1.3" />
            </prod>
            <prod vendor="freebsd" name="freebsd">
                <vers num="2.0" />
                <vers num="2.0.5" />
                <vers num="2.1.0" />
            </prod>
            <prod vendor="hp" name="hp-ux">
                <vers num="10" />
                <vers num="8" />
                <vers num="9" />
            </prod>
            <prod vendor="ibm" name="aix">
                <vers num="3.2.5" />
                <vers num="4" />
            </prod>
            <prod vendor="linux" name="linux_kernel">
                <vers num="1.2.0" />
                <vers num="2.0" />
            </prod>
            <prod vendor="nec" name="asl_ux_4800">
                <vers num="" />
            </prod>
            <prod vendor="nec" name="ews-ux_v">
                <vers num="4.2" />
                <vers num="4.2mp" />
            </prod>
            <prod vendor="nec" name="up-ux_v">
                <vers num="4.2mp" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0175" seq="1999-0175" severity="Medium" type="CVE" published="1996-07-01" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">The convert.bas program in the Novell web server allows a remote attackers to read any file on the system that is internally accessible by the web server.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="novell" name="web_server">
                <vers num="1.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0022" seq="1999-0022" severity="High" type="CVE" published="1996-07-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">Local user gains root privileges via buffer overflow in rdist, via expstr() function.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/179">00179</ref>
        </refs>
        <vuln_soft>
            <prod vendor="bsdi" name="bsd_os">
                <vers num="1.1" />
            </prod>
            <prod vendor="freebsd" name="freebsd">
                <vers num="2.0" />
                <vers num="2.0.5" />
                <vers num="2.1.0" />
            </prod>
            <prod vendor="hp" name="hp-ux">
                <vers num="10.00" />
            </prod>
            <prod vendor="ibm" name="aix">
                <vers num="3.1" />
                <vers num="3.2" />
                <vers num="3.2.4" />
                <vers num="3.2.5" />
                <vers num="4.1" />
                <vers num="4.1.1" />
                <vers num="4.1.2" />
                <vers num="4.1.3" />
                <vers num="4.1.4" />
                <vers num="4.1.5" />
                <vers num="4.2" />
            </prod>
            <prod vendor="sgi" name="irix">
                <vers num="5.0" />
                <vers num="5.0.1" />
                <vers num="5.1" />
                <vers num="5.1.1" />
                <vers num="5.2" />
                <vers edition="" num="5.3" />
                <vers edition=":xfs" num="5.3" />
                <vers num="6.0" />
                <vers edition="" num="6.0.1" />
                <vers edition=":xfs" num="6.0.1" />
                <vers num="6.1" />
                <vers num="6.2" />
                <vers num="6.3" />
                <vers num="6.4" />
            </prod>
            <prod vendor="sun" name="solaris">
                <vers num="2.0" />
                <vers num="2.1" />
                <vers num="2.2" />
                <vers num="2.3" />
                <vers num="2.4" />
                <vers num="4.1.1" />
                <vers num="4.1.2" />
                <vers edition="u1" num="4.1.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0137" seq="1999-0137" severity="High" type="CVE" published="1996-07-09" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">The dip program on many Linux systems allows local users to gain root access via a buffer overflow.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="fred_n._van_kempen" name="dip">
                <vers num="3.3.7o" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-1301" seq="1999-1301" severity="High" type="CVE" published="1996-07-16" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">A design flaw in the Z-Modem protocol allows the remote sender of a file to execute arbitrary programs on the client, as implemented in rz in the rzsz module of FreeBSD before 2.1.5, and possibly other programs.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CIAC" patch="1" url="http://ciac.llnl.gov/ciac/bulletins/g-31.shtml" adv="1">G-31</ref>
            <ref source="FREEBSD" patch="1" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-96:17.rzsz.asc" adv="1">FreeBSD-SA-96:17</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/7540.php">rzsz-command-execution(7540)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="freebsd" name="freebsd">
                <vers num="2.1.5" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-1999-1572" seq="1999-1572" severity="Low" type="CVE" published="1996-07-16" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-10">
        <desc>
            <descript source="cve">cpio on FreeBSD 2.1.0, Debian GNU/Linux 3.0, and possibly other operating systems, uses a 0 umask when creating files using the -O (archive) or -F options, which creates the files with mode 0666 and allows local users to read or overwrite those files.</descript>
        </desc>
        <sols>
            <sol source="nvd">Fixed in rev 1.3 of cpio/main.c.</sol>
        </sols>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19167">cpio-o-archive-insecure-permissions(19167)</ref>
            <ref source="TRUSTIX" url="http://www.trustix.org/errata/2005/0003/">2005-0003</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-080.html">RHSA-2005:080</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-073.html">RHSA-2005:073</ref>
            <ref source="MISC" url="http://www.freebsd.org/cgi/query-pr.cgi?pr=bin/1391">http://www.freebsd.org/cgi/query-pr.cgi?pr=bin/1391</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-664">DSA-664</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-806.html">RHSA-2005:806</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:032">MDKSA-2005:032</ref>
            <ref source="CONFIRM" url="http://support.avaya.com/elmodocs2/security/ASA-2005-212.pdf">http://support.avaya.com/elmodocs2/security/ASA-2005-212.pdf</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/17532">17532</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/17063">17063</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14357">14357</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110763404701519&amp;w=2">20050204 [USN-75-1] cpio vulnerability</ref>
        </refs>
        <vuln_soft>
            <prod vendor="debian" name="debian_linux">
                <vers num="3.0" />
            </prod>
            <prod vendor="freebsd" name="freebsd">
                <vers num="2.1.0" />
            </prod>
            <prod vendor="mandrakesoft" name="mandrake_linux">
                <vers num="10.0" />
                <vers num="10.1" />
                <vers num="9.2" />
                <vers num="cs2.1" />
                <vers num="cs3.0" />
            </prod>
            <prod vendor="redhat" name="enterprise_linux">
                <vers edition="" num="4.0" />
                <vers edition=":enterprise_server" num="4.0" />
                <vers edition=":workstation" num="4.0" />
                <vers edition=":advanced_server" num="4.0" />
            </prod>
            <prod vendor="redhat" name="enterprise_linux_desktop">
                <vers num="4.0" />
            </prod>
            <prod vendor="ubuntu" name="ubuntu_linux">
                <vers num="4.10" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0023" seq="1999-0023" severity="High" type="CVE" published="1996-07-24" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">Local user gains root privileges via buffer overflow in rdist, via lookup() function.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="inet" name="inet">
                <vers num="5.01" />
                <vers num="6.01" />
            </prod>
            <prod vendor="bsdi" name="bsd_os">
                <vers num="" />
            </prod>
            <prod vendor="freebsd" name="freebsd">
                <vers num="2.0" />
                <vers num="2.0.5" />
                <vers num="2.1.0" />
                <vers num="2.2" />
            </prod>
            <prod vendor="ibm" name="aix">
                <vers num="3.2" />
                <vers num="4.1" />
                <vers num="4.2" />
            </prod>
            <prod vendor="sco" name="internet_faststart">
                <vers num="1.0" />
            </prod>
            <prod vendor="sco" name="open_desktop">
                <vers num="2.0" />
                <vers num="3.0" />
            </prod>
            <prod vendor="sco" name="openserver">
                <vers num="2.0" />
                <vers num="5.0" />
                <vers num="5.0.2" />
            </prod>
            <prod vendor="sco" name="tcp_ip">
                <vers num="1.2.0" />
                <vers num="1.2.1" />
            </prod>
            <prod vendor="sco" name="unixware">
                <vers num="2.0" />
                <vers num="2.1" />
            </prod>
            <prod vendor="sun" name="solaris">
                <vers num="1.1" />
                <vers num="1.1.1a" />
                <vers num="1.1.2" />
                <vers num="2.3" />
                <vers num="2.4" />
                <vers num="2.5" />
                <vers num="2.5.1" />
            </prod>
            <prod vendor="sun" name="sunos">
                <vers num="4.1.3" />
                <vers num="4.1.3u1" />
                <vers num="4.1.4" />
                <vers num="5.3" />
                <vers num="5.4" />
                <vers num="5.5" />
                <vers num="5.5.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0135" seq="1999-0135" severity="High" type="CVE" published="1996-07-25" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">admintool in Solaris allows a local user to write to arbitrary files and gain root access.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers edition="" num="2.5" />
                <vers edition=":x86" num="2.5" />
                <vers edition="" num="2.5.1" />
                <vers edition=":x86" num="2.5.1" />
                <vers edition=":ppc" num="2.5.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0136" seq="1999-0136" severity="High" type="CVE" published="1996-07-31" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">Kodak Color Management System (KCMS) on Solaris allows a local user to write to arbitrary files and gain root access.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers num="2.5" />
                <vers num="2.5.1" />
            </prod>
            <prod vendor="sun" name="sunos">
                <vers edition="" num="5.5" />
                <vers edition=":x86" num="5.5" />
                <vers edition="" num="5.5.1" />
                <vers edition=":x86" num="5.5.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0335" seq="1999-0335" severity="High" type="CVE" published="1996-08-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">DEPRECATED.  This entry has been deprecated.  It is a duplicate of CVE-1999-0032.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="bsdi" name="bsd_os">
                <vers num="2.1" />
            </prod>
            <prod vendor="linux" name="linux_kernel">
                <vers num="2.6.20.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-1999-1413" seq="1999-1413" severity="Medium" type="CVE" published="1996-08-03" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which allows local users to overwrite or create files at higher privileges by causing a core dump, e.g. through dmesg.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/296" adv="1">296</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167419549&amp;w=2" adv="1">19960803 Exploiting Zolaris 2.4 ??  :)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers edition="" num="2.4" />
                <vers edition=":x86" num="2.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0134" seq="1999-0134" severity="High" type="CVE" published="1996-08-06" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">vold in Solaris 2.x allows local users to gain root access.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="OSVDB" url="http://www.osvdb.org/8159">8159</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="sunos">
                <vers edition="" num="5.4" />
                <vers edition=":x86" num="5.4" />
                <vers edition="" num="5.5" />
                <vers edition=":x86" num="5.5" />
                <vers edition="" num="5.5.1" />
                <vers edition=":x86" num="5.5.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-1999-0133" seq="1999-0133" severity="Low" type="CVE" published="1996-08-14" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-09">
        <desc>
            <descript source="cve">fm_fls license server for Adobe Framemaker allows local users to overwrite arbitrary files and gain root access.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="adobe" name="framemaker">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-1999-0132" seq="1999-0132" severity="Low" type="CVE" published="1996-08-15" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-09">
        <desc>
            <descript source="cve">Expreserve, as used in vi and ex, allows local users to overwrite arbitrary files and gain root access.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT" url="http://www.cert.org/advisories/CA-1996-19.html">CA-1996-19</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/401">expreserve(401)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/11723">11723</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="10" />
                <vers num="9" />
            </prod>
            <prod vendor="sun" name="solaris">
                <vers num="2.0" />
                <vers num="2.1" />
                <vers num="2.2" />
                <vers num="2.3" />
                <vers edition="" num="2.4" />
                <vers edition=":x86" num="2.4" />
            </prod>
            <prod vendor="sun" name="sunos">
                <vers num="4.1.1" />
                <vers num="4.1.2" />
                <vers num="4.1.3" />
                <vers num="4.1.3c" />
                <vers num="4.1.3u1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0085" seq="1999-0085" severity="High" type="CVE" published="1996-08-21" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow in rwhod on AIX and other operating systems allows remote attackers to execute arbitrary code via a UDP packet with a long hostname.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/119">rwhod(119)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/118">rwhod-vuln(118)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="freebsd" name="freebsd">
                <vers edition="stable" num="6.2" />
            </prod>
            <prod vendor="ibm" name="aix">
                <vers num="4.2" />
            </prod>
            <prod vendor="netbsd" name="netbsd">
                <vers num="2.0.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-1999-1187" seq="1999-1187" severity="Medium" type="CVE" published="1996-08-26" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Pine before version 3.94 allows local users to gain privileges via a symlink attack on a lockfile that is created when a user receives new mail.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/416.php" adv="1">pine-tmpfile(416)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167419803&amp;w=2" adv="1">19960826 [BUG] Vulnerability in PINE</ref>
        </refs>
        <vuln_soft>
            <prod vendor="university_of_washington" name="pine">
                <vers num="3.94" prev="1" />
            </prod>
            <prod vendor="freebsd" name="freebsd">
                <vers num="2.1.0" />
            </prod>
            <prod vendor="slackware" name="slackware_linux">
                <vers num="3.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1309" seq="1999-1309" severity="High" type="CVE" published="1996-08-30" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Sendmail before 8.6.7 allows local users to gain root access via a large value in the debug (-d) command line option.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-94.12.sendmail.vulnerabilities" adv="1">CA-1994-12</ref>
            <ref source="BUGTRAQ" url="http://www.dataguard.no/bugtraq/1994_1/0048.html" adv="1">19940315 Security problem in sendmail versions 8.x.x</ref>
            <ref source="BUGTRAQ" url="http://www.dataguard.no/bugtraq/1994_1/0042.html" adv="1">19940315 anyone know details?</ref>
            <ref source="BUGTRAQ" url="http://www.dataguard.no/bugtraq/1994_1/0040.html" adv="1">19940314 sendmail -d problem (OLD yet still here)</ref>
            <ref source="XF" url="http://xforce.iss.net/static/7155.php">sendmail-debug-gain-root(7155)</ref>
            <ref source="BUGTRAQ" url="http://www.dataguard.no/bugtraq/1994_1/0078.html">19940327 sendmail exploit script - resend</ref>
            <ref source="BUGTRAQ" url="http://www.dataguard.no/bugtraq/1994_1/0043.html">19940315 so...</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sendmail" name="sendmail">
                <vers num="8.6.7" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0324" seq="1999-0324" severity="High" type="CVE" published="1996-09-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">ppl program in HP-UX allows local users to create root files through symlinks.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9702-053">HPSBUX9702-053</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="10.00" />
                <vers num="10.01" />
                <vers num="10.10" />
                <vers num="10.20" />
                <vers num="9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1252" seq="1999-1252" severity="High" type="CVE" published="1996-09-04" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Vulnerability in a certain system call in SCO UnixWare 2.0.x and 2.1.0 allows local users to access arbitrary files and gain root privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/vendor_bulletins/VB-96.15.sco" adv="1">VB-96.15</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/1966.php" adv="1">sco-system-call(1966)</ref>
            <ref source="SCO" url="ftp://ftp.sco.COM/SSE/security_bulletins/SB.96:02a">96:002</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sco" name="unixware">
                <vers num="2.0.x" />
                <vers num="2.1.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0131" seq="1999-0131" severity="High" type="CVE" published="1996-09-11" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/717">717</ref>
        </refs>
        <vuln_soft>
            <prod vendor="eric_allman" name="sendmail">
                <vers num="8.6" />
                <vers num="8.7.1" />
                <vers num="8.7.2" />
                <vers num="8.7.3" />
                <vers num="8.7.4" />
                <vers num="8.7.5" />
            </prod>
            <prod vendor="bsdi" name="bsd_os">
                <vers num="2.1" />
            </prod>
            <prod vendor="digital" name="osf_1">
                <vers num="1.3.2" />
            </prod>
            <prod vendor="freebsd" name="freebsd">
                <vers num="2.1.5" />
            </prod>
            <prod vendor="hp" name="hp-ux">
                <vers num="10.01" />
                <vers num="10.10" />
                <vers num="10.20" />
            </prod>
            <prod vendor="ibm" name="aix">
                <vers num="3.2" />
                <vers num="4.1" />
                <vers num="4.2" />
            </prod>
            <prod vendor="redhat" name="linux">
                <vers num="3.0.3" />
            </prod>
            <prod vendor="sco" name="internet_faststart">
                <vers num="1.0" />
            </prod>
            <prod vendor="sco" name="openserver">
                <vers num="5.0" />
                <vers num="5.0.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-1999-1383" seq="1999-1383" severity="Medium" type="CVE" published="1996-09-13" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">(1) bash before 1.14.7, and (2) tcsh 6.05 allow local users to gain privileges via directory names that contain shell metacharacters (` back-tick), which can cause the commands enclosed in the directory name to be executed when the shell expands filenames using the \w option in the PS1 variable.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BUGTRAQ" patch="1" url="http://www.dataguard.no/bugtraq/1996_3/0503.html" adv="1">19960919 Vulnerability in expansion of PS1 in bash &amp; tcsh</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167419868&amp;w=2">19960913 tee see shell problems</ref>
        </refs>
        <vuln_soft>
            <prod vendor="bash" name="bash">
                <vers num="1.14.7" prev="1" />
            </prod>
            <prod vendor="tcsh" name="tcsh">
                <vers num="6.05" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-1999-1295" seq="1999-1295" severity="Medium" type="CVE" published="1996-09-17" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Transarc DCE Distributed File System (DFS) 1.1 for Solaris 2.4 and 2.5 does not properly initialize the grouplist for users who belong to a large number of groups, which could allow those users to gain access to resources that are protected by DFS.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/vendor_bulletins/VB-96.16.transarc" adv="1">VB-96.16</ref>
            <ref source="CERT" url="http://www.cert.org/vendor_bulletins/VB-96.16.transarc">VB-96.16</ref>
            <ref source="XF" url="http://xforce.iss.net/static/7154.php">dfs-login-groups(7154)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="transarc" name="dce_distributed_file_system">
                <vers num="1.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0116" seq="1999-0116" severity="Medium" type="CVE" published="1996-09-19" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Denial of service when an attacker sends many SYN packets to create multiple connections without ever sending an ACK to complete the connection, aka SYN flood.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/136">00136</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19961202-01-PX">19961202-01-PX</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ibm" name="sng">
                <vers num="2.1" />
                <vers num="2.2" />
            </prod>
            <prod vendor="ibm" name="aix">
                <vers num="3.2.5" />
                <vers num="4.1" />
                <vers num="4.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" name="CVE-1999-0961" seq="1999-0961" severity="Medium" type="CVE" published="1996-09-21" CVSS_version="2.0 incomplete approximation" CVSS_score="6.2" modified="2008-09-09">
        <desc>
            <descript source="cve">HPUX sysdiag allows local users to gain root privileges via a symlink attack during log file creation.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <race />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167419906&amp;w=2">19960921 Vunerability in HP sysdiag ?</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="9.04" />
                <vers num="9.05" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-0206" seq="1999-0206" severity="High" type="CVE" published="1996-10-01" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-09">
        <desc>
            <descript source="cve">MIME buffer overflow in Sendmail 8.8.0 and 8.8.1 gives root access.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="eric_allman" name="sendmail">
                <vers num="8.8" />
                <vers num="8.8.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-0246" seq="1999-0246" severity="High" type="CVE" published="1996-10-01" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-09">
        <desc>
            <descript source="cve">HP Remote Watch allows a remote user to gain root access.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0319" seq="1999-0319" severity="High" type="CVE" published="1996-10-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow in xmcd 2.1 allows local users to gain access through a user resource setting.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-1999-0308" seq="1999-0308" severity="Medium" type="CVE" published="1996-10-01" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-09">
        <desc>
            <descript source="cve">HP-UX gwind program allows users to modify arbitrary files.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9410-018">HPSBUX9410-018</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="8" />
