<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns="http://nvd.nist.gov/feeds/cve/1.2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd" pub_date="2012-02-13" nvd_xml_version="1.2">
  <entry type="CVE" severity="Medium" seq="1999-0001" published="1999-12-30" name="CVE-1999-0001" modified="2010-12-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ip_input.c in BSD-derived TCP/IP implementations allows remote attackers to cause a denial of service (crash or hang) via crafted packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/5707" source="OSVDB">5707</ref>
      <ref url="http://www.openbsd.org/errata23.html#tcpfix" source="CONFIRM">http://www.openbsd.org/errata23.html#tcpfix</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bsdi" name="bsd_os">
        <vers num="3.1" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.1.5.1" />
        <vers num="1.2" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.5" />
        <vers num="2.1.5" />
        <vers num="2.1.6" />
        <vers num="2.1.6.1" />
        <vers num="2.1.7" />
        <vers num="2.1.7.1" />
        <vers num="2.2" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.8" />
        <vers num="3.0" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.3" />
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0002" published="1998-10-12" name="CVE-1999-0002" modified="2009-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in NFS mountd gives root access to remote attackers, mostly in Linux systems.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/121" source="BID" patch="1" adv="1">121</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/j-006.shtml" source="CIAC">J-006</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19981006-01-I" source="SGI">19981006-01-I</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bsdi" name="bsd_os">
        <vers num="1.1" />
      </prod>
      <prod vendor="caldera" name="openlinux">
        <vers num="1.2" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="3.0.3" />
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0003" published="1998-04-01" name="CVE-1999-0003" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/122" source="BID">122</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19981101-01-PX" source="SGI">19981101-01-PX</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19981101-01-A" source="SGI">19981101-01-A</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tritreal" name="ted_cde">
        <vers num="4.3" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.01" />
        <vers num="10.02" />
        <vers num="10.03" />
        <vers num="11.00" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
        <vers num="4.2" />
        <vers num="4.2.1" />
        <vers num="4.3" />
      </prod>
      <prod vendor="sgi" name="irix">
        <vers num="5.2" />
        <vers num="5.3" />
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.5.1" />
        <vers num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0004" published="1997-12-16" name="CVE-1999-0004" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">MIME buffer overflow in email clients, e.g. Solaris mailtool and Outlook.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms98-008.asp" source="MS">MS98-008</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="dtmail">
        <vers num="" />
      </prod>
      <prod vendor="university_of_washington" name="pine">
        <vers num="4.02" />
      </prod>
      <prod vendor="sco" name="unixware">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0005" published="1998-07-20" name="CVE-1999-0005" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Arbitrary command execution via IMAP buffer overflow in authenticate command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/130" source="BID">130</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/177" source="SUN">00177</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="messaging_server">
        <vers num="3.55" />
      </prod>
      <prod vendor="university_of_washington" name="imap">
        <vers num="10.234" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0006" published="1998-07-14" name="CVE-1999-0006" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in POP servers based on BSD/Qualcomm's qpopper allows remote attackers to gain root access using a long PASS command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/133" source="BID">133</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19980801-01-I" source="SGI">19980801-01-I</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qualcomm" name="qpopper">
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0007" published="1998-06-26" name="CVE-1999-0007" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Information from SSL-encrypted sessions via PKCS #1.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms98-002.mspx" source="MS">MS98-002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="c2net" name="stonghold_web_server">
        <vers num="2.0.1" />
        <vers num="2.2" />
        <vers num="2.3" />
      </prod>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="5.5" />
      </prod>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="3.0" />
        <vers num="4.0" />
      </prod>
      <prod vendor="microsoft" name="site_server">
        <vers num="3.0" />
      </prod>
      <prod vendor="netscape" name="certificate_server">
        <vers num="1.0" edition="patch1" />
      </prod>
      <prod vendor="netscape" name="collabra_server">
        <vers num="3.5.2" />
      </prod>
      <prod vendor="netscape" name="directory_server">
        <vers num="1.3" edition="patch5" />
        <vers num="3.1" edition="patch1" />
        <vers num="3.12" />
      </prod>
      <prod vendor="netscape" name="enterprise_server">
        <vers num="2.0" />
        <vers num="3.0.1b" />
        <vers num="3.5.1" />
      </prod>
      <prod vendor="netscape" name="fasttrack_server">
        <vers num="3.01b" />
      </prod>
      <prod vendor="netscape" name="messaging_server">
        <vers num="3.54" />
      </prod>
      <prod vendor="netscape" name="proxy_server">
        <vers num="3.5.1" />
      </prod>
      <prod vendor="open_market" name="secure_webserver">
        <vers num="2.1" />
      </prod>
      <prod vendor="ssleay" name="ssleay">
        <vers num="0.6.6" />
        <vers num="0.8.1" />
        <vers num="0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0008" published="1998-06-08" name="CVE-1999-0008" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in NIS+, in Sun's rpc.nisd program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/170" source="SUN">00170</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.34" />
        <vers num="11.00" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.5.1" />
        <vers num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0009" published="1998-04-08" name="CVE-1999-0009" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9808-083" source="HP">HPSBUX9808-083</ref>
      <ref url="http://www.securityfocus.com/bid/134" source="BID">134</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/180" source="SUN">00180</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX" source="SGI">19980603-01-PX</ref>
    </refs>
    <vuln_soft>
      <prod vendor="data_general" name="dg_ux">
        <vers num="5.4_3.0" />
        <vers num="5.4_3.1" />
        <vers num="5.4_4.1" />
        <vers num="5.4_4.11" />
      </prod>
      <prod vendor="isc" name="bind">
        <vers num="4.9.6" />
        <vers num="8.1" />
        <vers num="8.1.1" />
      </prod>
      <prod vendor="bsdi" name="bsd_os">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.1" />
      </prod>
      <prod vendor="caldera" name="openlinux">
        <vers num="1.0" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
        <vers num="4.2" />
        <vers num="4.2.1" />
        <vers num="4.3" />
      </prod>
      <prod vendor="nec" name="asl_ux_4800">
        <vers num="64" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.3" />
        <vers num="1.3.1" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.0" />
      </prod>
      <prod vendor="sco" name="open_desktop">
        <vers num="3.0" />
        <vers num="5.0" />
      </prod>
      <prod vendor="sco" name="unixware">
        <vers num="2.1" />
        <vers num="7.0" />
      </prod>
      <prod vendor="sgi" name="irix">