                <vers num="9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-1999-0234" seq="1999-0234" severity="Medium" type="CVE" published="1996-10-08" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-09">
        <desc>
            <descript source="cve">Bash treats any character with a value of 255 as a command separator.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="caldera" name="openlinux">
                <vers num="" />
            </prod>
            <prod vendor="redhat" name="linux">
                <vers num="3.0.3" />
            </prod>
            <prod vendor="sgi" name="irix">
                <vers num="" />
            </prod>
            <prod vendor="suse" name="suse_linux">
                <vers num="4.2" />
            </prod>
            <prod vendor="yggdrasil" name="linux">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0075" seq="1999-0075" severity="Medium" type="CVE" published="1996-10-16" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">PASV core dump in wu-ftpd daemon when attacker uses a QUOTE PASV command after specifying a username and password.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="OSVDB" url="http://www.osvdb.org/5742">5742</ref>
        </refs>
        <vuln_soft>
            <prod vendor="washington_university" name="wu-ftpd">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0032" seq="1999-0032" severity="High" type="CVE" published="1996-10-25" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow in lpr, as used in BSD-based systems including Linux, allows local users to execute arbitrary code as root via a long -C (classification) command line option.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/707">707</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-042.shtml">I-042</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980402-01-PX">19980402-01-PX</ref>
        </refs>
        <vuln_soft>
            <prod vendor="bsdi" name="bsd_os">
                <vers num="2.1" />
            </prod>
            <prod vendor="freebsd" name="freebsd">
                <vers num="2.0" />
                <vers num="2.0.5" />
                <vers num="2.1.0" />
                <vers num="2.1.5" />
            </prod>
            <prod vendor="next" name="nextstep">
                <vers num="4.0" />
                <vers num="4.1" />
            </prod>
            <prod vendor="sgi" name="irix">
                <vers num="5.0" />
                <vers num="5.0.1" />
                <vers num="5.1" />
                <vers num="5.1.1" />
                <vers num="5.2" />
                <vers num="5.3" />
                <vers num="6.0" />
                <vers num="6.0.1" />
                <vers num="6.1" />
                <vers num="6.2" />
                <vers num="6.3" />
                <vers num="6.4" />
            </prod>
            <prod vendor="sun" name="sunos">
                <vers num="4.1.3u1" />
                <vers num="4.1.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0277" seq="1999-0277" severity="High" type="CVE" published="1996-10-28" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">The WorkMan program can be used to overwrite any file to get root access.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <env />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers num="2.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1384" seq="1999-1384" severity="High" type="CVE" published="1996-10-30" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Indigo Magic System Tour in the SGI system tour package (systour) for IRIX 5.x through 6.3 allows local users to gain root privileges via a Trojan horse .exitops program, which is called by the inst command that is executed by the RemoveSystemTour program.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="AUSCERT" patch="1" url="ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-96.08.SGI.systour.vul" adv="1">AA-96.08</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/470" adv="1">470</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420095&amp;w=2" adv="1">19961030 (Another) vulnerability in new SGIs</ref>
            <ref source="SGI" patch="1" url="ftp://patches.sgi.com/support/free/security/advisories/19961101-01-I" adv="1">19961101-01-I</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/7456.php">irix-systour(7456)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sgi" name="irix">
                <vers num="5" />
                <vers num="5.0" />
                <vers num="5.0.1" />
                <vers num="5.1" />
                <vers num="5.1.1" />
                <vers num="5.2" />
                <vers edition="" num="5.3" />
                <vers edition=":xfs" num="5.3" />
                <vers num="6.0" />
                <vers edition="" num="6.0.1" />
                <vers edition=":xfs" num="6.0.1" />
                <vers num="6.1" />
                <vers num="6.2" />
                <vers num="6.3" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0311" seq="1999-0311" severity="High" type="CVE" published="1996-11-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">fpkg2swpk in HP-UX allows local users to gain root access.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9612-042">HPSBUX9612-042</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="10" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0336" seq="1999-0336" severity="High" type="CVE" published="1996-11-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow in mstm in HP-UX allows local users to gain root access.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="10" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1161" seq="1999-1161" severity="High" type="CVE" published="1996-11-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Vulnerability in ppl in HP-UX 10.x and earlier allows local users to gain root privileges by forcing ppl to core dump.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="HP" patch="1" url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9704-057.html" adv="1">HPSBUX9704-057</ref>
            <ref source="CIAC" patch="1" url="http://ciac.llnl.gov/ciac/bulletins/h-32.shtml" adv="1">H-32</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420103&amp;w=2" adv="1">19961104 ppl bugs</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420102&amp;w=2">19961103 Re: Untitled</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/7438.php">hp-ppl(7438)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="10" prev="1" />
                <vers num="9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0130" seq="1999-0130" severity="High" type="CVE" published="1996-11-16" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">Local users can start Sendmail in daemon mode and gain root privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/716">716</ref>
        </refs>
        <vuln_soft>
            <prod vendor="caldera" name="network_desktop">
                <vers num="1.0" />
            </prod>
            <prod vendor="eric_allman" name="sendmail">
                <vers num="8.7" />
                <vers num="8.8" />
                <vers num="8.8.1" />
                <vers num="8.8.2" />
            </prod>
            <prod vendor="bsdi" name="bsd_os">
                <vers num="2.1" />
            </prod>
            <prod vendor="freebsd" name="freebsd">
                <vers num="2.1.5" />
                <vers num="2.1.6" />
            </prod>
            <prod vendor="hp" name="hp-ux">
                <vers num="10.00" />
                <vers num="10.01" />
                <vers num="10.10" />
                <vers num="10.20" />
            </prod>
            <prod vendor="ibm" name="aix">
                <vers num="4.2" />
            </prod>
            <prod vendor="redhat" name="linux">
                <vers num="4.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-1999-1221" seq="1999-1221" severity="Low" type="CVE" published="1996-11-17" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">dxchpwd in Digital Unix (OSF/1) 3.x allows local users to modify arbitrary files via a symlink attack on the dxchpwd.log file.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/399.php" adv="1">dgux-chpwd(399)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420141&amp;w=2">19961117 Digital Unix v3.x (v4.x?) security vulnerability</ref>
        </refs>
        <vuln_soft>
            <prod vendor="digital" name="unix">
                <vers num="3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-1099" seq="1999-1099" severity="Medium" type="CVE" published="1996-11-22" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Kerberos 4 allows remote attackers to obtain sensitive information via a malformed UDP packet that generates an error string that inadvertently includes the realm name and the last user.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/65.php" adv="1">kerberos-user-grab(65)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420184&amp;w=2" adv="1">19961122 L0pht Kerberos Advisory</ref>
        </refs>
        <vuln_soft>
            <prod vendor="kth" name="kth_kerberos">
                <vers num="4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-1240" seq="1999-1240" severity="High" type="CVE" published="1996-11-26" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in cddbd CD database server allows remote attackers to execute arbitrary commands via a long log message.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/2203.php" adv="1">cddbd-bo(2203)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="gracenote" name="cddbd">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0050" seq="1999-0050" severity="High" type="CVE" published="1996-12-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow in HP-UX newgrp program.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="10.00" />
                <vers num="10.01" />
                <vers num="10.10" />
                <vers num="10.20" />
                <vers num="9.00" />
                <vers num="9.01" />
                <vers num="9.03" />
                <vers num="9.04" />
                <vers num="9.05" />
                <vers num="9.06" />
                <vers num="9.07" />
                <vers num="9.08" />
                <vers num="9.09" />
                <vers num="9.10" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0044" seq="1999-0044" severity="High" type="CVE" published="1996-12-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">fsdump command in IRIX allows local users to obtain root access by modifying sensitive files.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970301-01-P">19970301-01-P</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sgi" name="irix">
                <vers num="5.1" />
                <vers num="5.1.1" />
                <vers num="5.2" />
                <vers num="5.3" />
                <vers num="6.0" />
                <vers num="6.0.1" />
                <vers num="6.1" />
                <vers num="6.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-1999-0129" seq="1999-0129" severity="Medium" type="CVE" published="1996-12-03" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-09">
        <desc>
            <descript source="cve">Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="eric_allman" name="sendmail">
                <vers num="8.8" />
                <vers num="8.8.1" />
                <vers num="8.8.2" />
                <vers num="8.8.3" />
            </prod>
            <prod vendor="bsdi" name="bsd_os">
                <vers num="2.1" />
            </prod>
            <prod vendor="freebsd" name="freebsd">
                <vers num="2.1.5" />
                <vers num="2.1.6" />
                <vers num="2.1.6.1" />
            </prod>
            <prod vendor="hp" name="hp-ux">
                <vers num="10.00" />
                <vers num="10.01" />
                <vers num="10.10" />
                <vers num="10.16" />
                <vers num="10.20" />
            </prod>
            <prod vendor="ibm" name="aix">
                <vers num="3.2" />
                <vers num="4.1" />
                <vers num="4.2" />
            </prod>
            <prod vendor="sco" name="internet_faststart">
                <vers num="1.0" />
                <vers num="1.1" />
            </prod>
            <prod vendor="sco" name="openserver">
                <vers num="5.0" />
                <vers num="5.0.2" />
            </prod>
            <prod vendor="sun" name="solaris">
                <vers num="2.3" />
                <vers edition="" num="2.4" />
                <vers edition=":x86" num="2.4" />
                <vers edition="" num="2.5" />
                <vers edition=":x86" num="2.5" />
                <vers edition="" num="2.5.1" />
                <vers edition=":x86" num="2.5.1" />
            </prod>
            <prod vendor="sun" name="sunos">
                <vers num="4.1.3u1" />
                <vers num="4.1.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-0043" seq="1999-0043" severity="High" type="CVE" published="1996-12-04" CVSS_version="2.0" CVSS_score="10.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="isc" name="inn">
                <vers num="1.4sec" />
                <vers num="1.4sec2" />
                <vers num="1.4unoff3" />
                <vers num="1.4unoff4" />
                <vers num="1.5" />
            </prod>
            <prod vendor="netscape" name="news_server">
                <vers num="1.1" />
            </prod>
            <prod vendor="nec" name="goah_intrasv">
                <vers num="1.1" />
            </prod>
            <prod vendor="nec" name="goah_networksv">
                <vers num="1.2" />
                <vers num="2.2" />
                <vers num="3.1" />
            </prod>
            <prod vendor="bsdi" name="bsd_os">
                <vers num="2.1" />
            </prod>
            <prod vendor="caldera" name="openlinux">
                <vers num="1.0" />
            </prod>
            <prod vendor="redhat" name="linux">
                <vers num="4.0" />
                <vers num="4.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-1999-1401" seq="1999-1401" severity="Medium" type="CVE" published="1996-12-05" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Vulnerability in Desktop searchbook program in IRIX 5.0.x through 6.2 sets insecure permissions for certain user files (iconbook and searchbook).</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/463" adv="1">463</ref>
            <ref source="SGI" patch="1" url="ftp://patches.sgi.com/support/free/security/advisories/19961201-01-PX" adv="1">19961201-01-PX</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/7575.php">irix-searchbook-permissions(7575)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/8563">8563</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sgi" name="irix">
                <vers num="5.0" />
                <vers num="5.0.1" />
                <vers num="5.1" />
                <vers num="5.1.1" />
                <vers num="5.2" />
                <vers edition="" num="5.3" />
                <vers edition=":xfs" num="5.3" />
                <vers num="6.0" />
                <vers edition="" num="6.0.1" />
                <vers edition=":xfs" num="6.0.1" />
                <vers num="6.1" />
                <vers num="6.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0045" seq="1999-0045" severity="High" type="CVE" published="1996-12-10" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">List of arbitrary files on Web host via nph-test-cgi script.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <input />
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="apache" name="http_server">
                <vers num="0.8.11" />
                <vers num="0.8.14" />
                <vers num="1.0" />
                <vers num="1.0.2" />
                <vers num="1.0.3" />
                <vers num="1.0.5" />
                <vers num="1.1" />
            </prod>
            <prod vendor="netscape" name="commerce_server">
                <vers num="1.12" />
            </prod>
            <prod vendor="netscape" name="communications_server">
                <vers num="1.1" />
                <vers num="1.12" />
            </prod>
            <prod vendor="netscape" name="enterprise_server">
                <vers num="2.0a" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-0101" seq="1999-0101" severity="High" type="CVE" published="1996-12-10" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow in AIX and Solaris "gethostbyname" library call allows root access through corrupt DNS host names.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-13.shtml" adv="1">H-13</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ibm" name="aix">
                <vers num="3.2" />
                <vers num="4.1" />
                <vers num="4.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0096" seq="1999-0096" severity="Medium" type="CVE" published="1996-12-10" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Sendmail decode alias can be used to overwrite sensitive files.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/122&amp;type=0&amp;nav=sec.sba">00122</ref>
        </refs>
        <vuln_soft>
            <prod vendor="bsdi" name="bsd_os">
                <vers num="" />
            </prod>
            <prod vendor="freebsd" name="freebsd">
                <vers num="2.1.5" />
                <vers num="2.1.6" />
                <vers num="2.1.6.1" />
            </prod>
            <prod vendor="sco" name="internet_faststart">
                <vers num="1.0" />
                <vers num="1.1" />
            </prod>
            <prod vendor="sco" name="openserver">
                <vers num="5.0" />
                <vers num="5.0.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0297" seq="1999-0297" severity="High" type="CVE" published="1996-12-12" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow in Vixie Cron library up to version 3.0 allows local users to obtain root access via a long environmental variable.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="paul_vixie" name="vixie_cron">
                <vers num="3.0" />
            </prod>
            <prod vendor="bsdi" name="bsd_os">
                <vers num="2.1" />
            </prod>
            <prod vendor="freebsd" name="freebsd">
                <vers num="2.1.0" />
            </prod>
            <prod vendor="netbsd" name="netbsd">
                <vers num="2.0.4" />
            </prod>
            <prod vendor="redhat" name="linux">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1089" seq="1999-1089" severity="High" type="CVE" published="1996-12-13" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in chfn command in HP-UX 9.X through 10.20 allows local users to gain privileges via a long command line argument.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CIAC" patch="1" url="http://ciac.llnl.gov/ciac/bulletins/h-21.shtml" adv="1">H-21</ref>
            <ref source="CIAC" patch="1" url="http://ciac.llnl.gov/ciac/bulletins/h-16.shtml" adv="1">H-16</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420285&amp;w=2" adv="1">19961209 the HP Bug of the Week!</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="10" />
                <vers num="10.20" prev="1" />
                <vers num="9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0128" seq="1999-0128" severity="Medium" type="CVE" published="1996-12-18" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="ibm" name="sng">
                <vers num="2.1" />
                <vers num="2.2" />
            </prod>
            <prod vendor="digital" name="osf_1">
                <vers num="1.3.3" />
            </prod>
            <prod vendor="ibm" name="aix">
                <vers num="3.2" />
                <vers num="4.1" />
                <vers num="4.2" />
            </prod>
            <prod vendor="linux" name="linux_kernel">
                <vers num="1.3.0" />
                <vers num="2.0" />
            </prod>
            <prod vendor="sco" name="internet_faststart">
                <vers num="1.0" />
                <vers num="1.1" />
            </prod>
            <prod vendor="sco" name="open_desktop">
                <vers num="3.0" />
            </prod>
            <prod vendor="sco" name="openserver">
                <vers num="5.0" />
                <vers num="5.0.2" />
            </prod>
            <prod vendor="sco" name="tcp_ip">
                <vers num="1.2.1" />
            </prod>
            <prod vendor="sun" name="sunos">
                <vers edition="" num="5.4" />
                <vers edition=":x86" num="5.4" />
                <vers edition="" num="5.5" />
                <vers edition=":x86" num="5.5" />
                <vers edition="" num="5.5.1" />
                <vers edition=":x86" num="5.5.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0127" seq="1999-0127" severity="High" type="CVE" published="1996-12-19" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">swinstall and swmodify commands in SD-UX package in HP-UX systems allow local users to create or overwrite arbitrary files to gain root access.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1385" seq="1999-1385" severity="High" type="CVE" published="1996-12-19" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-10">
        <desc>
            <descript source="cve">Buffer overflow in ppp program in FreeBSD 2.1 and earlier allows local users to gain privileges via a long HOME environment variable.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="FREEBSD" patch="1" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-96:20.stack-overflow.asc" adv="1">FreeBSD-SA-96:20</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/6085">6085</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/7465.php">ppp-bo(7465)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420332&amp;w=2">19961219 Exploit for ppp bug (FreeBSD 2.1.0).</ref>
        </refs>
        <vuln_soft>
            <prod vendor="freebsd" name="freebsd">
                <vers num="1.0" />
                <vers num="1.1" />
                <vers num="2.1.0" prev="1" />
                <vers num="2.1.5" />
                <vers num="2.1.6" />
                <vers num="2.1.6.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1026" seq="1999-1026" severity="High" type="CVE" published="1996-12-20" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">aspppd on Solaris 2.5 x86 allows local users to modify arbitrary files and gain root privileges via a symlink attack on the /tmp/.asppp.fifo file.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/292" adv="1">292</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420343&amp;w=2" adv="1">19961220 Solaris 2.5 x86 aspppd (semi-exploitable-hole)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers edition="" num="2.4" />
                <vers edition=":x86" num="2.4" />
                <vers edition="" num="2.5" />
                <vers edition=":x86" num="2.5" />
                <vers edition="" num="2.5.1" />
                <vers edition=":x86" num="2.5.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0260" seq="1999-0260" severity="High" type="CVE" published="1996-12-24" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">The jj CGI program allows command execution via shell metacharacters.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="renaud_deraison" name="jj">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-1999-1251" seq="1999-1251" severity="Low" type="CVE" published="1996-12-24" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">Vulnerability in direct audio user space code on HP-UX 10.20 and 10.10 allows local users to cause a denial of service.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/2010.php" adv="1">hp-audio-panic(2010)</ref>
            <ref source="HP" patch="1" url="http://packetstormsecurity.org/advisories/hpalert/043" adv="1">HPSBUX9612-043</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="10.10" />
                <vers num="10.20" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0265" seq="1999-0265" severity="Medium" type="CVE" published="1997-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">ICMP redirect messages may crash or lock up a host.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q154174">Q154174</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microware" name="os-9">
                <vers num="" />
            </prod>
            <prod vendor="novell" name="netware">
                <vers num="3.12" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0274" seq="1999-0274" severity="Medium" type="CVE" published="1997-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Denial of service in Windows NT DNS servers through malicious packet which contains a response to a query that wasn't made.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="microsoft" name="windows_nt">
                <vers edition="sp1" num="4.0" />
                <vers edition="sp2" num="4.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-0236" seq="1999-0236" severity="High" type="CVE" published="1997-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-09">
        <desc>
            <descript source="cve">ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <env />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="apache" name="http_server">
                <vers num="" />
            </prod>
            <prod vendor="ncsa" name="servers">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0217" seq="1999-0217" severity="Medium" type="CVE" published="1997-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Malicious option settings in UDP packets could force a reboot in SunOS 4.1.3 systems.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="sun" name="sunos">
                <vers num="4.0.3" />
                <vers num="4.0.3c" />
                <vers num="4.1" />
                <vers num="4.1.1" />
                <vers num="4.1.2" />
                <vers num="4.1.3" />
                <vers num="4.1.3a1" />
                <vers num="4.1psr_a" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0249" seq="1999-0249" severity="High" type="CVE" published="1997-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">Windows NT RSHSVC program allows remote users to execute arbitrary commands.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="microsoft" name="windows_2000">
                <vers num="" />
            </prod>
            <prod vendor="microsoft" name="windows_nt">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0251" seq="1999-0251" severity="Medium" type="CVE" published="1997-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Denial of service in talk program allows remote attackers to disrupt a user's display.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="talkd" name="talkd">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0252" seq="1999-0252" severity="High" type="CVE" published="1997-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow in listserv allows arbitrary command execution.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="lsoft" name="listserv">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0253" seq="1999-0253" severity="High" type="CVE" published="1997-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="microsoft" name="internet_information_server">
                <vers num="1.0" />
                <vers num="2.0" />
                <vers num="3.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-0204" seq="1999-0204" severity="High" type="CVE" published="1997-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Sendmail 8.6.9 allows remote attackers to execute root commands, using ident.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="eric_allman" name="sendmail">
                <vers num="8.6.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" name="CVE-1999-0201" seq="1999-0201" severity="Medium" type="CVE" published="1997-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="6.4" modified="2008-09-09">
        <desc>
            <descript source="cve">A quote cwd command on FTP servers can reveal the full path of the home directory of the "ftp" user.</descript>
        </desc>
        <loss_types>
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="ftp" name="ftp">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0202" seq="1999-0202" severity="High" type="CVE" published="1997-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">The GNU tar command, when used in FTP sessions, may allow an attacker to execute arbitrary commands.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="washington_university" name="wu-ftpd">
                <vers num="2.4.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0178" seq="1999-0178" severity="High" type="CVE" published="1997-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow in the win-c-sample program (win-c-sample.exe) in the WebSite web server 1.1e allows remote attackers to execute arbitrary code via a long query string.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/295">http-website-winsample(295)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/2078">2078</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/8">8</ref>
            <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/1997_1/0021.html">19970106 Re: signal handling</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oreilly" name="oreilly_website">
                <vers num="1.1e" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0179" seq="1999-0179" severity="Medium" type="CVE" published="1997-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Windows NT crashes or locks up when a Samba client executes a "cd .." command on a file share.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q140818">Q140818</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="windows_95">
                <vers num="" />
            </prod>
            <prod vendor="microsoft" name="windows_nt">
                <vers num="3.5.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0180" seq="1999-0180" severity="High" type="CVE" published="1997-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">in.rshd allows users to login with a NULL username and execute commands.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0173" seq="1999-0173" severity="Medium" type="CVE" published="1997-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">FormMail CGI program can be used by web servers other than the host server that the program resides on.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="matt_wright" name="formmail">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0170" seq="1999-0170" severity="High" type="CVE" published="1997-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">Remote attackers can mount an NFS file system in Ultrix or OSF, even if it is denied on the access list.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="digital" name="ultrix">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-1999-0171" seq="1999-0171" severity="Low" type="CVE" published="1997-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-09">
        <desc>
            <descript source="cve">Denial of service in syslog by sending it a large number of superfluous messages.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="linux" name="linux_kernel">
                <vers num="2.6.20.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0163" seq="1999-0163" severity="High" type="CVE" published="1997-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">In older versions of Sendmail, an attacker could use a pipe character to execute root commands.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="eric_allman" name="sendmail">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0166" seq="1999-0166" severity="Medium" type="CVE" published="1997-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">NFS allows users to use a "cd .." command to access other directories besides the exported file system.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="sun" name="nfs">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-0100" seq="1999-0100" severity="High" type="CVE" published="1997-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Remote access in AIX innd 1.5.1, using control messages.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="isc" name="inn">
                <vers num="1.5.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0345" seq="1999-0345" severity="Medium" type="CVE" published="1997-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Jolt ICMP attack causes a denial of service in Windows 95 and Windows NT systems.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="ibm" name="sng">
                <vers num="2.1" />
                <vers num="2.2" />
            </prod>
            <prod vendor="freebsd" name="freebsd">
                <vers num="1.0" />
                <vers num="1.1" />
                <vers num="1.1.5.1" />
                <vers num="1.2" />
                <vers num="2.0" />
                <vers num="2.0.5" />
            </prod>
            <prod vendor="ibm" name="aix">
                <vers num="3.2" />
                <vers num="4.1" />
                <vers num="4.2" />
            </prod>
            <prod vendor="sco" name="internet_faststart">
                <vers num="1.0" />
                <vers num="1.1" />
            </prod>
            <prod vendor="sco" name="open_desktop">
                <vers num="3" />
            </prod>
            <prod vendor="sco" name="openserver">
                <vers num="5" />
            </prod>
            <prod vendor="sun" name="sunos">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0510" seq="1999-0510" severity="High" type="CVE" published="1997-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">A router or firewall allows source routed packets from arbitrary hosts.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <other />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0511" seq="1999-0511" severity="High" type="CVE" published="1997-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">IP forwarding is enabled on a machine which is not a router or firewall.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="microsoft" name="windows_2000">
                <vers num="" />
            </prod>
            <prod vendor="microsoft" name="windows_nt">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0499" seq="1999-0499" severity="High" type="CVE" published="1997-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">NETBIOS share information may be published through SNMP registry keys in NT.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="microsoft" name="windows_2000">
                <vers num="" />
            </prod>
            <prod vendor="microsoft" name="windows_nt">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0503" seq="1999-0503" severity="High" type="CVE" published="1997-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">A Windows NT local user or administrator account has a guessable password.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <config />
            <other />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="microsoft" name="windows_2000">
                <vers num="" />
            </prod>
            <prod vendor="microsoft" name="windows_nt">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0504" seq="1999-0504" severity="High" type="CVE" published="1997-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">A Windows NT local user or administrator account has a default, null, blank, or missing password.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <other />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="microsoft" name="windows_2000">
                <vers num="" />
            </prod>
            <prod vendor="microsoft" name="windows_nt">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-1999-0496" seq="1999-0496" severity="Medium" type="CVE" published="1997-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-09">
        <desc>
            <descript source="cve">A Windows NT 4.0 user can gain administrative rights by forcing NtOpenProcessToken to succeed regardless of the user's permissions, aka GetAdmin.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q146965">Q146965</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="windows_nt">
                <vers num="4.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0521" seq="1999-0521" severity="High" type="CVE" published="1997-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">An NIS domain name is easily guessable.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0517" seq="1999-0517" severity="High" type="CVE" published="1997-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">An SNMP community name is the default (e.g. public), null, or missing.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="10" />
                <vers num="11.00" />
            </prod>
            <prod vendor="sun" name="solaris">
                <vers num="2.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0518" seq="1999-0518" severity="High" type="CVE" published="1997-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">A NETBIOS/SMB share password is guessable.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <design />
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="microsoft" name="windows_95">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0519" seq="1999-0519" severity="High" type="CVE" published="1997-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">A NETBIOS/SMB share password is the default, null, or missing.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="microsoft" name="outlook">
                <vers num="2000" />
            </prod>
            <prod vendor="microsoft" name="windows_2000">
                <vers num="" />
            </prod>
            <prod vendor="microsoft" name="windows_95">
                <vers num="" />
            </prod>
            <prod vendor="microsoft" name="windows_nt">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0525" seq="1999-0525" severity="High" type="CVE" published="1997-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">IP traceroute is allowed from arbitrary hosts.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-1999-0534" seq="1999-0534" severity="Medium" type="CVE" published="1997-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-09">
        <desc>
            <descript source="cve">A Windows NT user has inappropriate rights or privileges, e.g. Act as System, Add Workstation, Backup, Change System Time, Create Pagefile, Create Permanent Object, Create Token Name, Debug, Generate Security Audit, Increase Priority, Increase Quota, Load Driver, Lock Memory, Profile Single Process, Remote Shutdown, Replace Process Token, Restore, System Environment, Take Ownership, or Unsolicited Input.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <other />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="microsoft" name="windows_2000">
                <vers num="" />
            </prod>
            <prod vendor="microsoft" name="windows_nt">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-0535" seq="1999-0535" severity="High" type="CVE" published="1997-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-09">
        <desc>
            <descript source="cve">A Windows NT account policy for passwords has inappropriate, security-critical settings, e.g. for password length, password age, or uniqueness.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <env />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="microsoft" name="windows_2000">
                <vers num="" />
            </prod>
            <prod vendor="microsoft" name="windows_nt">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0550" seq="1999-0550" severity="High" type="CVE" published="1997-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">A router's routing tables can be obtained from arbitrary hosts.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <other />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0562" seq="1999-0562" severity="High" type="CVE" published="1997-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">The registry in Windows NT can be accessed remotely by users who are not administrators.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1023" sig="1">oval:org.mitre.oval:def:1023</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="windows_2000">
                <vers num="" />
            </prod>
            <prod vendor="microsoft" name="windows_nt">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-1999-0572" seq="1999-0572" severity="High" type="CVE" published="1997-01-01" CVSS_version="2.0" CVSS_score="9.3" modified="2008-09-09">
        <desc>
            <descript source="cve">.reg files are associated with the Windows NT registry editor (regedit), making the registry susceptible to Trojan Horse attacks.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <other />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="microsoft" name="windows_2000">
                <vers num="" />
            </prod>
            <prod vendor="microsoft" name="windows_nt">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0575" seq="1999-0575" severity="High" type="CVE" published="1997-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">A Windows NT system's user audit policy does not log an event success or failure, e.g. for Logon and Logoff, File and Object Access, Use of User Rights, User and Group Management, Security Policy Changes, Restart, Shutdown, and System, and Process Tracking.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="microsoft" name="windows_nt">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0576" seq="1999-0576" severity="High" type="CVE" published="1997-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">A Windows NT system's file audit policy does not log an event success or failure for security-critical files or directories.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="microsoft" name="windows_nt">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0582" seq="1999-0582" severity="Medium" type="CVE" published="1997-01-01" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">A Windows NT account policy has inappropriate, security-critical settings for lockout, e.g. lockout duration, lockout after bad logon attempts, etc.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="microsoft" name="windows_2000">
                <vers num="" />
            </prod>
            <prod vendor="microsoft" name="windows_nt">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)" CVSS_base_score="0.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="0.0" name="CVE-1999-0626" seq="1999-0626" severity="Low" type="CVE" published="1997-01-01" CVSS_version="2.0" CVSS_score="0.0" modified="2008-09-09">
        <desc>
            <descript source="cve">A version of rusers is running that exposes valid user information to any entity on the network.</descript>
        </desc>
        <impacts>
            <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
        </impacts>
        <sols>
            <sol source="nvd">rusers is an unsecured and obsolete protocol and it should be disabled.</sol>
        </sols>
        <vuln_types>
            <other />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="sun" name="rpc.ruserd">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-1999-1120" seq="1999-1120" severity="Medium" type="CVE" published="1997-01-04" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">netprint in SGI IRIX 6.4 and earlier trusts the PATH environmental variable for finding and executing the disable program, which allows local users to gain privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/2107.php" adv="1">sgi-netprint(2107)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/395" adv="1">395</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420403&amp;w=2" adv="1">19970104 Irix: netprint story</ref>
            <ref source="SGI" patch="1" url="ftp://patches.sgi.com/support/free/security/advisories/19961203-02-PX" adv="1">19961203-02-PX</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/993">993</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19961203-01-PX">19961203-01-PX</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sgi" name="irix">
                <vers num="5.3" />
                <vers num="6.0" />
                <vers num="6.0.1" />
                <vers num="6.1" />
                <vers num="6.2" />
                <vers num="6.3" />
                <vers num="6.4" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0051" seq="1999-0051" severity="High" type="CVE" published="1997-01-06" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">Arbitrary file creation and program execution using FLEXlm LicenseManager, from versions 4.0 to 5.0, in IRIX.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="globetrotter" name="flexlm">
                <vers num="4.0" />
                <vers num="4.1" />
                <vers num="5.0" />
            </prod>
            <prod vendor="sgi" name="license_oeo">
                <vers num="3.0" />
                <vers num="3.1" />
                <vers num="3.1.1" />
            </prod>
            <prod vendor="sgi" name="irix">
                <vers num="3.3.2" />
                <vers num="3.3.3" />
                <vers num="4.0" />
                <vers num="4.0.1" />
                <vers num="4.0.1t" />
                <vers num="4.0.2" />
                <vers num="4.0.3" />
                <vers num="4.0.4" />
                <vers num="4.0.4b" />
                <vers num="4.0.4t" />
                <vers num="4.0.5" />
                <vers num="4.0.5_iop" />
                <vers num="4.0.5_ipr" />
                <vers num="4.0.5a" />
                <vers num="4.0.5d" />
                <vers num="4.0.5e" />
                <vers num="4.0.5f" />
                <vers num="4.0.5g" />
                <vers num="4.0.5h" />
                <vers num="5.0" />
                <vers num="5.0.1" />
                <vers num="5.1" />
                <vers num="5.1.1" />
                <vers num="5.2" />
                <vers num="5.3" />
                <vers num="6.0" />
                <vers edition="" num="6.0.1" />
                <vers edition=":xfs" num="6.0.1" />
                <vers num="6.1" />
                <vers num="6.2" />
                <vers num="6.3" />
                <vers num="6.4" />
            </prod>
            <prod vendor="sun" name="solaris">
                <vers edition="" num="2.4" />
                <vers edition=":x86" num="2.4" />
                <vers edition="" num="2.5" />
                <vers edition=":x86" num="2.5" />
                <vers edition="" num="2.5.1" />
                <vers edition=":x86" num="2.5.1" />
            </prod>
            <prod vendor="sun" name="sunos">
                <vers num="4.1.1" />
                <vers num="4.1.2" />
                <vers num="4.1.3" />
                <vers num="4.1.3u1" />
                <vers num="4.1.4" />
                <vers num="4.1.4jl" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-1999-1249" seq="1999-1249" severity="Medium" type="CVE" published="1997-01-06" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">movemail in HP-UX 10.20 has insecure permissions, which allows local users to gain privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/2057.php" adv="1">hp-movemail(2057)</ref>
            <ref source="HP" patch="1" url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9701-047.html" adv="1">HPSBUX9701-047</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/8099">8099</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="10.20" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1145" seq="1999-1145" severity="High" type="CVE" published="1997-01-07" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Vulnerability in Glance programs in GlancePlus for HP-UX 10.20 and earlier allows local users to access arbitrary files and gain privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/2059.php" adv="1">hp-glanceplus(2059)</ref>
            <ref source="CIAC" patch="1" url="http://ciac.llnl.gov/ciac/bulletins/h-21.shtml" adv="1">H-21</ref>
            <ref source="HP" url="http://www.securityfocus.com/templates/advisory.html?id=1514">HPSBUX9701-044</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="10.01" />
                <vers num="10.10" />
                <vers num="10.20" prev="1" />
                <vers num="9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-1999-1311" seq="1999-1311" severity="Medium" type="CVE" published="1997-01-07" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-10">
        <desc>
            <descript source="cve">Vulnerability in dtlogin and dtsession in HP-UX 10.20 and 10.10 allows local users to bypass authentication and gain privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CIAC" patch="1" url="http://ciac.llnl.gov/ciac/bulletins/h-21.shtml" adv="1">H-21</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="10.10" />
                <vers num="10.20" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0049" seq="1999-0049" severity="High" type="CVE" published="1997-01-08" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">Csetup under IRIX allows arbitrary file creation or overwriting.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="sgi" name="irix">
                <vers num="5" />
                <vers num="6.0" />
                <vers num="6.0.1" />
                <vers num="6.1" />