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.3.1" />
        <vers num="3.3.2" />
        <vers num="3.3.3" />
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="4.0.1t" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.4b" />
        <vers num="4.0.4t" />
        <vers num="4.0.5" />
        <vers num="4.0.5_iop" />
        <vers num="4.0.5_ipr" />
        <vers num="4.0.5a" />
        <vers num="4.0.5d" />
        <vers num="4.0.5e" />
        <vers num="4.0.5f" />
        <vers num="4.0.5g" />
        <vers num="4.0.5h" />
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.1" />
        <vers num="5.1.1" />
        <vers num="5.2" />
        <vers num="5.3" />
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":ppc" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0010" published="1998-04-08" name="CVE-1999-0010" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9808-083" source="HP">HPSBUX9808-083</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX" source="SGI">19980603-01-PX</ref>
    </refs>
    <vuln_soft>
      <prod vendor="data_general" name="dg_ux">
        <vers num="y2k_patchr4.11mu05" />
        <vers num="y2k_patchr4.12mu03" />
        <vers num="y2k_patchr4.20mu01" />
        <vers num="y2k_patchr4.20mu02" />
        <vers num="y2k_patchr4.20mu03" />
      </prod>
      <prod vendor="isc" name="bind">
        <vers num="4.9" />
        <vers num="8" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="4.3" />
      </prod>
      <prod vendor="nec" name="asl_ux_4800">
        <vers num="11" />
        <vers num="13" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.3" />
        <vers num="1.3.1" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="4.2" />
        <vers num="5.0" />
      </prod>
      <prod vendor="sco" name="open_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="sco" name="openserver">
        <vers num="5.0" />
      </prod>
      <prod vendor="sco" name="unix">
        <vers num="3.2v4" />
      </prod>
      <prod vendor="sco" name="unixware">
        <vers num="2.1" />
        <vers num="7.0" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="5.3" />
        <vers num="5.4" />
        <vers num="5.5" />
        <vers num="5.5.1" />
        <vers num="5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0011" published="1998-04-08" name="CVE-1999-0011" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9808-083" source="HP">HPSBUX9808-083</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/180" source="SUN">00180</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX" source="SGI">19980603-01-PX</ref>
    </refs>
    <vuln_soft>
      <prod vendor="data_general" name="dg_ux">
        <vers num="y2k_patchr4.11mu05" />
        <vers num="y2k_patchr4.12mu03" />
        <vers num="y2k_patchr4.20mu01" />
        <vers num="y2k_patchr4.20mu02" />
        <vers num="y2k_patchr4.20mu03" />
      </prod>
      <prod vendor="isc" name="bind">
        <vers num="4.9" />
        <vers num="8" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="4.3" />
      </prod>
      <prod vendor="nec" name="asl_ux_4800">
        <vers num="11" />
        <vers num="13" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.3" />
        <vers num="1.3.1" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="4.2" />
        <vers num="5.0" />
      </prod>
      <prod vendor="sco" name="open_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="sco" name="openserver">
        <vers num="5.0" />
      </prod>
      <prod vendor="sco" name="unix">
        <vers num="3.2v4" />
      </prod>
      <prod vendor="sco" name="unixware">
        <vers num="2.1" />
        <vers num="7.0" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="5.3" />
        <vers num="5.4" />
        <vers num="5.5" />
        <vers num="5.5.1" />
        <vers num="5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0012" published="1998-02-06" name="CVE-1999-0012" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="frontpage">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
      </prod>
      <prod vendor="microsoft" name="personal_web_server">
        <vers num="4.0" />
      </prod>
      <prod vendor="netscape" name="enterprise_server">
        <vers num="3.0" />
      </prod>
      <prod vendor="netscape" name="fasttrack_server">
        <vers num="2.01" />
        <vers num="3.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0013" published="1998-01-22" name="CVE-1999-0013" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stolen credentials from SSH clients via ssh-agent program, allowing other local users to access remote accounts belonging to the ssh-agent user.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="ssh" name="ssh">
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.12" />
        <vers num="1.2.13" />
        <vers num="1.2.14" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0014" published="1998-01-21" name="CVE-1999-0014" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unauthorized privileged access or denial of service via dtappgather program in CDE.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9801-075" source="HP">HPSBUX9801-075</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/185" source="SUN">00185</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cde" name="cde">
        <vers num="1.01" />
        <vers num="1.01_x86" />
        <vers num="1.02" />
        <vers num="1.02_x86" />
        <vers num="1.2" />
        <vers num="1.2_x86" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.10" />
        <vers num="10.20" />
        <vers num="11.00" />
      </prod>
      <prod vendor="hp" name="vvos">
        <vers num="10.24" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0015" published="1997-12-16" name="CVE-1999-0015" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Teardrop IP denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5579" source="OVAL">oval:org.mitre.oval:def:5579</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10" />
        <vers num="10.01" />
        <vers num="10.16" />
        <vers num="10.20" />
        <vers num="10.24" />
        <vers num="10.30" />
        <vers num="11.00" />
        <vers num="9.00" />
        <vers num="9.01" />
        <vers num="9.03" />
        <vers num="9.04" />
        <vers num="9.05" />
        <vers num="9.07" />
      </prod>
      <prod vendor="microsoft" name="windows_95">
        <vers num="0.0a" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="3.5.1" edition="sp1" />
        <vers num="3.5.1" edition="sp2" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp2" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.2.1" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="4.1.3u1" />
        <vers num="4.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0016" published="1997-12-01" name="CVE-1999-0016" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Land IP denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" bound="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9801-076" source="HP">HPSBUX9801-076</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="inet">
        <vers num="5.01" />
      </prod>
      <prod vendor="microsoft" name="winsock">
        <vers num="2.0" />
      </prod>
      <prod vendor="cisco" name="ios">
        <vers num="7000" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.00" />
        <vers num="10.01" />
        <vers num="10.10" />
        <vers num="10.16" />
        <vers num="10.20" />
        <vers num="10.24" />
        <vers num="10.30" />
        <vers num="11.00" />
        <vers num="9.00" />
        <vers num="9.01" />
        <vers num="9.03" />
        <vers num="9.04" />
        <vers num="9.05" />
        <vers num="9.07" />
      </prod>
      <prod vendor="microsoft" name="windows_95">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.0" />
        <vers num="1.1" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="4.1.3u1" />
        <vers num="4.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0017" published="1997-12-10" name="CVE-1999-0017" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="gnu" name="inet">
        <vers num="5.01" />
        <vers num="6.01" />
        <vers num="6.02" />
      </prod>
      <prod vendor="washington_university" name="wu-ftpd">
        <vers num="2.4" />
      </prod>
      <prod vendor="caldera" name="openlinux">
        <vers num="1.2" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="2.0" />
        <vers num="2.1.0" />
        <vers num="2.1.7" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="3.2" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="4.3" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.2.1" />
      </prod>
      <prod vendor="sco" name="open_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="sco" name="openserver">
        <vers num="5.0.4" />
      </prod>
      <prod vendor="sco" name="unixware">
        <vers num="2.1" />
      </prod>
      <prod vendor="siemens" name="reliant_unix">
        <vers num="" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="4.1.3u1" />
        <vers num="4.1.4" />
        <vers num="5.3" />
        <vers num="5.4" edition="" />
        <vers num="5.4" edition=":x86" />
        <vers num="5.5" edition="" />
        <vers num="5.5" edition=":x86" />
        <vers num="5.5.1" edition="" />
        <vers num="5.5.1" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0018" published="1997-12-05" name="CVE-1999-0018" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in statd allows root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/127" source="BID" patch="1">127</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="3.2" />
        <vers num="4.1" />
      </prod>
      <prod vendor="sgi" name="irix">
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.1" />
        <vers num="5.1.1" />
        <vers num="5.2" />
        <vers num="5.3" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0019" published="1996-04-24" name="CVE-1999-0019" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Delete or create a file via rpc.statd, due to invalid information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/135" source="SUN">00135</ref>
    </refs>
    <vuln_soft>
      <prod vendor="data_general" name="dg_ux">
        <vers num="4.11" />
      </prod>
      <prod vendor="ncr" name="mp-ras">
        <vers num="2.03" />
        <vers num="3.0" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="3.2" />
        <vers num="4.1" />
      </prod>
      <prod vendor="nighthawk" name="cx_ux">
        <vers num="" />
      </prod>
      <prod vendor="nighthawk" name="powerux">
        <vers num="" />
      </prod>
      <prod vendor="sco" name="open_desktop">
        <vers num="2" />
        <vers num="3" />
      </prod>
      <prod vendor="sco" name="openserver">
        <vers num="3.0" />
        <vers num="5.0" />
      </prod>
      <prod vendor="sco" name="unixware">
        <vers num="2" />
      </prod>
      <prod vendor="sgi" name="irix">
        <vers num="6.1" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="5.3" />
        <vers num="5.4" edition="" />
        <vers num="5.4" edition=":x86" />
        <vers num="5.5" edition="" />
        <vers num="5.5" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="1999-0020" reject="1" published="1999-01-01" name="CVE-1999-0020" modified="2008-09-09">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-0032.  Reason: This candidate is a duplicate of CVE-1999-0032.  Notes: All CVE users should reference CVE-1999-0032 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0021" published="1997-11-05" name="CVE-1999-0021" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Arbitrary command execution via buffer overflow in Count.cgi (wwwcount) cgi-bin program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/128" source="BID">128</ref>
    </refs>
    <vuln_soft>
      <prod vendor="muhammad_a._muquit" name="wwwcount">
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0022" published="1996-07-03" name="CVE-1999-0022" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Local user gains root privileges via buffer overflow in rdist, via expstr() function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/179" source="SUN">00179</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bsdi" name="bsd_os">
        <vers num="1.1" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="2.0" />
        <vers num="2.0.5" />
        <vers num="2.1.0" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.00" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.2.4" />
        <vers num="3.2.5" />
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
        <vers num="4.2" />
      </prod>
      <prod vendor="sgi" name="irix">
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.1" />
        <vers num="5.1.1" />
        <vers num="5.2" />
        <vers num="5.3" edition="" />
        <vers num="5.3" edition=":xfs" />
        <vers num="6.0" />
        <vers num="6.0.1" edition="" />
        <vers num="6.0.1" edition=":xfs" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" edition="u1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0023" published="1996-07-24" name="CVE-1999-0023" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Local user gains root privileges via buffer overflow in rdist, via lookup() function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="inet" name="inet">
        <vers num="5.01" />
        <vers num="6.01" />
      </prod>
      <prod vendor="bsdi" name="bsd_os">
        <vers num="" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="2.0" />
        <vers num="2.0.5" />
        <vers num="2.1.0" />
        <vers num="2.2" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="3.2" />
        <vers num="4.1" />
        <vers num="4.2" />
      </prod>
      <prod vendor="sco" name="internet_faststart">
        <vers num="1.0" />
      </prod>
      <prod vendor="sco" name="open_desktop">
        <vers num="2.0" />
        <vers num="3.0" />
      </prod>
      <prod vendor="sco" name="openserver">
        <vers num="2.0" />
        <vers num="5.0" />
        <vers num="5.0.2" />
      </prod>
      <prod vendor="sco" name="tcp_ip">
        <vers num="1.2.0" />
        <vers num="1.2.1" />
      </prod>
      <prod vendor="sco" name="unixware">
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="1.1" />
        <vers num="1.1.1a" />
        <vers num="1.1.2" />
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.5.1" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="4.1.3" />
        <vers num="4.1.3u1" />
        <vers num="4.1.4" />
        <vers num="5.3" />
        <vers num="5.4" />
        <vers num="5.5" />
        <vers num="5.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0024" published="1997-08-13" name="CVE-1999-0024" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">DNS cache poisoning via BIND, by predictable query IDs.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="isc" name="bind">
        <vers num="4.9.5" />
        <vers num="8.1" />
      </prod>
      <prod vendor="bsdi" name="bsd_os">
        <vers num="2.1" />
        <vers num="3.0" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="4.1" />
        <vers num="4.2" />
      </prod>
      <prod vendor="nec" name="asl_ux_4800">
        <vers num="64" />
      </prod>
      <prod vendor="nec" name="ews-ux_v">
        <vers num="4.2" />
        <vers num="4.2mp" />
      </prod>
      <prod vendor="nec" name="up-ux_v">
        <vers num="4.2mp" />
      </prod>
      <prod vendor="sco" name="open_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="sco" name="openserver">
        <vers num="5.0" />
      </prod>
      <prod vendor="sco" name="unix">
        <vers num="3.2v4" />
      </prod>
      <prod vendor="sco" name="unixware">
        <vers num="2.1" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.3" />
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0025" published="1997-07-16" name="CVE-1999-0025" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">root privileges via buffer overflow in df command on SGI IRIX systems.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/20851" source="CERT-VN">VU#20851</ref>
      <ref url="http://www.cert.org/advisories/CA-1997-21.html" source="CERT">CA-1997-21</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/440" source="XF">df-bo(440)</ref>