                <vers num="6.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1088" seq="1999-1088" severity="High" type="CVE" published="1997-01-09" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Vulnerability in chsh command in HP-UX 9.X through 10.20 allows local users to gain privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/2012.php" adv="1">hp-chsh(2012)</ref>
            <ref source="CIAC" patch="1" url="http://ciac.llnl.gov/ciac/bulletins/h-21.shtml" adv="1">H-21</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="10.00" />
                <vers num="10.01" />
                <vers num="10.02" prev="1" />
                <vers num="10.10" />
                <vers num="10.20" />
                <vers num="9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0081" seq="1999-0081" severity="Medium" type="CVE" published="1997-01-11" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">wu-ftp allows files to be overwritten via the rnfr command.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="washington_university" name="wu-ftpd">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-0048" seq="1999-0048" severity="High" type="CVE" published="1997-01-27" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Talkd, when given corrupt DNS information, can be used to execute arbitrary commands with root privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/147">00147</ref>
        </refs>
        <vuln_soft>
            <prod vendor="debian" name="netkit">
                <vers num="0.07" />
            </prod>
            <prod vendor="ibm" name="aix">
                <vers num="3.1" />
                <vers num="4.1" />
                <vers num="4.2" />
            </prod>
            <prod vendor="nec" name="asl_ux_4800">
                <vers num="" />
            </prod>
            <prod vendor="nec" name="ews-ux_v">
                <vers num="" />
            </prod>
            <prod vendor="nec" name="up-ux_v">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0966" seq="1999-0966" severity="High" type="CVE" published="1997-01-27" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow in Solaris getopt in libc allows local users to gain root privileges via a long argv[0].</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers num="2.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-0047" seq="1999-0047" severity="High" type="CVE" published="1997-01-28" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-09">
        <desc>
            <descript source="cve">MIME conversion buffer overflow in sendmail versions 8.8.3 and 8.8.4.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/685">685</ref>
        </refs>
        <vuln_soft>
            <prod vendor="eric_allman" name="sendmail">
                <vers num="8.8.3" />
                <vers num="8.8.4" />
            </prod>
            <prod vendor="bsdi" name="bsd_os">
                <vers num="2.1" />
            </prod>
            <prod vendor="caldera" name="openlinux">
                <vers num="1.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1144" seq="1999-1144" severity="High" type="CVE" published="1997-01-30" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Certain files in MPower in HP-UX 10.x are installed with insecure permissions, which allows local users to gain privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" admin="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/2056.php" adv="1">hp-mpower(2056)</ref>
            <ref source="HP" patch="1" url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9701-051.html" adv="1">HPSBUX9701-051</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="10.00" />
                <vers num="10.01" />
                <vers num="10.10" />
                <vers num="10.20" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" name="CVE-1999-0174" seq="1999-0174" severity="Medium" type="CVE" published="1997-02-01" CVSS_version="2.0 incomplete approximation" CVSS_score="6.4" modified="2008-09-09">
        <desc>
            <descript source="cve">The view-source CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
        </desc>
        <loss_types>
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="netscape" name="communicator">
                <vers num="4.0" />
                <vers num="4.05" />
                <vers num="4.06" />
                <vers num="4.07" />
                <vers num="4.5" />
                <vers num="4.51" />
                <vers num="4.6" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0309" seq="1999-0309" severity="High" type="CVE" published="1997-02-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">HP-UX vgdisplay program gives root access to local users.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9702-056">HPSBUX9702-056</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="10.00" />
                <vers num="10.01" />
                <vers num="10.10" />
                <vers num="10.20" />
                <vers num="10.24" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0369" seq="1999-0369" severity="High" type="CVE" published="1997-02-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">The Sun sdtcm_convert calendar utility for OpenWindows has a buffer overflow which can gain root access.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/183">00183</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers edition=":x86" num="" />
                <vers num="1.1" />
                <vers num="1.1.1a" />
                <vers num="1.1.2" />
                <vers edition="u1" num="1.1.3" />
                <vers edition="" num="1.1.4" />
                <vers edition=":jl" num="1.1.4" />
                <vers num="1.2" />
                <vers num="2.0" />
                <vers num="2.1" />
                <vers num="2.2" />
                <vers num="2.3" />
                <vers edition="" num="2.4" />
                <vers edition=":x86" num="2.4" />
                <vers edition="" num="2.5" />
                <vers edition=":x86" num="2.5" />
                <vers num="2.5.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0959" seq="1999-0959" severity="High" type="CVE" published="1997-02-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">IRIX startmidi program allows local users to modify arbitrary files via a symlink attack.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" user="1" />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/469">469</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/8447">8447</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980301-01-PX">19980301-01-PX</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sgi" name="irix">
                <vers num="5" />
                <vers num="6.0" />
                <vers num="6.0.1" />
                <vers num="6.1" />
                <vers num="6.2" />
                <vers num="6.3" />
                <vers num="6.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-1160" seq="1999-1160" severity="High" type="CVE" published="1997-02-02" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Vulnerability in ftpd/kftpd in HP-UX 10.x and 9.x allows local and possibly remote users to gain root privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="HP" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420581&amp;w=2" adv="1">HPSBUX9702-055</ref>
            <ref source="CIAC" patch="1" url="http://ciac.llnl.gov/ciac/bulletins/h-33.shtml" adv="1">H-33</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/7437.php">hp-ftpd-kftpd(7437)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="10" />
                <vers num="9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-1299" seq="1999-1299" severity="High" type="CVE" published="1997-02-03" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">rcp on various Linux systems including Red Hat 4.0 allows a "nobody" user or other user with UID of 65535 to overwrite arbitrary files, since 65535 is interpreted as -1 by chown and other system calls, which causes the calls to fail to modify the ownership of the file.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420509&amp;w=2" adv="1">19970203 Linux rcp bug</ref>
        </refs>
        <vuln_soft>
            <prod vendor="redhat" name="linux">
                <vers num="4.0" />
            </prod>
            <prod vendor="slackware" name="slackware_linux">
                <vers num="3.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0298" seq="1999-0298" severity="High" type="CVE" published="1997-02-05" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">ypbind with -ypset and -ypsetme options activated in Linux Slackware and SunOS allows local and remote attackers to overwrite files via a .. (dot dot) attack.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="NAI" url="http://www.nai.com/nai_labs/asp_set/advisory/06_ypbindsetme_adv.asp">19970205 Vulnerabilities in Ypbind when run with -ypset/-ypsetme</ref>
        </refs>
        <vuln_soft>
            <prod vendor="slackware" name="slackware_linux">
                <vers num="2.1" />
                <vers num="2.2" />
                <vers num="2.3" />
            </prod>
            <prod vendor="sun" name="sunos">
                <vers num="4.1.3" />
                <vers num="4.1.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-0046" seq="1999-0046" severity="High" type="CVE" published="1997-02-06" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow of rlogin program using TERM environmental variable.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="data_general" name="dg_ux">
                <vers num="1.0" />
                <vers num="2.0" />
                <vers num="3.0" />
                <vers num="4.0" />
            </prod>
            <prod vendor="bsdi" name="bsd_os">
                <vers num="1.1" />
                <vers num="2.0" />
                <vers num="2.0.1" />
                <vers num="2.1" />
            </prod>
            <prod vendor="debian" name="debian_linux">
                <vers num="0.93" />
            </prod>
            <prod vendor="digital" name="ultrix">
                <vers num="2.2" />
                <vers num="3.0" />
                <vers num="4.0" />
                <vers num="4.1" />
                <vers num="4.2" />
                <vers num="4.3" />
                <vers num="4.3a" />
                <vers num="4.4" />
                <vers num="4.5" />
            </prod>
            <prod vendor="digital" name="unix">
                <vers num="3.2g" />
                <vers num="4.0" />
                <vers num="4.0a" />
                <vers num="4.0b" />
            </prod>
            <prod vendor="freebsd" name="freebsd">
                <vers num="1.1.5.1" />
                <vers num="2.0" />
                <vers num="2.0.5" />
                <vers num="2.1.0" />
                <vers num="2.1.5" />
            </prod>
            <prod vendor="hp" name="hp-ux">
                <vers num="10.00" />
                <vers num="10.01" />
                <vers num="10.08" />
                <vers num="10.09" />
                <vers num="10.10" />
                <vers num="10.16" />
                <vers num="10.20" />
                <vers num="10.24" />
                <vers num="10.30" />
                <vers num="10.34" />
            </prod>
            <prod vendor="ibm" name="aix">
                <vers num="3.2" />
                <vers num="4.1" />
                <vers num="4.1.1" />
                <vers num="4.1.2" />
                <vers num="4.1.3" />
                <vers num="4.1.4" />
                <vers num="4.1.5" />
            </prod>
            <prod vendor="netbsd" name="netbsd">
                <vers num="1.0" />
                <vers num="1.1" />
            </prod>
            <prod vendor="next" name="nextstep">
                <vers num="1.0" />
                <vers num="1.0a" />
                <vers num="2.0" />
                <vers num="2.1" />
                <vers num="3.0" />
                <vers num="3.1" />
                <vers num="3.2" />
                <vers num="3.3" />
                <vers num="4.0" />
            </prod>
            <prod vendor="sun" name="solaris">
                <vers num="2.3" />
                <vers edition="" num="2.4" />
                <vers edition=":x86" num="2.4" />
                <vers edition="" num="2.5" />
                <vers edition=":x86" num="2.5" />
                <vers edition="" num="2.5.1" />
                <vers edition=":x86" num="2.5.1" />
                <vers edition=":ppc" num="2.5.1" />
            </prod>
            <prod vendor="sun" name="sunos">
                <vers num="4.1.3u1" />
                <vers num="4.1.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0228" seq="1999-0228" severity="Medium" type="CVE" published="1997-02-07" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Denial of service in RPCSS.EXE program (RPC Locator) in Windows NT.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q162567">Q162567</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="windows_nt">
                <vers edition="sp1" num="4.0" />
                <vers edition="sp2" num="4.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0109" seq="1999-0109" severity="High" type="CVE" published="1997-02-10" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow in ffbconfig in Solaris 2.5.1.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/140">00140</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers edition="" num="2.5" />
                <vers edition=":x86" num="2.5" />
                <vers edition="" num="2.5.1" />
                <vers edition=":x86" num="2.5.1" />
                <vers edition=":ppc" num="2.5.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0041" seq="1999-0041" severity="High" type="CVE" published="1997-02-13" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow in NLS (Natural Language Service).</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="gnu" name="libc">
                <vers num="5.0.9" />
                <vers num="5.2.18" />
                <vers num="5.3.12" />
            </prod>
            <prod vendor="cray" name="unicos">
                <vers edition="" num="1.5" />
                <vers edition=":mk" num="1.5" />
                <vers num="9.0" />
                <vers num="9.2" />
            </prod>
            <prod vendor="cray" name="unicos_max">
                <vers num="1.3" />
            </prod>
            <prod vendor="ibm" name="aix">
                <vers num="3.2.5" />
                <vers num="4.1" />
                <vers num="4.2" />
            </prod>
            <prod vendor="redhat" name="linux">
                <vers num="4.0" />
            </prod>
            <prod vendor="slackware" name="slackware_linux">
                <vers num="3.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0868" seq="1999-0868" severity="High" type="CVE" published="1997-02-20" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">ucbmail allows remote attackers to execute commands via shell metacharacters that are passed to it from INN.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="isc" name="inn">
                <vers num="1.5.1" />
            </prod>
            <prod vendor="netscape" name="news_server">
                <vers num="1.1" />
            </prod>
            <prod vendor="nec" name="goah_intrasv">
                <vers num="r1.1" />
            </prod>
            <prod vendor="nec" name="goah_networksv">
                <vers num="r1.2" />
                <vers num="r2.2" />
                <vers num="r3.1" />
            </prod>
            <prod vendor="sun" name="sparc">
                <vers num="" />
            </prod>
            <prod vendor="redhat" name="linux">
                <vers num="4.0" />
                <vers num="4.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)" CVSS_base_score="0.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="0.0" name="CVE-1999-0612" seq="1999-0612" severity="Low" type="CVE" published="1997-03-01" CVSS_version="2.0" CVSS_score="0.0" modified="2008-09-09">
        <desc>
            <descript source="cve">A version of finger is running that exposes valid user information to any entity on the network.</descript>
        </desc>
        <impacts>
            <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
        </impacts>
        <sols>
            <sol source="nvd">The FTP Service should be disabled because it could reveal information about a host's users, which could be used as reconnaissance information for attacks.</sol>
        </sols>
        <vuln_types>
            <other />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="gnu" name="finger_service">
                <vers num="" />
            </prod>
            <prod vendor="gnu" name="fingerd">
                <vers num="" />
            </prod>
            <prod vendor="microsoft" name="windows_2000">
                <vers num="" />
            </prod>
            <prod vendor="microsoft" name="windows_nt">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-1999-0105" seq="1999-0105" severity="Low" type="CVE" published="1997-03-01" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-09">
        <desc>
            <descript source="cve">finger allows recursive searches by using a long string of @ symbols.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <other />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-1999-0106" seq="1999-0106" severity="Low" type="CVE" published="1997-03-01" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-09">
        <desc>
            <descript source="cve">Finger redirection allows finger bombs.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <other />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-0165" seq="1999-0165" severity="High" type="CVE" published="1997-03-01" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-09">
        <desc>
            <descript source="cve">NFS cache poisoning.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="sun" name="nfs">
                <vers num="" />
            </prod>
            <prod vendor="bsdi" name="bsd_os">
                <vers num="" />
            </prod>
            <prod vendor="linux" name="linux_kernel">
                <vers num="2.6.20.1" />
            </prod>
            <prod vendor="sun" name="solaris">
                <vers num="1.1" />
                <vers num="1.1.1a" />
                <vers num="1.1.2" />
                <vers num="1.2" />
                <vers num="2.0" />
                <vers num="2.1" />
                <vers num="2.2" />
                <vers num="2.3" />
                <vers edition="" num="2.4" />
                <vers edition=":x86" num="2.4" />
            </prod>
            <prod vendor="sun" name="sunos">
                <vers num="3.5" />
                <vers num="4.0" />
                <vers num="4.0.1" />
                <vers num="4.0.2" />
                <vers num="4.0.3" />
                <vers num="4.1" />
                <vers num="4.1.1" />
                <vers num="4.1.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0318" seq="1999-0318" severity="High" type="CVE" published="1997-03-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow in xmcd 2.0p12 allows local users to gain access through an environmental variable.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="11" />
            </prod>
            <prod vendor="ibm" name="aix">
                <vers num="4" />
            </prod>
            <prod vendor="redhat" name="linux">
                <vers num="6.0" />
            </prod>
            <prod vendor="sun" name="solaris">
                <vers num="2.5.1" />
                <vers num="2.6" />
                <vers num="7.0" />
                <vers num="8.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" name="CVE-1999-1128" seq="1999-1128" severity="Medium" type="CVE" published="1997-03-01" CVSS_version="2.0 incomplete approximation" CVSS_score="5.1" modified="2008-09-10">
        <desc>
            <descript source="cve">Internet Explorer 3.01 on Windows 95 allows remote malicious web sites to execute arbitrary commands via a .isp file, which is automatically downloaded and executed without prompting the user.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="MISC" url="http://oliver.efri.hr/~crv/security/bugs/NT/ie3.html">http://oliver.efri.hr/~crv/security/bugs/NT/ie3.html</ref>
            <ref source="MISC" url="http://members.tripod.com/~unibyte/iebug3.htm">http://members.tripod.com/~unibyte/iebug3.htm</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="ie">
                <vers num="3.0.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1489" seq="1999-1489" severity="High" type="CVE" published="1997-03-04" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in TestChip function in XFree86 SuperProbe in Slackware Linux 3.1 allows local users to gain root privileges via a long -nopr argument.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/364" adv="1">364</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/6384" adv="1">19970304 Linux SuperProbe exploit</ref>
        </refs>
        <vuln_soft>
            <prod vendor="slackware" name="slackware_linux">
                <vers num="3.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-1999-0299" seq="1999-0299" severity="High" type="CVE" published="1997-03-05" CVSS_version="2.0" CVSS_score="9.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in FreeBSD lpd through long DNS hostnames.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="OSVDB" url="http://www.osvdb.org/6093">6093</ref>
        </refs>
        <vuln_soft>
            <prod vendor="freebsd" name="freebsd">
                <vers edition="stable" num="6.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-1999-1408" seq="1999-1408" severity="Low" type="CVE" published="1997-03-05" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the socket, then using the same socket to connect to a different port on localhost.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/352" adv="1">352</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420641&amp;w=2">19970305 Bug in connect() for aix 4.1.4 ?</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="10.01" />
                <vers num="10.20" />
                <vers num="9.05" />
            </prod>
            <prod vendor="ibm" name="aix">
                <vers num="4.1" />
                <vers num="4.1.1" />
                <vers num="4.1.2" />
                <vers num="4.1.3" />
                <vers num="4.1.4" />
                <vers num="4.1.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" name="CVE-1999-1525" seq="1999-1525" severity="Medium" type="CVE" published="1997-03-14" CVSS_version="2.0 incomplete approximation" CVSS_score="5.1" modified="2008-09-05">
        <desc>
            <descript source="cve">Macromedia Shockwave before 6.0 allows a malicious webmaster to read a user's mail box and possibly access internal web servers via the GetNextText command on a Shockwave movie.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/460.php" adv="1">http-ns-shockwave(460)</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/1586.php" adv="1">shockwave-file-read-vuln(1586)</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/1585.php" adv="1">shockwave-internal-access(1585)</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420670&amp;w=2" adv="1">19970314 Shockwave Security Alert</ref>
        </refs>
        <vuln_soft>
            <prod vendor="macromedia" name="shockwave_flash_plugin">
                <vers num="6.0" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0292" seq="1999-0292" severity="Medium" type="CVE" published="1997-04-01" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Denial of service through Winpopup using large user names.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="microsoft" name="windows_nt">
                <vers edition="sp1" num="4.0" />
                <vers edition="sp2" num="4.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0315" seq="1999-0315" severity="High" type="CVE" published="1997-04-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow in Solaris fdformat command gives root access to local users.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/138">00138</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers num="2.3" />
                <vers edition="" num="2.4" />
                <vers edition=":x86" num="2.4" />
                <vers edition="" num="2.5" />
                <vers edition=":x86" num="2.5" />
                <vers edition="" num="2.5.1" />
                <vers edition=":x86" num="2.5.1" />
                <vers num="2.6" />
                <vers num="7.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0280" seq="1999-0280" severity="High" type="CVE" published="1997-04-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">Remote command execution in Microsoft Internet Explorer using .lnk and .url files.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="microsoft" name="ie">
                <vers num="3.0" />