      <ref url="http://www.securityfocus.com/bid/346" source="BID">346</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0026" published="1997-07-16" name="CVE-1999-0026" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">root privileges via buffer overflow in pset command on SGI IRIX systems.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0027" published="1997-07-16" name="CVE-1999-0027" modified="2009-02-25" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">root privileges via buffer overflow in eject command on SGI IRIX systems.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0028" published="1997-07-16" name="CVE-1999-0028" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">root privileges via buffer overflow in login/scheme command on SGI IRIX systems.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0029" published="1997-07-16" name="CVE-1999-0029" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">root privileges via buffer overflow in ordist command on SGI IRIX systems.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0030" published="1997-07-16" name="CVE-1999-0030" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">root privileges via buffer overflow in xlock command on SGI IRIX systems.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0031" published="1997-07-08" name="CVE-1999-0031" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers to monitor a user's web activities, aka the Bell Labs vulnerability.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9707-065.html" source="HP">HPSBUX9707-065</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="3.0" />
        <vers num="4.0" />
      </prod>
      <prod vendor="netscape" name="communicator">
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0032" published="1996-10-25" name="CVE-1999-0032" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in lpr, as used in BSD-based systems including Linux, allows local users to execute arbitrary code as root via a long -C (classification) command line option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/707" source="BID">707</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/i-042.shtml" source="CIAC">I-042</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19980402-01-PX" source="SGI">19980402-01-PX</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bsdi" name="bsd_os">
        <vers num="2.1" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="2.0" />
        <vers num="2.0.5" />
        <vers num="2.1.0" />
        <vers num="2.1.5" />
      </prod>
      <prod vendor="next" name="nextstep">
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
      <prod vendor="sgi" name="irix">
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.1" />
        <vers num="5.1.1" />
        <vers num="5.2" />
        <vers num="5.3" />
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="4.1.3u1" />
        <vers num="4.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0033" published="1997-06-12" name="CVE-1999-0033" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Command execution in Sun systems via buffer overflow in the at program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="ncr" name="mp-ras">
        <vers num="3.0" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="" />
      </prod>
      <prod vendor="sco" name="open_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="sco" name="openserver">
        <vers num="3.0" />
        <vers num="5.0" />
      </prod>
      <prod vendor="sco" name="unixware">
        <vers num="2.1" />
        <vers num="3.2v4" />
      </prod>
      <prod vendor="sgi" name="irix">
        <vers num="" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="5.3" />
        <vers num="5.4" edition="" />
        <vers num="5.4" edition=":x86" />
        <vers num="5.5" edition="" />
        <vers num="5.5" edition=":x86" />
        <vers num="5.5.1" edition="" />
        <vers num="5.5.1" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0034" published="1997-05-29" name="CVE-1999-0034" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in suidperl (sperl), Perl 4.x and 5.x.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="larry_wall" name="perl">
        <vers num="5.3" />
      </prod>
      <prod vendor="sgi" name="freeware">
        <vers num="1.0" />
        <vers num="2.0" />
      </prod>
      <prod vendor="bsdi" name="bsd_os">
        <vers num="2.1" />
        <vers num="3.0" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0035" published="1997-05-29" name="CVE-1999-0035" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Race condition in signal handling routine in ftpd, allowing read/write arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <config />
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="gnu" name="inet">
        <vers num="5.01" />
      </prod>
      <prod vendor="sgi" name="irix">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0036" published="1997-05-26" name="CVE-1999-0036" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">IRIX login program with a nonzero LOCKOUT parameter allows creation or damage to files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/557" source="XF">sgi-lockout(557)</ref>
      <ref url="http://www.osvdb.org/990" source="OSVDB">990</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/h-106.shtml" source="CIAC">H-106</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19970508-02-PX" source="SGI">19970508-02-PX</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="5.3" />
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0037" published="1997-05-21" name="CVE-1999-0037" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Arbitrary command execution via metamail package using message headers, when user processes attacker's message using metamail.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="6.2" edition="stable" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0038" published="1997-04-26" name="CVE-1999-0038" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in xlock program allows local users to execute commands as root.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="data_general" name="dg_ux">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="7.0" />
      </prod>
      <prod vendor="bsdi" name="bsd_os">
        <vers num="2.1" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="0.93" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.00" />
        <vers num="10.01" />
        <vers num="10.08" />
        <vers num="10.10" />
        <vers num="10.16" />
        <vers num="10.20" />
        <vers num="10.24" />
        <vers num="10.30" />
        <vers num="10.34" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="3.2" />
        <vers num="4.1" />
        <vers num="4.2" />
      </prod>
      <prod vendor="sgi" name="irix">
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.1" />
        <vers num="5.1.1" />
        <vers num="5.2" />
        <vers num="5.3" edition="" />
        <vers num="5.3" edition=":xfs" />
        <vers num="6.0" />
        <vers num="6.0.1" edition="" />
        <vers num="6.0.1" edition=":xfs" />
        <vers num="6.1" />
        <vers num="6.3" />
        <vers num="6.4" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.3" />
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":ppc" />
        <vers num="2.5.1" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0039" published="1997-05-06" name="CVE-1999-0039" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">webdist CGI program (webdist.cgi) in SGI IRIX allows remote attackers to execute arbitrary commands via shell metacharacters in the distloc parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1997-12.html" source="CERT">CA-1997-12</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/333" source="XF">http-sgi-webdist(333)</ref>
      <ref url="http://www.securityfocus.com/bid/374" source="BID">374</ref>
      <ref url="http://www.osvdb.org/235" source="OSVDB">235</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX" source="SGI">19970501-02-PX</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="5.3" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0040" published="1997-05-01" name="CVE-1999-0040" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="bsdi" name="bsd_os">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.1" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="1.1.5.1" />
        <vers num="2.0" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.00" />
        <vers num="10.01" />
        <vers num="10.08" />
        <vers num="10.09" />
        <vers num="10.10" />
        <vers num="10.16" />
        <vers num="10.20" />
        <vers num="10.24" />
        <vers num="10.30" />
        <vers num="10.34" />
        <vers num="9.00" />
        <vers num="9.01" />
        <vers num="9.10" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="3.2" />
        <vers num="4.1" />
        <vers num="4.2" />
      </prod>