                <vers num="3.0.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-1387" seq="1999-1387" severity="Medium" type="CVE" published="1997-04-02" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Windows NT 4.0 SP2 allows remote attackers to cause a denial of service (crash), possibly via malformed inputs or packets, such as those generated by a Linux smbmount command that was compiled on the Linux 2.0.29 kernel but executed on Linux 2.0.25.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <env />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420741&amp;w=2" adv="1">19970407 DUMP of NT system crash</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420732&amp;w=2" adv="1">19970403 Fatal bug in NT 4.0 server (more comments)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420731&amp;w=2" adv="1">19970402 Fatal bug in NT 4.0 server</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="windows_nt">
                <vers edition="sp2" num="4.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-0042" seq="1999-0042" severity="High" type="CVE" published="1997-04-07" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow in University of Washington's implementation of IMAP and POP servers.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="university_of_washington" name="imap">
                <vers num="4" />
            </prod>
            <prod vendor="university_of_washington" name="pop">
                <vers num="3" />
            </prod>
            <prod vendor="bsdi" name="bsd_os">
                <vers num="2.1" />
                <vers num="3.0" />
            </prod>
            <prod vendor="caldera" name="openlinux">
                <vers num="1.0" />
            </prod>
            <prod vendor="ibm" name="aix">
                <vers num="4.2.1" />
            </prod>
            <prod vendor="redhat" name="linux">
                <vers num="2.0" />
                <vers num="4.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-1298" seq="1999-1298" severity="High" type="CVE" published="1997-04-07" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Sysinstall in FreeBSD 2.2.1 and earlier, when configuring anonymous FTP, creates the ftp user without a password and with /bin/date as the shell, which could allow attackers to gain access to certain system resources.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="FREEBSD" patch="1" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-97:03.sysinstall.asc" adv="1">FreeBSD-SA-97:03</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/6087">6087</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/7537.php">freebsd-sysinstall-ftp-password(7537)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="freebsd" name="freebsd">
                <vers num="2.1.0" />
                <vers num="2.1.5" />
                <vers num="2.1.6" />
                <vers num="2.1.7" />
                <vers num="2.2" />
                <vers num="2.2.1" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0058" seq="1999-0058" severity="High" type="CVE" published="1997-04-17" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow in PHP cgi program, php.cgi allows shell access.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/712">712</ref>
        </refs>
        <vuln_soft>
            <prod vendor="php" name="php">
                <vers num="1.0" />
                <vers num="2.0b10" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0149" seq="1999-0149" severity="High" type="CVE" published="1997-04-19" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">The wrap CGI program in IRIX allows remote attackers to view arbitrary directory listings via a .. (dot dot) attack.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/290">http-sgi-wrap(290)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/373">373</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/247">247</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX">19970501-02-PX</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sgi" name="irix">
                <vers num="6.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0038" seq="1999-0038" severity="High" type="CVE" published="1997-04-26" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow in xlock program allows local users to execute commands as root.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="data_general" name="dg_ux">
                <vers num="1.0" />
                <vers num="2.0" />
                <vers num="3.0" />
                <vers num="4.0" />
                <vers num="5.0" />
                <vers num="6.0" />
                <vers num="7.0" />
            </prod>
            <prod vendor="bsdi" name="bsd_os">
                <vers num="2.1" />
            </prod>
            <prod vendor="debian" name="debian_linux">
                <vers num="0.93" />
                <vers num="1.1" />
                <vers num="1.2" />
                <vers num="1.3" />
            </prod>
            <prod vendor="hp" name="hp-ux">
                <vers num="10.00" />
                <vers num="10.01" />
                <vers num="10.08" />
                <vers num="10.10" />
                <vers num="10.16" />
                <vers num="10.20" />
                <vers num="10.24" />
                <vers num="10.30" />
                <vers num="10.34" />
            </prod>
            <prod vendor="ibm" name="aix">
                <vers num="3.2" />
                <vers num="4.1" />
                <vers num="4.2" />
            </prod>
            <prod vendor="sgi" name="irix">
                <vers num="5.0" />
                <vers num="5.0.1" />
                <vers num="5.1" />
                <vers num="5.1.1" />
                <vers num="5.2" />
                <vers edition="" num="5.3" />
                <vers edition=":xfs" num="5.3" />
                <vers num="6.0" />
                <vers edition="" num="6.0.1" />
                <vers edition=":xfs" num="6.0.1" />
                <vers num="6.1" />
                <vers num="6.3" />
                <vers num="6.4" />
            </prod>
            <prod vendor="sun" name="solaris">
                <vers num="2.3" />
                <vers edition="" num="2.4" />
                <vers edition=":x86" num="2.4" />
                <vers edition="" num="2.5" />
                <vers edition=":x86" num="2.5" />
                <vers edition="" num="2.5.1" />
                <vers edition=":ppc" num="2.5.1" />
                <vers edition=":x86" num="2.5.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1296" seq="1999-1296" severity="High" type="CVE" published="1997-04-29" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in Kerberos IV compatibility libraries as used in Kerberos V allows local users to gain root privileges via a long line in a kerberos configuration file, which can be specified via the KRB_CONF environmental variable.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420878&amp;w=2" adv="1">19970429 vulnerabilities in kerberos</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mit" name="kerberos">
                <vers num="5-1.5.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0040" seq="1999-0040" severity="High" type="CVE" published="1997-05-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="bsdi" name="bsd_os">
                <vers num="2.0" />
                <vers num="2.0.1" />
                <vers num="2.1" />
            </prod>
            <prod vendor="freebsd" name="freebsd">
                <vers num="1.1.5.1" />
                <vers num="2.0" />
            </prod>
            <prod vendor="hp" name="hp-ux">
                <vers num="10.00" />
                <vers num="10.01" />
                <vers num="10.08" />
                <vers num="10.09" />
                <vers num="10.10" />
                <vers num="10.16" />
                <vers num="10.20" />
                <vers num="10.24" />
                <vers num="10.30" />
                <vers num="10.34" />
                <vers num="9.00" />
                <vers num="9.01" />
                <vers num="9.10" />
            </prod>
            <prod vendor="ibm" name="aix">
                <vers num="3.2" />
                <vers num="4.1" />
                <vers num="4.2" />
            </prod>
            <prod vendor="nec" name="asl_ux_4800">
                <vers num="64" />
            </prod>
            <prod vendor="nec" name="ews-ux_v">
                <vers num="4.2" />
                <vers num="4.2mp" />
            </prod>
            <prod vendor="nec" name="up-ux_v">
                <vers num="4.2mp" />
            </prod>
            <prod vendor="sgi" name="irix">
                <vers num="4.0" />
                <vers num="5.0" />
                <vers num="5.3" />
                <vers num="6.0" />
                <vers num="6.1" />
                <vers num="6.2" />
                <vers num="6.3" />
                <vers num="6.4" />
            </prod>
            <prod vendor="sun" name="solaris">
                <vers num="2.3" />
                <vers edition="" num="2.4" />
                <vers edition=":x86" num="2.4" />
                <vers edition="" num="2.5" />
                <vers edition=":x86" num="2.5" />
                <vers edition="" num="2.5.1" />
                <vers edition=":x86" num="2.5.1" />
            </prod>
            <prod vendor="sun" name="sunos">
                <vers num="4.1.3" />
                <vers num="4.1.3u1" />
                <vers num="4.1.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0112" seq="1999-0112" severity="High" type="CVE" published="1997-05-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow in AIX dtterm program for the CDE.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/878">dtterm-bo(878)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="cde" name="cde">
                <vers num="" />
            </prod>
            <prod vendor="ibm" name="aix">
                <vers num="4.1" />
                <vers num="4.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1116" seq="1999-1116" severity="High" type="CVE" published="1997-05-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Vulnerability in runpriv in Indigo Magic System Administration subsystem of SGI IRIX 6.3 and 6.4 allows local users to gain root privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/2108.php" adv="1">sgi-runpriv(2108)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/462" adv="1">462</ref>
            <ref source="SGI" patch="1" url="ftp://patches.sgi.com/support/free/security/advisories/19970503-01-PX" adv="1">19970503-01-PX</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/1009">1009</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sgi" name="irix">
                <vers num="6.3" />
                <vers num="6.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" name="CVE-1999-1380" seq="1999-1380" severity="Medium" type="CVE" published="1997-05-04" CVSS_version="2.0 incomplete approximation" CVSS_score="5.1" modified="2008-09-05">
        <desc>
            <descript source="cve">Symantec Norton Utilities 2.0 for Windows 95 marks the TUNEOCX.OCX ActiveX control as safe for scripting, which allows remote attackers to execute arbitrary commands via the run option through malicious web pages that are accessed by browsers such as Internet Explorer 3.0.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
            <env />
        </vuln_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="MISC" patch="1" url="http://mlarchive.ima.com/win95/1997/May/0342.html" adv="1">http://mlarchive.ima.com/win95/1997/May/0342.html</ref>
            <ref source="MISC" url="http://www.net-security.sk/bugs/NT/nu20.html">http://www.net-security.sk/bugs/NT/nu20.html</ref>
            <ref source="MISC" url="http://news.zdnet.co.uk/story/0,,s2065518,00.html" adv="1">http://news.zdnet.co.uk/story/0,,s2065518,00.html</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/7188.php">nu-tuneocx-activex-control(7188)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="symantec" name="norton_utilities">
                <vers num="2.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-1267" seq="1999-1267" severity="Medium" type="CVE" published="1997-05-05" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">KDE file manager (kfm) uses a TCP server for certain file operations, which allows remote attackers to modify arbitrary files by sending a copy command to the server.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/1646.php" adv="1">kde-flawed-ipc(1646)</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420906&amp;w=2" adv="1">19970505 Hole in the KDE desktop</ref>
        </refs>
        <vuln_soft>
            <prod vendor="kde" name="kde">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0039" seq="1999-0039" severity="High" type="CVE" published="1997-05-06" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">webdist CGI program (webdist.cgi) in SGI IRIX allows remote attackers to execute arbitrary commands via shell metacharacters in the distloc parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" url="http://www.cert.org/advisories/CA-1997-12.html">CA-1997-12</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/333">http-sgi-webdist(333)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/374">374</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/235">235</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX">19970501-02-PX</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sgi" name="irix">
                <vers num="5.0" />
                <vers num="5.1" />
                <vers num="5.2" />
                <vers num="5.3" />
                <vers num="6.1" />
                <vers num="6.2" />
                <vers num="6.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-1067" seq="1999-1067" severity="Medium" type="CVE" published="1997-05-07" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">SGI MachineInfo CGI program, installed by default on some web servers, prints potentially sensitive system status information, which could be used by remote attackers for information gathering activities.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420919&amp;w=2">19970507 Re: SGI Security Advisory 19970501-01-A - Vulnerability in webdist.cgi</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sgi" name="irix">
                <vers num="6.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" name="CVE-1999-1398" seq="1999-1398" severity="Medium" type="CVE" published="1997-05-07" CVSS_version="2.0 incomplete approximation" CVSS_score="6.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Vulnerability in xfsdump in SGI IRIX may allow local users to obtain root privileges via the bck.log log file, possibly via a symlink attack.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <race />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/472" adv="1">472</ref>
            <ref source="MISC" url="http://www.insecure.org/sploits/irix.xfsdump.html">http://www.insecure.org/sploits/irix.xfsdump.html</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420921&amp;w=2" adv="1">19970507 Irix: misc</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sgi" name="irix">
                <vers num="5.0" />
                <vers num="5.0.1" />
                <vers num="5.1" />
                <vers num="5.1.1" />
                <vers num="5.2" />
                <vers edition="" num="5.3" />
                <vers edition=":xfs" num="5.3" />
                <vers num="6.0" />
                <vers edition="" num="6.0.1" />
                <vers edition=":xfs" num="6.0.1" />
                <vers num="6.1" />
                <vers num="6.2" />
                <vers num="6.3" />
                <vers num="6.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1461" seq="1999-1461" severity="High" type="CVE" published="1997-05-07" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-10">
        <desc>
            <descript source="cve">inpview in InPerson on IRIX 5.3 through IRIX 6.5.10 trusts the PATH environmental variable to find and execute the ttsession program, which allows local users to obtain root access by modifying the PATH to point to a Trojan horse ttsession program.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/381" adv="1">381</ref>
            <ref source="SGI" patch="1" url="ftp://patches.sgi.com/support/free/security/advisories/20001101-01-I" adv="1">20001101-01-I</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420921&amp;w=2">19970507 Irix: misc</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sgi" name="irix">
                <vers num="5.3" />
                <vers num="6.1" />
                <vers num="6.2" />
                <vers num="6.3" />
                <vers num="6.4" />
                <vers num="6.5.10" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" name="CVE-1999-1410" seq="1999-1410" severity="Medium" type="CVE" published="1997-05-09" CVSS_version="2.0 incomplete approximation" CVSS_score="6.2" modified="2008-09-05">
        <desc>
            <descript source="cve">addnetpr in IRIX 5.3 and 6.2 allows local users to overwrite arbitrary files and possibly gain root privileges via a symlink attack on the printers temporary file.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <race />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/330" adv="1">330</ref>
            <ref source="MISC" patch="1" url="ftp://patches.sgi.com/support/free/security/advisories/19961203-02-PX" adv="1">ftp://patches.sgi.com/support/free/security/advisories/19961203-02-PX</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420927&amp;w=2">19970509 Re: Irix: misc</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sgi" name="irix">
                <vers num="5.0" />
                <vers num="5.0.1" />
                <vers num="5.1" />
                <vers num="5.1.1" />
                <vers num="5.2" />
                <vers num="5.3" />
                <vers edition="" num="6.0.1" />
                <vers edition=":xfs" num="6.0.1" />
                <vers num="6.1" />
                <vers num="6.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1286" seq="1999-1286" severity="High" type="CVE" published="1997-05-09" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">addnetpr in SGI IRIX 6.2 and earlier allows local users to modify arbitrary files and possibly gain root access via a symlink attack on a temporary file.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/1433.php" adv="1">irix-addnetpr(1433)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420927&amp;w=2" adv="1">19970509 Re: Irix: misc</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/330">330</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/8560">8560</ref>
            <ref source="MISC" url="ftp://patches.sgi.com/support/free/security/advisories/19961203-02-PX">ftp://patches.sgi.com/support/free/security/advisories/19961203-02-PX</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sgi" name="irix">
                <vers num="5.3" />
                <vers num="6.2" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1158" seq="1999-1158" severity="High" type="CVE" published="1997-05-13" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in (1) pluggable authentication module (PAM) on Solaris 2.5.1 and 2.5 and (2) unix_scheme in Solaris 2.4 and 2.3 allows local users to gain root privileges via programs that use these modules such as passwd, yppasswd, and nispasswd.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="SUN" patch="1" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/139&amp;type=0&amp;nav=sec.sba" adv="1">00139</ref>
            <ref source="AUSCERT" url="ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-97.09.Solaris.passwd.buffer.overrun.vul">AA-97.09</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers num="2.3" />
                <vers num="2.4" />
                <vers num="2.5" />
                <vers num="2.5.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-1999-1184" seq="1999-1184" severity="Medium" type="CVE" published="1997-05-13" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in Elm 2.4 and earlier allows local users to gain privileges via a long TERM environmental variable.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420970&amp;w=2" adv="1">19970514 Re: ELM overflow</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420967&amp;w=2" adv="1">19970513</ref>
        </refs>
        <vuln_soft>
            <prod vendor="elm_development_group" name="elm">
                <vers num="2.3" />
                <vers num="2.4" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0962" seq="1999-0962" severity="High" type="CVE" published="1997-05-14" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow in HPUX passwd command allows local users to gain root privileges via a command line option.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9701-045">HPSBUX9701-045</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/6415">6415</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="10" />
                <vers num="9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-1141" seq="1999-1141" severity="High" type="CVE" published="1997-05-15" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Ascom Timeplex router allows remote attackers to obtain sensitive information or conduct unauthorized activities by entering debug mode through a sequence of CTRL-D characters.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/static/1824.php" adv="1">ascom-timeplex-debug(1824)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420981&amp;w=2">19970515 MicroSolved finds hole in Ascom Timeplex Router Security</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ascom" name="timeplex_routers">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1232" seq="1999-1232" severity="High" type="CVE" published="1997-05-16" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Untrusted search path vulnerability in day5datacopier in SGI IRIX 6.2 allows local users to execute arbitrary commands via a modified PATH environment variable that points to a malicious cp program.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" admin="1" />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/3316.php" adv="1">sgi-day5datacopier(3316)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/8559">8559</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420994&amp;w=2" adv="1">19970516 Irix and WWW</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sgi" name="irix">
                <vers num="6.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-1999-1402" seq="1999-1402" severity="Low" type="CVE" published="1997-05-17" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">The access permissions for a UNIX domain socket are ignored in Solaris 2.x and SunOS 4.x, and other BSD-based operating systems before 4.4, which could allow local users to connect to the socket and possibly disrupt or control the operations of the program using that socket.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/456" adv="1">456</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602248718482&amp;w=2" adv="1">19971003 Solaris 2.6 and sockets</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167418317&amp;w=2" adv="1">19970517 UNIX domain socket (Solarisx86 2.5)</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/7172.php">sun-domain-socket-permissions(7172)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="freebsd" name="freebsd">
                <vers num="2.2.2" />
                <vers num="2.2.3" />
                <vers num="2.2.4" />
                <vers num="2.2.5" />
                <vers num="2.2.6" />
                <vers num="2.2.8" />
                <vers num="3.0" />
                <vers num="3.1" />
            </prod>
            <prod vendor="sun" name="solaris">
                <vers num="2.0" />
                <vers edition="" num="2.5" />
                <vers edition=":x86" num="2.5" />
                <vers edition="" num="2.5.1" />
                <vers edition=":x86" num="2.5.1" />
                <vers edition=":ppc" num="2.5.1" />
                <vers edition="" num="2.6" />
                <vers edition=":x86" num="2.6" />
            </prod>
            <prod vendor="sun" name="sunos">
                <vers num="4.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1191" seq="1999-1191" severity="High" type="CVE" published="1997-05-19" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in chkey in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="AUSCERT" patch="1" url="ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-97.18.solaris.chkey.buffer.overflow.vul" adv="1">AA-97.18</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/207" adv="1">207</ref>