      <prod vendor="nec" name="asl_ux_4800">
        <vers num="64" />
      </prod>
      <prod vendor="nec" name="ews-ux_v">
        <vers num="4.2" />
        <vers num="4.2mp" />
      </prod>
      <prod vendor="nec" name="up-ux_v">
        <vers num="4.2mp" />
      </prod>
      <prod vendor="sgi" name="irix">
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="5.3" />
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.3" />
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":x86" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="4.1.3" />
        <vers num="4.1.3u1" />
        <vers num="4.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0041" published="1997-02-13" name="CVE-1999-0041" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in NLS (Natural Language Service).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="gnu" name="libc">
        <vers num="5.0.9" />
        <vers num="5.2.18" />
        <vers num="5.3.12" />
      </prod>
      <prod vendor="cray" name="unicos">
        <vers num="1.5" edition="" />
        <vers num="1.5" edition=":mk" />
        <vers num="9.0" />
        <vers num="9.2" />
      </prod>
      <prod vendor="cray" name="unicos_max">
        <vers num="1.3" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="3.2.5" />
        <vers num="4.1" />
        <vers num="4.2" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="4.0" />
      </prod>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0042" published="1997-04-07" name="CVE-1999-0042" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in University of Washington's implementation of IMAP and POP servers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="university_of_washington" name="imap">
        <vers num="4" />
      </prod>
      <prod vendor="university_of_washington" name="pop">
        <vers num="3" />
      </prod>
      <prod vendor="bsdi" name="bsd_os">
        <vers num="2.1" />
        <vers num="3.0" />
      </prod>
      <prod vendor="caldera" name="openlinux">
        <vers num="1.0" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="4.2.1" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="2.0" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0043" published="1996-12-04" name="CVE-1999-0043" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="isc" name="inn">
        <vers num="1.4sec" />
        <vers num="1.4sec2" />
        <vers num="1.4unoff3" />
        <vers num="1.4unoff4" />
        <vers num="1.5" />
      </prod>
      <prod vendor="netscape" name="news_server">
        <vers num="1.1" />
      </prod>
      <prod vendor="nec" name="goah_intrasv">
        <vers num="1.1" />
      </prod>
      <prod vendor="nec" name="goah_networksv">
        <vers num="1.2" />
        <vers num="2.2" />
        <vers num="3.1" />
      </prod>
      <prod vendor="bsdi" name="bsd_os">
        <vers num="2.1" />
      </prod>
      <prod vendor="caldera" name="openlinux">
        <vers num="1.0" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0044" published="1996-12-03" name="CVE-1999-0044" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">fsdump command in IRIX allows local users to obtain root access by modifying sensitive files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19970301-01-P" source="SGI">19970301-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="5.1" />
        <vers num="5.1.1" />
        <vers num="5.2" />
        <vers num="5.3" />
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.1" />
        <vers num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0045" published="1996-12-10" name="CVE-1999-0045" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">List of arbitrary files on Web host via nph-test-cgi script.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="0.8.11" />
        <vers num="0.8.14" />
        <vers num="1.0" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.5" />
        <vers num="1.1" />
      </prod>
      <prod vendor="netscape" name="commerce_server">
        <vers num="1.12" />
      </prod>
      <prod vendor="netscape" name="communications_server">
        <vers num="1.1" />
        <vers num="1.12" />
      </prod>
      <prod vendor="netscape" name="enterprise_server">
        <vers num="2.0a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0046" published="1997-02-06" name="CVE-1999-0046" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow of rlogin program using TERM environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="data_general" name="dg_ux">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="4.0" />
      </prod>
      <prod vendor="bsdi" name="bsd_os">
        <vers num="1.1" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.1" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="0.93" />
      </prod>
      <prod vendor="digital" name="ultrix">
        <vers num="2.2" />
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="4.3" />
        <vers num="4.3a" />
        <vers num="4.4" />
        <vers num="4.5" />
      </prod>
      <prod vendor="digital" name="unix">
        <vers num="3.2g" />
        <vers num="4.0" />
        <vers num="4.0a" />
        <vers num="4.0b" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="1.1.5.1" />
        <vers num="2.0" />
        <vers num="2.0.5" />
        <vers num="2.1.0" />
        <vers num="2.1.5" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.00" />
        <vers num="10.01" />
        <vers num="10.08" />
        <vers num="10.09" />
        <vers num="10.10" />
        <vers num="10.16" />
        <vers num="10.20" />
        <vers num="10.24" />
        <vers num="10.30" />
        <vers num="10.34" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="3.2" />
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.0" />
        <vers num="1.1" />
      </prod>
      <prod vendor="next" name="nextstep">
        <vers num="1.0" />
        <vers num="1.0a" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="4.0" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.3" />
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":ppc" />
        <vers num="2.5.1" edition=":x86" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="4.1.3u1" />
        <vers num="4.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0047" published="1997-01-28" name="CVE-1999-0047" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">MIME conversion buffer overflow in sendmail versions 8.8.3 and 8.8.4.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/685" source="BID">685</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eric_allman" name="sendmail">
        <vers num="8.8.3" />
        <vers num="8.8.4" />
      </prod>
      <prod vendor="bsdi" name="bsd_os">
        <vers num="2.1" />
      </prod>
      <prod vendor="caldera" name="openlinux">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0048" published="1997-01-27" name="CVE-1999-0048" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Talkd, when given corrupt DNS information, can be used to execute arbitrary commands with root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/147" source="SUN">00147</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="netkit">
        <vers num="0.07" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="3.1" />
        <vers num="4.1" />
        <vers num="4.2" />
      </prod>
      <prod vendor="nec" name="asl_ux_4800">
        <vers num="" />
      </prod>
      <prod vendor="nec" name="ews-ux_v">
        <vers num="" />
      </prod>
      <prod vendor="nec" name="up-ux_v">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0049" published="1997-01-08" name="CVE-1999-0049" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Csetup under IRIX allows arbitrary file creation or overwriting.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="5" />
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.1" />
        <vers num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0050" published="1996-12-01" name="CVE-1999-0050" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in HP-UX newgrp program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.00" />
        <vers num="10.01" />
        <vers num="10.10" />
        <vers num="10.20" />
        <vers num="9.00" />
        <vers num="9.01" />
        <vers num="9.03" />
        <vers num="9.04" />
        <vers num="9.05" />
        <vers num="9.06" />
        <vers num="9.07" />
        <vers num="9.08" />
        <vers num="9.09" />
        <vers num="9.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0051" published="1997-01-06" name="CVE-1999-0051" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Arbitrary file creation and program execution using FLEXlm LicenseManager, from versions 4.0 to 5.0, in IRIX.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="globetrotter" name="flexlm">
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="5.0" />
      </prod>
      <prod vendor="sgi" name="license_oeo">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.1.1" />
      </prod>
      <prod vendor="sgi" name="irix">
        <vers num="3.3.2" />
        <vers num="3.3.3" />
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="4.0.1t" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.4b" />
        <vers num="4.0.4t" />
        <vers num="4.0.5" />
        <vers num="4.0.5_iop" />
        <vers num="4.0.5_ipr" />
        <vers num="4.0.5a" />
        <vers num="4.0.5d" />
        <vers num="4.0.5e" />
        <vers num="4.0.5f" />
        <vers num="4.0.5g" />
        <vers num="4.0.5h" />
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.1" />
        <vers num="5.1.1" />
        <vers num="5.2" />
        <vers num="5.3" />
        <vers num="6.0" />
        <vers num="6.0.1" edition="" />
        <vers num="6.0.1" edition=":xfs" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":x86" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.3u1" />
        <vers num="4.1.4" />
        <vers num="4.1.4jl" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0052" published="1998-11-04" name="CVE-1999-0052" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IP fragmentation denial of service in FreeBSD allows a remote attacker to cause a crash.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/1389" source="XF">freebsd-ip-frag-dos(1389)</ref>
      <ref url="http://www.osvdb.org/908" source="OSVDB">908</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bsdi" name="bsd_os">
        <vers num="4.0" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="1.1.5.1" />
        <vers num="2.0" />
        <vers num="2.0.5" />
        <vers num="2.1.0" />
        <vers num="2.1.5" />
        <vers num="2.1.6" />
        <vers num="2.1.7.1" />
        <vers num="2.2.2" />
        <vers num="2.2.8" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0053" published="1998-10-13" name="CVE-1999-0053" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">TCP RST denial of service in FreeBSD.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/6094" source="OSVDB">6094</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="6.2" edition="stable" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0054" published="1998-06-10" name="CVE-1999-0054" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sun's ftpd daemon can be subjected to a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/171" source="SUN">00171</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.3" />
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":ppc" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0055" published="1998-05-14" name="CVE-1999-0055" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflows in Sun libnsl allow root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IX80543&amp;apar=only" source="AIXAPAR">IX80543</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/172" source="SUN">00172</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.2" />
        <vers num="4.2.1" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.2" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":ppc" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0056" published="1998-09-09" name="CVE-1999-0056" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Sun's ping program can give root access to local users.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/174" source="SUN">00174</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.5.1" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0057" published="1998-11-16" name="CVE-1999-0057" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Vacation program allows command execution by remote users through a sendmail command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9811-087" source="HP">HPSBUX9811-087</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eric_allman" name="vacation">
        <vers num="" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="6.2" edition="stable" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.00" />
        <vers num="10.09" />
        <vers num="10.24" />
        <vers num="9" />
      </prod>
      <prod vendor="hp" name="vvos">
        <vers num="" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0058" published="1997-04-17" name="CVE-1999-0058" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in PHP cgi program, php.cgi allows shell access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/712" source="BID">712</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="1.0" />
        <vers num="2.0b10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0059" published="1997-07-14" name="CVE-1999-0059" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:N/A:N)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">IRIX fam service allows an attacker to obtain a list of all files on the server.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/325" source="XF">irix-fam(325)</ref>
      <ref url="http://www.securityfocus.com/bid/353" source="BID">353</ref>
      <ref url="http://www.osvdb.org/164" source="OSVDB">164</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="5.3" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0060" published="1998-03-16" name="CVE-1999-0060" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Attackers can cause a denial of service in Ascend MAX and Pipeline routers with a malformed packet to the discard port, which is used by the Java Configurator tool.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="lucent" name="ascend_max_router">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
      <prod vendor="lucent" name="ascend_pipeline_router">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="6.0" />
      </prod>
      <prod vendor="lucent" name="ascend_tnt_router">
        <vers num="1.0" />
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0061" published="1997-10-02" name="CVE-1999-0061" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">File creation and deletion, and remote execution, in the BSD line printer daemon (lpd).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="bsdi" name="bsd_os">
        <vers num="" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="6.2" edition="stable" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.20.1" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0062" published="1998-08-03" name="CVE-1999-0062" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The chpass command in OpenBSD allows a local user to gain root access through file descriptor leakage.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/7559" source="OSVDB">7559</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0063" published="1999-01-11" name="CVE-1999-0063" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco IOS 12.0 and other versions can be crashed by malicious UDP packets to the syslog port.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="11.3aa" />
        <vers num="11.3db" />
        <vers num="12.0" />
        <vers num="12.0(1)w" />
        <vers num="12.0(1)xa3" />
        <vers num="12.0(1)xb" />
        <vers num="12.0(1)xe" />
        <vers num="12.0(2)xc" />
        <vers num="12.0(2)xd" />
        <vers num="12.0db" />
        <vers num="12.0s" />
        <vers num="12.0t" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0064" published="1997-05-26" name="CVE-1999-0064" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in AIX lquerylv program gives root access to local users.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="3.2" />
        <vers num="3.2.4" />
        <vers num="3.2.5" />
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0065" published="1998-08-31" name="CVE-1999-0065" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in how dtmail handles attachments allows a remote attacker to execute commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/181" source="SUN">00181</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0066" published="1995-07-31" name="CVE-1999-0066" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">AnyForm CGI remote execution.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/719" source="BID">719</ref>