            <ref source="SUN" patch="1" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/144" adv="1">00144</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167418335&amp;w=2" adv="1">19970519 Re: Finally, most of an exploit for Solaris 2.5.1's ps.</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/7442.php">solaris-chkey-bo(7442)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers edition="" num="2.4" />
                <vers edition=":x86" num="2.4" />
                <vers edition="" num="2.5" />
                <vers edition=":x86" num="2.5" />
                <vers edition="" num="2.5.1" prev="1" />
                <vers edition=":x86" num="2.5.1" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-1999-1449" seq="1999-1449" severity="Low" type="CVE" published="1997-05-19" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">SunOS 4.1.4 on a Sparc 20 machine allows local users to cause a denial of service (kernel panic) by reading from the /dev/tcx0 TCX device.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="MISC" url="http://www.insecure.org/sploits/sunos.dev.tcx0.write.wierd.shit.to.device.bug.html" adv="1">http://www.insecure.org/sploits/sunos.dev.tcx0.write.wierd.shit.to.device.bug.html</ref>
            <ref source="BUGTRAQ" url="http://oamk.fi/~jukkao/bugtraq/before-971202/0498.html" adv="1">19970519 /dev/tcx0 crashes SunOS 4.1.4 on Sparc 20's</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="sunos">
                <vers num="4.1.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0037" seq="1999-0037" severity="High" type="CVE" published="1997-05-21" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">Arbitrary command execution via metamail package using message headers, when user processes attacker's message using metamail.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="freebsd" name="freebsd">
                <vers edition="stable" num="6.2" />
            </prod>
            <prod vendor="redhat" name="linux">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0259" seq="1999-0259" severity="Medium" type="CVE" published="1997-05-23" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">cfingerd lists all users on a system via search.**@target.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="infodrom" name="cfingerd">
                <vers num="1.2.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0064" seq="1999-0064" severity="High" type="CVE" published="1997-05-26" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow in AIX lquerylv program gives root access to local users.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="ibm" name="aix">
                <vers num="3.2" />
                <vers num="3.2.4" />
                <vers num="3.2.5" />
                <vers num="4.1" />
                <vers num="4.1.1" />
                <vers num="4.1.2" />
                <vers num="4.1.3" />
                <vers num="4.1.4" />
                <vers num="4.1.5" />
                <vers num="4.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0036" seq="1999-0036" severity="High" type="CVE" published="1997-05-26" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">IRIX login program with a nonzero LOCKOUT parameter allows creation or damage to files.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/557">sgi-lockout(557)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/990">990</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/h-106.shtml">H-106</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970508-02-PX">19970508-02-PX</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sgi" name="irix">
                <vers num="5.1" />
                <vers num="5.2" />
                <vers num="5.3" />
                <vers num="6.0" />
                <vers num="6.1" />
                <vers num="6.2" />
                <vers num="6.3" />
                <vers num="6.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1143" seq="1999-1143" severity="High" type="CVE" published="1997-05-28" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Vulnerability in runtime linker program rld in SGI IRIX 6.x and earlier allows local users to gain privileges via setuid and setgid programs.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/2109.php" adv="1">sgi-rld(2109)</ref>
            <ref source="CIAC" patch="1" url="http://ciac.llnl.gov/ciac/bulletins/h-65.shtml" adv="1">H-065</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970504-01-PX">19970504-01-PX</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sgi" name="irix">
                <vers num="5" />
                <vers num="6.0" prev="1" />
                <vers num="6.0.1" />
                <vers num="6.1" />
                <vers num="6.2" />
                <vers num="6.3" />
                <vers num="6.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0034" seq="1999-0034" severity="High" type="CVE" published="1997-05-29" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow in suidperl (sperl), Perl 4.x and 5.x.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="larry_wall" name="perl">
                <vers num="5.3" />
            </prod>
            <prod vendor="sgi" name="freeware">
                <vers num="1.0" />
                <vers num="2.0" />
            </prod>
            <prod vendor="bsdi" name="bsd_os">
                <vers num="2.1" />
                <vers num="3.0" />
            </prod>
            <prod vendor="redhat" name="linux">
                <vers num="4.0" />
                <vers num="4.1" />
                <vers num="4.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" name="CVE-1999-0035" seq="1999-0035" severity="Medium" type="CVE" published="1997-05-29" CVSS_version="2.0 incomplete approximation" CVSS_score="5.1" modified="2008-09-09">
        <desc>
            <descript source="cve">Race condition in signal handling routine in ftpd, allowing read/write arbitrary files.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <config />
            <race />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="gnu" name="inet">
                <vers num="5.01" />
            </prod>
            <prod vendor="sgi" name="irix">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-1999-0144" seq="1999-0144" severity="Low" type="CVE" published="1997-06-01" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2005-10-20">
        <desc>
            <descript source="cve">Denial of service in Qmail by specifying a large number of recipients with the RCPT command.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <other />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/static/208.php" adv="1">qmail-rcpt</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/2237">2237</ref>
            <ref source="MISC" url="http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html">http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html</ref>
            <ref source="MISC" url="http://cr.yp.to/qmail/venema.html">http://cr.yp.to/qmail/venema.html</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319029&amp;w=2">19970612 Re: Denial of service (qmail-smtpd)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319024&amp;w=2">19970612 qmail-dos-2.c, another denial of service attack</ref>
        </refs>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0281" seq="1999-0281" severity="Medium" type="CVE" published="1997-06-01" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Denial of service in IIS using long URLs.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="microsoft" name="internet_information_server">
                <vers num="2.0" />
                <vers num="3.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0227" seq="1999-0227" severity="Medium" type="CVE" published="1997-06-01" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Access violation in LSASS.EXE (LSA/LSARPC) program in Windows NT allows a denial of service.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q154087">Q154087</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="windows_nt">
                <vers num="4.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-0799" seq="1999-0799" severity="High" type="CVE" published="1997-06-01" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow in bootpd 2.4.3 and earlier via a long boot file location.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="cmu" name="bootpd">
                <vers num="2.4.3" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0189" seq="1999-0189" severity="High" type="CVE" published="1997-06-04" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <access />
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/142">00142</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers num="2.3" />
                <vers edition="" num="2.4" />
                <vers edition=":x86" num="2.4" />
                <vers edition="" num="2.5" />
                <vers edition=":x86" num="2.5" />
                <vers edition="" num="2.5.1" />
                <vers edition=":x86" num="2.5.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0275" seq="1999-0275" severity="Medium" type="CVE" published="1997-06-10" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Denial of service in Windows NT DNS servers by flooding port 53 with too many characters.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="microsoft" name="windows_nt">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0083" seq="1999-0083" severity="Medium" type="CVE" published="1997-06-11" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">getcwd() file descriptor leak in FTP.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="sgi" name="irix">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0033" seq="1999-0033" severity="High" type="CVE" published="1997-06-12" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">Command execution in Sun systems via buffer overflow in the at program.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="ncr" name="mp-ras">
                <vers num="3.0" />
            </prod>
            <prod vendor="ibm" name="aix">
                <vers num="" />
            </prod>
            <prod vendor="sco" name="open_desktop">
                <vers num="3.0" />
            </prod>
            <prod vendor="sco" name="openserver">
                <vers num="3.0" />
                <vers num="5.0" />
            </prod>
            <prod vendor="sco" name="unixware">
                <vers num="2.1" />
                <vers num="3.2v4" />
            </prod>
            <prod vendor="sgi" name="irix">
                <vers num="" />
            </prod>
            <prod vendor="sun" name="sunos">
                <vers num="5.3" />
                <vers edition="" num="5.4" />
                <vers edition=":x86" num="5.4" />
                <vers edition="" num="5.5" />
                <vers edition=":x86" num="5.5" />
                <vers edition="" num="5.5.1" />
                <vers edition=":x86" num="5.5.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-1266" seq="1999-1266" severity="Medium" type="CVE" published="1997-06-13" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">rsh daemon (rshd) generates different error messages when a valid username is provided versus an invalid name, which allows remote attackers to determine valid users on the system.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/1660.php" adv="1">rsh-username-leaks(1660)</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/6978" adv="1">19970613 rshd gives away usernames</ref>
        </refs>
        <vuln_soft>
            <prod vendor="metamail_corporation" name="metamail">
                <vers num="7.2" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-1999-0957" seq="1999-0957" severity="Low" type="CVE" published="1997-06-18" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-09">
        <desc>
            <descript source="cve">MajorCool mj_key_cache program allows local users to modify files via a symlink attack.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="great_circle_associates" name="majorcool">
                <vers num="1.0.3" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-1999-1483" seq="1999-1483" severity="Medium" type="CVE" published="1997-06-19" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in zgv in svgalib 1.2.10 and earlier allows local users to execute arbitrary code via a long HOME environment variable.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/7041" adv="1">19970619 svgalib/zgv</ref>
        </refs>
        <vuln_soft>
            <prod vendor="svgalib" name="svgalib">
                <vers num="1.2.10" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1192" seq="1999-1192" severity="High" type="CVE" published="1997-06-24" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in eeprom in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/206" adv="1">206</ref>
            <ref source="SUN" patch="1" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/143" adv="1">00143</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/7444.php">solaris-eeprom-bo(7444)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers num="2.3" />
                <vers num="2.4" />
                <vers num="2.5" />
                <vers num="2.5.1" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-1999-1423" seq="1999-1423" severity="Low" type="CVE" published="1997-06-26" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">ping in Solaris 2.3 through 2.6 allows local users to cause a denial of service (crash) via a ping request to a multicast address through the loopback interface, e.g. via ping -i.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/209" adv="1">209</ref>
            <ref source="SUN" patch="1" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/146" adv="1">00146</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319180&amp;w=2" adv="1">19971005 Solaris Ping Bug and other [bc] oddities</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319171&amp;w=2">19970627 SUMMARY: Solaris Ping bug (DoS)</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319160&amp;w=2" adv="1">19970626 Solaris Ping bug (DoS)</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/7492.php">ping-multicast-loopback-dos(7492)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319181&amp;w=2">19970627 Solaris Ping bug(inetsvc)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers num="2.3" />
                <vers edition="" num="2.4" />
                <vers edition=":x86" num="2.4" />
                <vers edition="" num="2.5" />
                <vers edition=":x86" num="2.5" />
                <vers edition="" num="2.5.1" />
                <vers edition=":x86" num="2.5.1" />
                <vers edition=":ppc" num="2.5.1" />
                <vers num="2.6" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0628" seq="1999-0628" severity="Medium" type="CVE" published="1997-07-01" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">The rwho/rwhod service is running, which exposes machine status and user information.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="freebsd" name="freebsd">
                <vers edition="stable" num="6.2" />
            </prod>
            <prod vendor="ibm" name="aix">
                <vers num="4.2" />
            </prod>
            <prod vendor="linux" name="linux_kernel">
                <vers num="2.6.20.1" />
            </prod>
            <prod vendor="netbsd" name="netbsd">
                <vers num="2.0.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" name="CVE-1999-0074" seq="1999-0074" severity="Medium" type="CVE" published="1997-07-01" CVSS_version="2.0 incomplete approximation" CVSS_score="6.4" modified="2008-09-09">
        <desc>
            <descript source="cve">Listening TCP ports are sequentially allocated, allowing spoofing attacks.</descript>
        </desc>
        <loss_types>
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="freebsd" name="freebsd">
                <vers edition="stable" num="6.2" />
            </prod>
            <prod vendor="linux" name="linux_kernel">
                <vers num="2.6.20.1" />
            </prod>
            <prod vendor="microsoft" name="windows_nt">
                <vers num="" />
            </prod>
            <prod vendor="netbsd" name="netbsd">
                <vers num="2.0.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0076" seq="1999-0076" severity="Medium" type="CVE" published="1997-07-01" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow in wu-ftp from PASV command causes a core dump.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="washington_university" name="wu-ftpd">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0111" seq="1999-0111" severity="Medium" type="CVE" published="1997-07-01" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">RIP v1 is susceptible to spoofing.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="ibm" name="aix">
                <vers num="3.2" />
                <vers num="4.1" />
                <vers num="4.2" />
                <vers num="4.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" name="CVE-1999-0219" seq="1999-0219" severity="High" type="CVE" published="1997-07-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.8" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow in FTP Serv-U 2.5 allows remote authenticated users to cause a denial of service (crash) via a long (1) CWD or (2) LS (list) command.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/205">ftp-servu(205)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/269">269</ref>
            <ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92582581330282&amp;w=2">19990504 Re: Buffer overflows in FTP Serv-U 2.5</ref>
            <ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92574916930144&amp;w=2">19990503 Buffer overflows in FTP Serv-U 2.5</ref>
        </refs>
        <vuln_soft>
            <prod vendor="cat_soft" name="serv-u">
                <vers num="2.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-0250" seq="1999-0250" severity="High" type="CVE" published="1997-07-01" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Denial of service in Qmail through long SMTP commands.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MISC" url="http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html">http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html</ref>
            <ref source="MISC" url="http://cr.yp.to/qmail/venema.html">http://cr.yp.to/qmail/venema.html</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319024&amp;w=2">19970612 qmail-dos-2.c, another denial of service attack</ref>
        </refs>
        <vuln_soft>
            <prod vendor="dan_bernstein" name="qmail">
                <vers num="1.01" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" name="CVE-1999-0184" seq="1999-0184" severity="Medium" type="CVE" published="1997-07-01" CVSS_version="2.0 incomplete approximation" CVSS_score="6.4" modified="2008-09-09">
        <desc>
            <descript source="cve">When compiled with the -DALLOW_UPDATES option, bind allows dynamic updates to the DNS server, allowing for malicious modification of DNS records.</descript>
        </desc>
        <loss_types>
            <avail />
            <int />
        </loss_types>
        <vuln_types>
            <access />
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="isc" name="bind">
                <vers num="9.4.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0195" seq="1999-0195" severity="Medium" type="CVE" published="1997-07-01" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Denial of service in RPC portmapper allows attackers to register or unregister RPC services or spoof RPC services using a spoofed source IP address such as 127.0.0.1.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="linux" name="linux_kernel">
                <vers num="2.6.20.1" />
            </prod>
            <prod vendor="sgi" name="irix">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0150" seq="1999-0150" severity="High" type="CVE" published="1997-07-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">The Perl fingerd program allows arbitrary command execution from remote users.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="gnu" name="fingerd">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0147" seq="1999-0147" severity="High" type="CVE" published="1997-07-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">The aglimpse CGI program of the Glimpse package allows remote execution of arbitrary commands.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="university_of_arizona" name="glimpse_http">
                <vers num="2.0" />
            </prod>
            <prod vendor="university_of_arizona" name="webglimpse">
                <vers num="1.5" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-1999-0156" seq="1999-0156" severity="Medium" type="CVE" published="1997-07-01" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-09">
        <desc>
            <descript source="cve">wu-ftpd FTP daemon allows any user and password combination.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="washington_university" name="wu-ftpd">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0153" seq="1999-0153" severity="Medium" type="CVE" published="1997-07-01" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="OSVDB" url="http://www.osvdb.org/1666">1666</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="windows_2000">
                <vers num="" />
            </prod>
            <prod vendor="microsoft" name="windows_95">
                <vers num="" />
            </prod>
            <prod vendor="microsoft" name="windows_nt">
                <vers num="" />
            </prod>
            <prod vendor="sco" name="openserver">
                <vers num="5.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-0169" seq="1999-0169" severity="High" type="CVE" published="1997-07-01" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-09">
        <desc>
            <descript source="cve">NFS allows attackers to read and write any file on the system by specifying a false UID.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="sun" name="nfs">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)" CVSS_base_score="0.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="0.0" name="CVE-1999-0532" seq="1999-0532" severity="Low" type="CVE" published="1997-07-01" CVSS_version="2.0" CVSS_score="0.0" modified="2008-09-09">
        <desc>
            <descript source="cve">A DNS server allows zone transfers.</descript>
        </desc>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0533" seq="1999-0533" severity="High" type="CVE" published="1997-07-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">A DNS server allows inverse queries.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <other />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0541" seq="1999-0541" severity="High" type="CVE" published="1997-07-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">A password for accessing a WWW URL is guessable.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <other />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-0526" seq="1999-0526" severity="High" type="CVE" published="1997-07-01" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-09">
        <desc>
            <descript source="cve">An X server's access control is disabled (e.g. through an "xhost +" command) and allows anyone to connect to the server.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/704969">VU#704969</ref>
        </refs>
        <vuln_soft>
            <prod vendor="x.org" name="x11">
                <vers num="7.1_1.1.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-1326" seq="1999-1326" severity="Medium" type="CVE" published="1997-07-04" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">wu-ftpd 2.4 FTP server does not properly drop privileges when an ABOR (abort file transfer) command is executed during a file transfer, which causes a signal to be handled incorrectly and allows local and possibly remote attackers to read arbitrary files.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420408&amp;w=2">19970105 BoS:  serious security bug in wu-ftpd v2.4 -- PATCH</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420401&amp;w=2" adv="1">19970104 serious security bug in wu-ftpd v2.4</ref>
            <ref source="XF" url="http://xforce.iss.net/static/7169.php">wuftpd-abor-gain-privileges(7169)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="washington_university" name="wu-ftpd">
                <vers num="2.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0196" seq="1999-0196" severity="Medium" type="CVE" published="1997-07-08" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">websendmail in Webgais 1.0 allows a remote user to access arbitrary files and execute arbitrary code via the receiver parameter ($VAR_receiver variable).</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/2077">2077</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/237">237</ref>
        </refs>
        <vuln_soft>
            <prod vendor="webgais_development_team" name="webgais">
                <vers num="1.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" name="CVE-1999-0031" seq="1999-0031" severity="Low" type="CVE" published="1997-07-08" CVSS_version="2.0 incomplete approximation" CVSS_score="2.6" modified="2008-09-09">
        <desc>
            <descript source="cve">JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers to monitor a user's web activities, aka the Bell Labs vulnerability.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="HP" url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9707-065.html">HPSBUX9707-065</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="ie">
                <vers num="3.0" />
                <vers num="4.0" />
            </prod>
            <prod vendor="netscape" name="communicator">
                <vers num="2.0" />
                <vers num="3.0" />
                <vers num="4.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0176" seq="1999-0176" severity="High" type="CVE" published="1997-07-10" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">The Webgais program allows a remote user to execute arbitrary commands.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="webgais_development_team" name="webgais">
                <vers num="1.0b2" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-1463" seq="1999-1463" severity="Medium" type="CVE" published="1997-07-10" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Windows NT 4.0 before SP3 allows remote attackers to bypass firewall restrictions or cause a denial of service (crash) by sending improperly fragmented IP packets without the first fragment, which the TCP/IP stack incorrectly reassembles into a valid session.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/528.php" adv="1">nt-frag(528)</ref>
            <ref source="BUGTRAQ" patch="1" url="http://www.securityfocus.com/archive/1/7219" adv="1">19970710 A New Fragmentation Attack</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="windows_nt">
                <vers edition="sp3" num="4.0" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:N/A:N)" CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" name="CVE-1999-0059" seq="1999-0059" severity="High" type="CVE" published="1997-07-14" CVSS_version="2.0" CVSS_score="7.1" modified="2008-09-09">
        <desc>
            <descript source="cve">IRIX fam service allows an attacker to obtain a list of all files on the server.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/325">irix-fam(325)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/353">353</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/164">164</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sgi" name="irix">
                <vers num="5.3" />
                <vers num="6.1" />
                <vers num="6.2" />
                <vers num="6.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0146" seq="1999-0146" severity="High" type="CVE" published="1997-07-15" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">The campas CGI program provided with some NCSA web servers allows an attacker to execute arbitrary commands via encoded carriage return characters in the query string, as demonstrated by reading the password file.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/298">http-cgi-campas(298)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/1975">1975</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ncsa" name="campas">
                <vers num="" />
            </prod>
            <prod vendor="ncsa" name="servers">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0025" seq="1999-0025" severity="High" type="CVE" published="1997-07-16" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">root privileges via buffer overflow in df command on SGI IRIX systems.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/20851">VU#20851</ref>
            <ref source="CERT" url="http://www.cert.org/advisories/CA-1997-21.html">CA-1997-21</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/440">df-bo(440)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/346">346</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sgi" name="irix">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-1999-0026" seq="1999-0026" severity="Medium" type="CVE" published="1997-07-16" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-09">
        <desc>
            <descript source="cve">root privileges via buffer overflow in pset command on SGI IRIX systems.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="sgi" name="irix">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0027" seq="1999-0027" severity="High" type="CVE" published="1997-07-16" CVSS_version="2.0" CVSS_score="7.2" modified="2009-02-25">
        <desc>
            <descript source="cve">root privileges via buffer overflow in eject command on SGI IRIX systems.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="sgi" name="irix">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0028" seq="1999-0028" severity="High" type="CVE" published="1997-07-16" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">root privileges via buffer overflow in login/scheme command on SGI IRIX systems.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="sgi" name="irix">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0029" seq="1999-0029" severity="High" type="CVE" published="1997-07-16" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">root privileges via buffer overflow in ordist command on SGI IRIX systems.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="sgi" name="irix">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0030" seq="1999-0030" severity="High" type="CVE" published="1997-07-16" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">root privileges via buffer overflow in xlock command on SGI IRIX systems.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="sgi" name="irix">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1182" seq="1999-1182" severity="High" type="CVE" published="1997-07-17" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in run-time linkers (1) ld.so or (2) ld-linux.so for Linux systems allows local users to gain privileges by calling a setuid program with a long program name (argv[0]) and forcing ld.so/ld-linux.so to report an error.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602661419351&amp;w=2" adv="1">19970722 ld.so vulnerability</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602661419318&amp;w=2" adv="1">19970717 KSR[T] Advisory #2: ld.so</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88661732807795&amp;w=2" adv="1">19980204 An old ld-linux.so hole</ref>
        </refs>
        <vuln_soft>
            <prod vendor="delix" name="dld">
                <vers num="5.2" />
            </prod>
            <prod vendor="caldera" name="openlinux_lite">
                <vers num="1.1" />
            </prod>
            <prod vendor="debian" name="debian_linux">
                <vers num="4.0" />
            </prod>
            <prod vendor="lst" name="lst_power_linux">
                <vers num="2.2" />
            </prod>
            <prod vendor="redhat" name="linux">
                <vers num="4.0" />
                <vers num="4.1" />
                <vers num="4.2" />
            </prod>
            <prod vendor="suse" name="suse_linux">
                <vers num="5.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0122" seq="1999-0122" severity="High" type="CVE" published="1997-07-21" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow in AIX lchangelv gives root access.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="ibm" name="aix">
                <vers num="4.1" />
                <vers num="4.1.1" />
                <vers num="4.1.2" />
                <vers num="4.1.3" />
                <vers num="4.1.4" />
                <vers num="4.1.5" />
                <vers num="4.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0247" seq="1999-0247" severity="High" type="CVE" published="1997-07-21" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow in nnrpd program in INN up to version 1.6 allows remote users to execute arbitrary commands.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/1443" adv="1">1443</ref>
            <ref source="NAI" url="http://www.nai.com/nai_labs/asp_set/advisory/17_inn_avd.asp">19970721 INN news server vulnerabilities</ref>
        </refs>
        <vuln_soft>
            <prod vendor="isc" name="inn">
                <vers num="1.4" />
                <vers num="1.4sec" />
                <vers num="1.4sec2" />
                <vers num="1.4unoff3" />
                <vers num="1.4unoff4" />
                <vers num="1.5" />
                <vers num="1.5.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1208" seq="1999-1208" severity="High" type="CVE" published="1997-07-21" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in ping in AIX 4.2 and earlier allows local users to gain root privileges via a long command line argument.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/803.php" adv="1">ping-bo(803)</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602661419337&amp;w=2">19970721 AIX ping, lchangelv, xlock fixes</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602661419330&amp;w=2">19970721 AIX ping (Exploit)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ibm" name="aix">
                <vers num="3.2.5" />
                <vers num="4.1" />
                <vers num="4.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0971" seq="1999-0971" severity="High" type="CVE" published="1997-07-22" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow in Exim allows local users to gain root privileges via a long :include: option in a .forward file.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/7301">19970722 Security hole in exim 1.62: local root exploit</ref>
        </refs>
        <vuln_soft>
            <prod vendor="university_of_cambridge" name="exim">
                <vers num="1.62" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-1068" seq="1999-1068" severity="Medium" type="CVE" published="1997-07-23" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Oracle Webserver 2.1, when serving PL/SQL stored procedures, allows remote attackers to cause a denial of service via a long HTTP GET request.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602661419366&amp;w=2" adv="1">19970723 DoS against Oracle Webserver 2.1 with PL/SQL stored procedures</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="http_server">
                <vers num="2.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-1999-1217" seq="1999-1217" severity="Medium" type="CVE" published="1997-07-25" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">The PATH in Windows NT includes the current working directory (.), which could allow local users to gain privileges by placing Trojan horse programs with the same name as commonly used system programs into certain directories.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/static/526.php" adv="1">nt-path(526)</ref>
            <ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=87602726319435&amp;w=2" adv="1">19970725 Re: NT security - why bother?</ref>
            <ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=87602726319426&amp;w=2" adv="1">19970723 NT security - why bother?</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="windows_nt">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1419" seq="1999-1419" severity="High" type="CVE" published="1997-07-30" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in nss_nisplus.so.1 library in NIS+ in Solaris 2.3 and 2.4 allows local users to gain root privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/219" adv="1">219</ref>
            <ref source="SUN" patch="1" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/148" adv="1">00148</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/7535.php">sun-nisplus-bo(7535)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers num="2.3" />
                <vers edition="" num="2.4" />
                <vers edition=":x86" num="2.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-1999-1308" seq="1999-1308" severity="Medium" type="CVE" published="1997-07-31" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Certain programs in HP-UX 10.20 do not properly handle large user IDs (UID) or group IDs (GID) over 60000, which could allow local users to gain privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CIAC" patch="1" url="http://ciac.llnl.gov/ciac/bulletins/h-91.shtml" adv="1">H-91</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/7594.php">hp-large-uid-gid(7594)</ref>
            <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-09.shtml">H-09</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="10.20" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:N)" CVSS_base_score="0.0" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="0.0" name="CVE-1999-0524" seq="1999-0524" severity="Low" type="CVE" published="1997-08-01" CVSS_version="2.0" CVSS_score="0.0" modified="2008-09-09">
        <desc>
            <descript source="cve">ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.</descript>
        </desc>
        <vuln_types>
            <other />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/322">icmp-timestamp(322)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/306">icmp-netmask(306)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/95">95</ref>
            <ref source="MISC" url="http://kb.vmware.com/selfservice/microsites/search.do?cmd=displayKC&amp;externalId=1434">http://kb.vmware.com/selfservice/microsites/search.do?cmd=displayKC&amp;externalId=1434</ref>
            <ref source="MISC" url="http://descriptions.securescout.com/tc/11011">http://descriptions.securescout.com/tc/11011</ref>
            <ref source="MISC" url="http://descriptions.securescout.com/tc/11010">http://descriptions.securescout.com/tc/11010</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apple" name="mac_os">
                <vers num="" />
            </prod>
            <prod vendor="apple" name="mac_os_x">
                <vers num="" />
            </prod>
            <prod vendor="cisco" name="ios">
                <vers num="" />
            </prod>
            <prod vendor="hp" name="hp-ux">
                <vers num="" />
            </prod>
            <prod vendor="hp" name="tru64">
                <vers num="" />
            </prod>
            <prod vendor="ibm" name="aix">
                <vers num="" />
            </prod>
            <prod vendor="ibm" name="os2">
                <vers num="" />
            </prod>
            <prod vendor="linux" name="linux_kernel">
                <vers num="" />
            </prod>
            <prod vendor="microsoft" name="all_windows">
                <vers num="abstract_cpe" />
            </prod>
            <prod vendor="novell" name="netware">
                <vers num="" />
            </prod>
            <prod vendor="santa_cruz_operation" name="sco_unix">
                <vers num="" />
            </prod>
            <prod vendor="windriver" name="bsdos">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-0238" seq="1999-0238" severity="High" type="CVE" published="1997-08-01" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-09">
        <desc>
            <descript source="cve">php.cgi allows attackers to read any file on the system.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="php" name="php">
                <vers num="1.0" />
                <vers num="2.0" />
                <vers num="2.0b10" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0566" seq="1999-0566" severity="Medium" type="CVE" published="1997-08-01" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">An attacker can write to syslog files from any location, causing a denial of service by filling up the logs, and hiding activities.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="ibm" name="aix">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0301" seq="1999-0301" severity="High" type="CVE" published="1997-08-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow in SunOS/Solaris ps command.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/149">00149</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers num="2.3" />
                <vers edition="" num="2.4" />
                <vers edition=":x86" num="2.4" />
                <vers edition="" num="2.5" />
                <vers edition=":x86" num="2.5" />
                <vers edition="" num="2.5.1" />
                <vers edition=":x86" num="2.5.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" name="CVE-1999-1262" seq="1999-1262" severity="Medium" type="CVE" published="1997-08-01" CVSS_version="2.0 incomplete approximation" CVSS_score="5.1" modified="2008-09-10">
        <desc>
            <descript source="cve">Java in Netscape 4.5 does not properly restrict applets from connecting to other hosts besides the one from which the applet was loaded, which violates the Java security model and could allow remote attackers to conduct unauthorized activities.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/static/1727.php">java-socket-open(1727)</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12231">19990202 Unsecured server in applets under Netscape</ref>
        </refs>
        <vuln_soft>
            <prod vendor="netscape" name="communicator">
                <vers num="4.01" />
                <vers num="4.06" />
                <vers num="4.07" />
                <vers num="4.08" />
                <vers num="4.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-1999-1446" seq="1999-1446" severity="Low" type="CVE" published="1997-08-05" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">Internet Explorer 3 records a history of all URL's that are visited by a user in DAT files located in the Temporary Internet Files and History folders, which are not cleared when the user selects the "Clear History" option, and are not visible when the user browses the folders because of tailored displays.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=87602837719655&amp;w=2" adv="1">19970806 Re: Strange behavior regarding directory</ref>
            <ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=87602837719654&amp;w=2" adv="1">19970805 Re: Strange behavior regarding directory</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="ie">
                <vers num="3.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0152" seq="1999-0152" severity="High" type="CVE" published="1997-08-11" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">The DG/UX finger daemon allows remote command execution through shell metacharacters.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="data_general" name="dg_ux">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0024" seq="1999-0024" severity="Medium" type="CVE" published="1997-08-13" CVSS_version="2.0" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">DNS cache poisoning via BIND, by predictable query IDs.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="isc" name="bind">
                <vers num="4.9.5" />
                <vers num="8.1" />
            </prod>
            <prod vendor="bsdi" name="bsd_os">
                <vers num="2.1" />
                <vers num="3.0" />
            </prod>
            <prod vendor="ibm" name="aix">
                <vers num="4.1" />
                <vers num="4.2" />
            </prod>
            <prod vendor="nec" name="asl_ux_4800">
                <vers num="64" />
            </prod>
            <prod vendor="nec" name="ews-ux_v">
                <vers num="4.2" />
                <vers num="4.2mp" />
            </prod>
            <prod vendor="nec" name="up-ux_v">
                <vers num="4.2mp" />
            </prod>
            <prod vendor="sco" name="open_desktop">
                <vers num="3.0" />
            </prod>
            <prod vendor="sco" name="openserver">
                <vers num="5.0" />
            </prod>
            <prod vendor="sco" name="unix">
                <vers num="3.2v4" />
            </prod>
            <prod vendor="sco" name="unixware">
                <vers num="2.1" />
            </prod>
            <prod vendor="sun" name="solaris">
                <vers num="2.3" />
                <vers edition="" num="2.4" />
                <vers edition=":x86" num="2.4" />
                <vers edition="" num="2.5" />
                <vers edition=":x86" num="2.5" />
                <vers edition="" num="2.5.1" />
                <vers edition=":x86" num="2.5.1" />
                <vers edition="" num="2.6" />
                <vers edition=":x86" num="2.6" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-1250" seq="1999-1250" severity="Medium" type="CVE" published="1997-08-19" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Vulnerability in CGI program in the Lasso application by Blue World, as used on WebSTAR and other servers, allows remote attackers to read arbitrary files.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/2044.php" adv="1">http-cgi-lasso(2044)</ref>
            <ref source="BUGTRAQ" patch="1" url="http://www.securityfocus.com/archive/1/7506" adv="1">19970819 Lasso CGI security hole (fwd)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="blue_world_communications" name="lasso_cgi">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1399" seq="1999-1399" severity="High" type="CVE" published="1997-08-20" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">spaceball program in SpaceWare 7.3 v1.0 in IRIX 6.2 allows local users to gain root privileges by setting the HOSTNAME environmental variable to contain the commands to be executed.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/471" adv="1">471</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602746719552&amp;w=2" adv="1">19970820 SpaceWare 7.3 v1.0</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sgi" name="irix">
                <vers num="6.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-1220" seq="1999-1220" severity="High" type="CVE" published="1997-08-24" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Majordomo 1.94.3 and earlier allows remote attackers to execute arbitrary commands when the advertise or noadvertise directive is used in a configuration file, via shell metacharacters in the Reply-To header.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/502.php" adv="1">majordomo-advertise(502)</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/7527" adv="1">19970824 Vulnerability in Majordomo</ref>
        </refs>
        <vuln_soft>
            <prod vendor="great_circle_associates" name="majordomo">
                <vers num="1.94.3" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-1225" seq="1999-1225" severity="Medium" type="CVE" published="1997-08-24" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">rpc.mountd on Linux, Ultrix, and possibly other operating systems, allows remote attackers to determine the existence of a file on the server by attempting to mount that file, which generates different error messages depending on whether the file exists or not.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/347.php" adv="1">mountd-file-exists(347)</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/7526">19970824 Serious security flaw in rpc.mountd on several operating systems.</ref>
        </refs>
        <vuln_soft>
            <prod vendor="digital" name="ultrix">
                <vers num="" />
            </prod>
            <prod vendor="linux" name="linux_kernel">
                <vers num="2.6.20.1" />
            </prod>
            <prod vendor="netbsd" name="netbsd">
                <vers num="2.0.4" />
            </prod>
            <prod vendor="openbsd" name="openbsd">
                <vers num="" />
            </prod>
            <prod vendor="sun" name="solaris">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0071" seq="1999-0071" severity="High" type="CVE" published="1997-09-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">Apache httpd cookie buffer overflow for versions 1.1.1 and earlier.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="apache" name="http_server">
                <vers num="1.1.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0115" seq="1999-0115" severity="High" type="CVE" published="1997-09-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">AIX bugfiler program allows local users to gain root access.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <other />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/1800">1800</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ibm" name="aix">
                <vers num="3.1" />
                <vers num="3.2" />
                <vers num="3.2.4" />