    </refs>
    <vuln_soft>
      <prod vendor="john_s._roberts" name="anyform">
        <vers num="1.0" />
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0067" published="1996-03-20" name="CVE-1999-0067" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">phf CGI program allows remote command execution through shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1996-06.html" source="CERT">CA-1996-06</ref>
      <ref url="http://www.securityfocus.com/bid/629" source="BID">629</ref>
      <ref url="http://www.osvdb.org/136" source="OSVDB">136</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="1.0.3" />
      </prod>
      <prod vendor="ncsa" name="ncsa_httpd">
        <vers num="1.5a" edition="" />
        <vers num="1.5a" edition=":export" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0068" published="1997-10-19" name="CVE-1999-0068" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">CGI PHP mylog script allows an attacker to read any file on the target server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/713" source="BID">713</ref>
      <ref url="http://www.osvdb.org/3396" source="OSVDB">3396</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="2.0b10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0069" published="1998-04-29" name="CVE-1999-0069" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Solaris ufsrestore buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/8158" source="OSVDB">8158</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/169" source="SUN">00169</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.5" />
        <vers num="2.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0070" published="1996-04-01" name="CVE-1999-0070" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">test-cgi program allows an attacker to list files on the server.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="" />
      </prod>
      <prod vendor="ncsa" name="ncsa_web_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0071" published="1997-09-01" name="CVE-1999-0071" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Apache httpd cookie buffer overflow for versions 1.1.1 and earlier.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="1.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0072" published="1997-10-22" name="CVE-1999-0072" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in AIX xdat gives root access to local users.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
        <vers num="4.2" />
        <vers num="4.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0073" published="1995-10-13" name="CVE-1999-0073" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Telnet allows a remote client to specify environment variables including LD_LIBRARY_PATH, allowing an attacker to bypass the normal system libraries and gain root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="digital" name="osf_1">
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="3.2" />
      </prod>
      <prod vendor="digital" name="unix">
        <vers num="3.2g" />
        <vers num="4.0" />
      </prod>
      <prod vendor="sgi" name="irix">
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.1" />
        <vers num="5.1.1" />
        <vers num="5.2" />
        <vers num="5.3" edition="" />
        <vers num="5.3" edition=":xfs" />
        <vers num="6.0" />
        <vers num="6.0.1" edition="" />
        <vers num="6.0.1" edition=":xfs" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0074" published="1997-07-01" name="CVE-1999-0074" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Listening TCP ports are sequentially allocated, allowing spoofing attacks.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="6.2" edition="stable" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.20.1" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="2.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0075" published="1996-10-16" name="CVE-1999-0075" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PASV core dump in wu-ftpd daemon when attacker uses a QUOTE PASV command after specifying a username and password.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/5742" source="OSVDB">5742</ref>
    </refs>
    <vuln_soft>
      <prod vendor="washington_university" name="wu-ftpd">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0076" published="1997-07-01" name="CVE-1999-0076" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in wu-ftp from PASV command causes a core dump.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="washington_university" name="wu-ftpd">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0077" published="1995-01-01" name="CVE-1999-0077" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Predictable TCP sequence numbers allow spoofing.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/139.php" source="XF" patch="1" adv="1">tcp-seq-predict(139)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0078" published="1996-04-18" name="CVE-1999-0078" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="ncr" name="mp-ras">
        <vers num="2.03" />
        <vers num="3.0" />
        <vers num="3.01" />
      </prod>
      <prod vendor="bsdi" name="bsd_os">
        <vers num="" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="6.2" edition="stable" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="3.2" />
        <vers num="4.1" />
        <vers num="4.2" />
      </prod>
      <prod vendor="nec" name="up-ux_v">
        <vers num="" />
      </prod>
      <prod vendor="next" name="nextstep">
        <vers num="" />
      </prod>
      <prod vendor="sco" name="openserver">
        <vers num="5" />
      </prod>
      <prod vendor="sco" name="unixware">
        <vers num="2.1" />
      </prod>
      <prod vendor="sgi" name="irix">
        <vers num="5.3" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.4" />
        <vers num="2.5" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0079" published="1997-09-12" name="CVE-1999-0079" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Remote attackers can cause a denial of service in FTP by issuing multiple PASV commands, causing the server to run out of available ports.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="bisonware" name="bisonware_ftp_server">
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0080" published="1995-11-30" name="CVE-1999-0080" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Certain configurations of wu-ftp FTP server 2.4 use a _PATH_EXECPATH setting to a directory with dangerous commands, such as /bin, which allows remote authenticated users to gain root access via the "site exec" command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="washington_university" name="wu-ftpd">
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0081" published="1997-01-11" name="CVE-1999-0081" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">wu-ftp allows files to be overwritten via the rnfr command.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="washington_university" name="wu-ftpd">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0082" published="1988-11-11" name="CVE-1999-0082" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">CWD ~root command in ftpd allows root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.alw.nih.gov/Security/Docs/admin-guide-to-cracking.101.html" source="FarmerVenema">Improving the Security of Your Site by Breaking Into it</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ftp" name="ftp">
        <vers num="" />
      </prod>