                <vers num="3.2.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0148" seq="1999-0148" severity="High" type="CVE" published="1997-09-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">The handler CGI program in IRIX allows arbitrary command execution.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/380">380</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX">19970501-02-PX</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sgi" name="irix">
                <vers num="5.3" />
                <vers num="6.2" />
                <vers num="6.3" />
                <vers num="6.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0177" seq="1999-0177" severity="High" type="CVE" published="1997-09-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">The uploader program in the WebSite web server allows a remote attacker to execute arbitrary programs.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="oreilly" name="website">
                <vers num="2.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" name="CVE-1999-0191" seq="1999-0191" severity="Medium" type="CVE" published="1997-09-01" CVSS_version="2.0 incomplete approximation" CVSS_score="6.4" modified="2008-09-09">
        <desc>
            <descript source="cve">IIS newdsn.exe CGI script allows remote users to overwrite files.</descript>
        </desc>
        <loss_types>
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="OSVDB" url="http://www.osvdb.org/275">275</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="internet_information_server">
                <vers num="3.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" name="CVE-1999-0183" seq="1999-0183" severity="Medium" type="CVE" published="1997-09-01" CVSS_version="2.0 incomplete approximation" CVSS_score="6.4" modified="2008-09-09">
        <desc>
            <descript source="cve">Linux implementations of TFTP would allow access to files outside the restricted directory.</descript>
        </desc>
        <loss_types>
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="tftp" name="tftp">
                <vers num="" />
            </prod>
            <prod vendor="linux" name="linux_kernel">
                <vers num="2.6.20.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0237" seq="1999-0237" severity="High" type="CVE" published="1997-09-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">Remote execution of arbitrary commands through Guestbook CGI program.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="webcom" name="cgi_guestbook">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1139" seq="1999-1139" severity="High" type="CVE" published="1997-09-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Character-Terminal User Environment (CUE) in HP-UX 11.0 and earlier allows local users to overwrite arbitrary files and gain root privileges via a symlink attack on the IOERROR.mytty file.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="HP" patch="1" url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9801-074.html" adv="1">HPSBUX9801-074</ref>
            <ref source="BUGTRAQ" patch="1" url="http://security-archive.merton.ox.ac.uk/bugtraq-199801/0122.html" adv="1">19980121 HP-UX CUE, CUD and LAND vulnerabilities</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602880019745&amp;w=2" adv="1">19970901 HP UX Bug :)</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/2007.php">hp-cue(2007)</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-027b.shtml">I-027B</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="11.00" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-1999-1133" seq="1999-1133" severity="Medium" type="CVE" published="1997-09-01" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">HP-UX 9.x and 10.x running X windows may allow local attackers to gain privileges via (1) vuefile, (2) vuepad, (3) dtfile, or (4) dtpad, which do not authenticate users.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/499.php" adv="1">hp-vue-dt(499)</ref>
            <ref source="HP" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602880019776&amp;w=2" adv="1">HPSBUX9709-069</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="10" />
                <vers num="9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-1999-1275" seq="1999-1275" severity="Medium" type="CVE" published="1997-09-08" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">Lotus cc:Mail release 8 stores the postoffice password in plaintext in a hidden file which has insecure permissions, which allows local users to gain privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/1619.php" adv="1">lotus-ccmail-passwords(1619)</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/9478" adv="1">19970908 Password unsecurity in cc:Mail release 8</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ibm" name="lotus_cc_mail">
                <vers num="8.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0079" seq="1999-0079" severity="Medium" type="CVE" published="1997-09-12" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Remote attackers can cause a denial of service in FTP by issuing multiple PASV commands, causing the server to run out of available ports.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="bisonware" name="bisonware_ftp_server">
                <vers num="3.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-1999-1214" seq="1999-1214" severity="Low" type="CVE" published="1997-09-15" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-05">
        <desc>
            <descript source="cve">The asynchronous I/O facility in 4.4 BSD kernel does not check user credentials when setting the recipient of I/O notification, which allows local users to cause a denial of service by using certain ioctl and fcntl calls to cause the signal to be sent to an arbitrary process ID.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/556.php" adv="1">openbsd-iosig(556)</ref>
            <ref source="OPENBSD" patch="1" url="http://www.openbsd.com/advisories/signals.txt" adv="1">19970915 Vulnerability in I/O Signal Handling</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/11062">11062</ref>
        </refs>
        <vuln_soft>
            <prod vendor="bsd" name="bsd">
                <vers num="4.4" />
            </prod>
            <prod vendor="freebsd" name="freebsd">
                <vers edition="stable" num="6.2" />
            </prod>
            <prod vendor="netbsd" name="netbsd">
                <vers num="2.0.4" />
            </prod>
            <prod vendor="openbsd" name="openbsd">
                <vers num="2.1" />
            </prod>
            <prod vendor="sgi" name="irix">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-0667" seq="1999-0667" severity="High" type="CVE" published="1997-09-19" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-09">
        <desc>
            <descript source="cve">The ARP protocol allows any host to spoof ARP replies and poison the ARP cache to conduct IP address spoofing or a denial of service.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="arp_protocol" name="arp_protocol">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-1125" seq="1999-1125" severity="High" type="CVE" published="1997-09-19" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Oracle Webserver 2.1 and earlier runs setuid root, but the configuration file is owned by the oracle account, which allows any local or remote attacker who obtains access to the oracle account to gain privileges or modify arbitrary files by modifying the configuration file.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602880019796&amp;w=2">19970919 Instresting practises of Oracle [Oracle Webserver]</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="http_server">
                <vers num="1.0" />
                <vers num="2.1" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0956" seq="1999-0956" severity="High" type="CVE" published="1997-09-19" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">The NeXT NetInfo _writers property allows local users to gain root privileges or conduct a denial of service.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="next" name="nextstep">
                <vers num="1.0" />
                <vers num="1.0a" />
                <vers num="2.0" />
                <vers num="2.1" />
                <vers num="3.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" name="CVE-1999-0965" seq="1999-0965" severity="Medium" type="CVE" published="1997-09-19" CVSS_version="2.0 incomplete approximation" CVSS_score="6.2" modified="2008-09-09">
        <desc>
            <descript source="cve">Race condition in xterm allows local users to modify arbitrary files via the logging option.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <race />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="x.org" name="xterm">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" name="CVE-1999-0955" seq="1999-0955" severity="High" type="CVE" published="1997-09-23" CVSS_version="2.0 incomplete approximation" CVSS_score="7.6" modified="2008-09-09">
        <desc>
            <descript source="cve">Race condition in wu-ftpd and BSDI ftpd allows remote attackers gain root access via the SITE EXEC command.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <race />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="washington_university" name="wu-ftpd">
                <vers num="2.4.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry reject="1" name="CVE-1999-0282" seq="1999-0282" type="CVE" published="1997-09-23" modified="2008-09-09">
        <desc>
            <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-1584, CVE-1999-1586.  Reason: This candidate combined references from one issue with the description from another issue.  Notes: Users should consult CVE-1999-1584 and CVE-1999-1586 to obtain the appropriate name.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
        </desc>
        <vuln_types>
            <design />
        </vuln_types>
        <refs />
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0267" seq="1999-0267" severity="High" type="CVE" published="1997-09-23" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow in NCSA HTTP daemon v1.3 allows remote command execution.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="ncsa" name="ncsa_httpd">
                <vers num="1.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-0182" seq="1999-0182" severity="High" type="CVE" published="1997-09-30" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Samba has a buffer overflow which allows a remote attacker to obtain root access by specifying a long password.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/h-110.shtml">H-110</ref>
        </refs>
        <vuln_soft>
            <prod vendor="samba" name="samba">
                <vers edition="p2" num="1.9.17" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0185" seq="1999-0185" severity="High" type="CVE" published="1997-10-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">In SunOS or Solaris, a remote user could connect from an FTP server's data port to an rlogin server on a host that trusts the FTP server, allowing remote command execution.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/156">00156</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers num="2.3" />
                <vers edition="" num="2.4" />
                <vers edition=":x86" num="2.4" />
                <vers edition="" num="2.5" />
                <vers edition=":x86" num="2.5" />
                <vers edition="" num="2.5.1" />
                <vers edition=":x86" num="2.5.1" />
            </prod>
            <prod vendor="sun" name="sunos">
                <vers num="4.1.3u1" />
                <vers num="4.1.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0160" seq="1999-0160" severity="High" type="CVE" published="1997-10-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">Some classic Cisco IOS devices have a vulnerability in the PPP CHAP authentication to establish unauthorized PPP connections.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="OSVDB" url="http://www.osvdb.org/1099">1099</ref>
        </refs>
        <vuln_soft>
            <prod vendor="cisco" name="ios">
                <vers num="10.3" />
                <vers num="11.0" />
                <vers num="11.1" />
                <vers num="11.2" />
                <vers num="11.2p" />
                <vers num="4.1" />
                <vers num="9.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0272" seq="1999-0272" severity="Medium" type="CVE" published="1997-10-01" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Denial of service in Slmail v2.5 through the POP3 port.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="slmail" name="slmail">
                <vers num="3.0.2421" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0090" seq="1999-0090" severity="High" type="CVE" published="1997-10-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow in AIX rcp command allows local users to obtain root access.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="ibm" name="aix">
                <vers num="4.1" />
                <vers num="4.1.1" />
                <vers num="4.1.3" />
                <vers num="4.1.4" />
                <vers num="4.1.5" />
                <vers num="4.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0294" seq="1999-0294" severity="Medium" type="CVE" published="1997-10-01" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">All records in a WINS database can be deleted through SNMP for a denial of service.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="microsoft" name="wins">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0295" seq="1999-0295" severity="High" type="CVE" published="1997-10-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">Solaris sysdef command allows local users to read kernel memory, potentially leading to root privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/157">00157</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers num="2.3" />
                <vers edition="" num="2.4" />
                <vers edition=":x86" num="2.4" />
                <vers edition="" num="2.5" />
                <vers edition=":x86" num="2.5" />
                <vers edition="" num="2.5.1" />
                <vers edition=":x86" num="2.5.1" />
                <vers edition=":ppc" num="2.5.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0300" seq="1999-0300" severity="High" type="CVE" published="1997-10-01" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">nis_cachemgr for Solaris NIS+ allows attackers to add malicious NIS+ servers.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/155">00155</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers num="2.3" />
                <vers edition="" num="2.4" />
                <vers edition=":x86" num="2.4" />
                <vers edition="" num="2.5" />
                <vers edition=":x86" num="2.5" />
                <vers edition="" num="2.5.1" />
                <vers edition=":x86" num="2.5.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-1999-0326" seq="1999-0326" severity="Medium" type="CVE" published="1997-10-01" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-09">
        <desc>
            <descript source="cve">Vulnerability in HP-UX mediainit program.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9710-071">HPSBUX9710-071</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="10.01" />
                <vers num="10.10" />
                <vers num="10.20" />
                <vers num="10.30" />
                <vers num="9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-1213" seq="1999-1213" severity="Medium" type="CVE" published="1997-10-01" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Vulnerability in telnet service in HP-UX 10.30 allows attackers to cause a denial of service.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/571.php" adv="1">hp-telnetdos(571)</ref>
            <ref source="HP" patch="1" url="http://www2.dataguard.no/bugtraq/1997_4/0001.html" adv="1">HPSBUX9710-070</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="10.30" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" name="CVE-1999-0061" seq="1999-0061" severity="Medium" type="CVE" published="1997-10-02" CVSS_version="2.0 incomplete approximation" CVSS_score="5.1" modified="2008-09-09">
        <desc>
            <descript source="cve">File creation and deletion, and remote execution, in the BSD line printer daemon (lpd).</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" user="1" />
        </loss_types>
        <vuln_types>
            <race />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="bsdi" name="bsd_os">
                <vers num="" />
            </prod>
            <prod vendor="freebsd" name="freebsd">
                <vers edition="stable" num="6.2" />
            </prod>
            <prod vendor="linux" name="linux_kernel">
                <vers num="2.6.20.1" />
            </prod>
            <prod vendor="openbsd" name="openbsd">
                <vers num="2.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-1061" seq="1999-1061" severity="High" type="CVE" published="1997-10-04" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">HP Laserjet printers with JetDirect cards, when configured with TCP/IP, can be configured without a password, which allows remote attackers to connect to the printer and change its IP address or disable logging.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/1876.php" adv="1">laserjet-unpassworded(1876)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602248518480&amp;w=2" adv="1">19971004 HP Laserjet 4M Plus DirectJet Problem</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="jetdirect">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-1062" seq="1999-1062" severity="High" type="CVE" published="1997-10-04" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">HP Laserjet printers with JetDirect cards, when configured with TCP/IP, allow remote attackers to bypass print filters by directly sending PostScript documents to TCP ports 9099 and 9100.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/1876.php" adv="1">laserjet-unpassworded(1876)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602248518480&amp;w=2" adv="1">19971004 HP Laserjet 4M Plus DirectJet Problem</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="jetdirect">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1095" seq="1999-1095" severity="High" type="CVE" published="1997-10-06" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">sort creates temporary files and follows symbolic links, which allows local users to modify arbitrary files that are writable by the user running sort, as observed in updatedb and other programs that use sort.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88890116304676&amp;w=2" adv="1">19980303 updatedb stuff</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87619953510834&amp;w=2" adv="1">19971006 KSR[T] Advisory #3: updatedb / crontabs</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88886870129518&amp;w=2" adv="1">19980302 overwrite any file with updatedb</ref>
        </refs>
        <vuln_soft>
            <prod vendor="redhat" name="linux">
                <vers num="4.1" />
            </prod>
            <prod vendor="slackware" name="slackware_linux">
                <vers num="3.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:P)" CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" name="CVE-1999-1224" seq="1999-1224" severity="Low" type="CVE" published="1997-10-08" CVSS_version="2.0 incomplete approximation" CVSS_score="3.6" modified="2008-09-05">
        <desc>
            <descript source="cve">IMAP 4.1 BETA, and possibly other versions, does not properly handle the SIGABRT (abort) signal, which allows local users to crash the server (imapd) via certain sequences of commands, which causes a core dump that may contain sensitive password information.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/349.php" adv="1">imapd-core(349)</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87635124302928&amp;w=2" adv="1">19971008 L0pht Advisory: IMAP4rev1 imapd server</ref>
        </refs>
        <vuln_soft>
            <prod vendor="university_of_washington" name="imapd">
                <vers num="4.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0346" seq="1999-0346" severity="Medium" type="CVE" published="1997-10-16" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-09">
        <desc>
            <descript source="cve">CGI PHP mlog script allows an attacker to read any file on the target server.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/713">713</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3397">3397</ref>
        </refs>
        <vuln_soft>
            <prod vendor="php" name="php_fi">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-1999-0192" seq="1999-0192" severity="High" type="CVE" published="1997-10-18" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="redhat" name="linux">
                <vers num="4.0" />
                <vers num="4.1" />
                <vers num="4.2" />
                <vers num="5.0" />
                <vers num="5.1" />
                <vers edition="" num="5.2" />
                <vers edition=":i386" num="5.2" />
                <vers edition="" num="6.0" />
                <vers edition=":i386" num="6.0" />
            </prod>
            <prod vendor="slackware" name="slackware_linux">
                <vers num="3.2" />
                <vers num="3.3" />
                <vers num="3.4" />
                <vers num="3.5" />
                <vers num="3.6" />
                <vers num="3.9" />
                <vers num="4.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-1999-0068" seq="1999-0068" severity="High" type="CVE" published="1997-10-19" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-09">
        <desc>
            <descript source="cve">CGI PHP mylog script allows an attacker to read any file on the target server.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/713">713</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3396">3396</ref>
        </refs>
        <vuln_soft>
            <prod vendor="php" name="php">
                <vers num="1.0" />
                <vers num="2.0" />
                <vers num="2.0b10" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0072" seq="1999-0072" severity="High" type="CVE" published="1997-10-22" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow in AIX xdat gives root access to local users.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="ibm" name="aix">
                <vers num="4.1" />
                <vers num="4.1.1" />
                <vers num="4.1.2" />
                <vers num="4.1.3" />
                <vers num="4.1.4" />
                <vers num="4.1.5" />
                <vers num="4.2" />
                <vers num="4.2.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-1261" seq="1999-1261" severity="Medium" type="CVE" published="1997-10-24" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Buffer overflow in Rainbow Six Multiplayer allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long nickname (nick) command.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/static/1772.php">rainbowsix-nick-bo(1772)</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12433">19990211 Rainbow Six Buffer Overflow.....</ref>
        </refs>
        <vuln_soft>
            <prod vendor="metamail_corporation" name="metamail">
                <vers num="7.2" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-1131" seq="1999-1131" severity="Medium" type="CVE" published="1997-10-24" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in OSF Distributed Computing Environment (DCE) security demon (secd) in IRIX 6.4 and earlier allows attackers to cause a denial of service via a long principal, group, or organization.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/vendor_bulletins/VB-97.12.opengroup" adv="1">VB-97.12</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/static/1123.php" adv="1">sgi-osf-dce-dos(1123)</ref>
            <ref source="CIAC" patch="1" url="http://ciac.llnl.gov/ciac/bulletins/i-060.shtml" adv="1">I-060</ref>
            <ref source="SGI" patch="1" url="ftp://patches.sgi.com/support/free/security/advisories/19980601-01-PX" adv="1">19980601-01-PX</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sgi" name="irix">
                <vers num="5.3" />
                <vers num="6.2" />
                <vers num="6.3" />
                <vers num="6.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-0091" seq="1999-0091" severity="High" type="CVE" published="1997-10-28" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-09">
        <desc>
            <descript source="cve">Buffer overflow in AIX writesrv command allows local users to obtain root access.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="ibm" name="aix">
                <vers num="4.1" />
                <vers num="4.1.1