      <prod vendor="ftpcd" name="ftpcd">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0083" published="1997-06-11" name="CVE-1999-0083" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">getcwd() file descriptor leak in FTP.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0084" published="1990-05-01" name="CVE-1999-0084" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Certain NFS servers allow users to use mknod to gain privileges by creating a writable kmem device and setting the UID to 0.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/78" source="XF">nfs-mknod(78)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="nfs">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0085" published="1996-08-21" name="CVE-1999-0085" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in rwhod on AIX and other operating systems allows remote attackers to execute arbitrary code via a UDP packet with a long hostname.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/119" source="XF">rwhod(119)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/118" source="XF">rwhod-vuln(118)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="6.2" edition="stable" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="4.2" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="2.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0086" published="1998-01-08" name="CVE-1999-0086" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">AIX routed allows remote users to modify sensitive files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="3.2" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0087" published="1998-02-01" name="CVE-1999-0087" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service in AIX telnet can freeze a system and prevent users from accessing the server.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/7992" source="OSVDB">7992</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0088" published="1998-10-26" name="CVE-1999-0088" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">IRIX and AIX automountd services (autofsd) allow remote users to execute root commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0089" published="1997-10-28" name="CVE-1999-0089" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in AIX libDtSvc library can allow local users to gain root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0090" published="1997-10-01" name="CVE-1999-0090" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in AIX rcp command allows local users to obtain root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0091" published="1997-10-28" name="CVE-1999-0091" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in AIX writesrv command allows local users to obtain root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
        <vers num="4.2" />
        <vers num="4.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0092" published="1997-10-29" name="CVE-1999-0092" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Various vulnerabilities in the AIX portmir command allows local users to obtain root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0093" published="1997-10-29" name="CVE-1999-0093" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">AIX nslookup command allows local users to obtain root access by not dropping privileges correctly.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0094" published="1997-10-29" name="CVE-1999-0094" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">AIX piodmgrsu command allows local users to gain additional group privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0095" published="1988-10-01" name="CVE-1999-0095" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The debug command in Sendmail is enabled, allowing attackers to execute commands as root.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1" source="BID">1</ref>
      <ref url="http://www.osvdb.org/195" source="OSVDB">195</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eric_allman" name="sendmail">
        <vers num="5.58" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0096" published="1996-12-10" name="CVE-1999-0096" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sendmail decode alias can be used to overwrite sensitive files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/122&amp;type=0&amp;nav=sec.sba" source="SUN">00122</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bsdi" name="bsd_os">
        <vers num="" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="2.1.5" />
        <vers num="2.1.6" />
        <vers num="2.1.6.1" />
      </prod>
      <prod vendor="sco" name="internet_faststart">
        <vers num="1.0" />
        <vers num="1.1" />
      </prod>
      <prod vendor="sco" name="openserver">
        <vers num="5.0" />
        <vers num="5.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0097" published="1997-10-29" name="CVE-1999-0097" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The AIX FTP client can be forced to execute commands from a malicious server through shell metacharacters (e.g. a pipe character).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.00" />
        <vers num="10.10" />
        <vers num="10.16" />
        <vers num="10.20" />
        <vers num="10.24" />
        <vers num="11.00" />
        <vers num="9.00" />
        <vers num="9.01" />
        <vers num="9.03" />
        <vers num="9.04" />
        <vers num="9.05" />
        <vers num="9.06" />
        <vers num="9.07" />
        <vers num="9.08" />
        <vers num="9.09" />
        <vers num="9.10" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="3.2" />
        <vers num="3.2.4" />
        <vers num="3.2.5" />
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
        <vers num="4.2" />
        <vers num="4.2.1" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.3" />
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":ppc" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="4.1.3c" />
        <vers num="4.1.3u1" />
        <vers num="4.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0098" published="1998-04-01" name="CVE-1999-0098" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in SMTP HELO command in Sendmail allows a remote attacker to hide activities.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="apple" name="appleshare">
        <vers num="" edition=":" />
        <vers num="" edition="::jp" />
      </prod>
      <prod vendor="pmail" name="mercury_mail_server">
        <vers num="" />
      </prod>
      <prod vendor="slmail" name="slmail">
        <vers num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0099" published="1995-10-19" name="CVE-1999-0099" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in syslog utility allows local or remote attackers to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="bsdi" name="bsd_os">
        <vers num="2.0" />
        <vers num="2.0.1" />
      </prod>
      <prod vendor="convex" name="convexos">
        <vers num="10.1" />
        <vers num="10.2" />
        <vers num="11.0" />
        <vers num="11.1" />
      </prod>
      <prod vendor="convex" name="spp-ux">
        <vers num="3" />
      </prod>
      <prod vendor="cray" name="unicos">
        <vers num="8.0" />
        <vers num="8.3" />
        <vers num="9.0" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="3.2" />
        <vers num="4.1" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.3" />
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="4.1.3" />
        <vers num="4.1.3u1" />
        <vers num="4.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0100" published="1997-01-01" name="CVE-1999-0100" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Remote access in AIX innd 1.5.1, using control messages.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="isc" name="inn">
        <vers num="1.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0101" published="1996-12-10" name="CVE-1999-0101" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in AIX and Solaris "gethostbyname" library call allows root access through corrupt DNS host names.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/h-13.shtml" source="CIAC" adv="1">H-13</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="3.2" />
        <vers num="4.1" />
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0102" published="1998-07-09" name="CVE-1999-0102" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in SLmail 3.x allows attackers to execute commands using a large FROM line.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="seattle_lab_software" name="slmail">
        <vers num="3.0.2421" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0103" published="1996-02-08" name="CVE-1999-0103" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Echo and chargen, or other combinations of UDP services, can be used in tandem to flood the server, a.k.a. UDP bomb or UDP packet storm.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0104" published="1997-12-16" name="CVE-1999-0104" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5743" source="OVAL">oval:org.mitre.oval:def:5743</ref>
    </refs>
    <vuln_soft>
      <prod vendor="caldera" name="openlinux">
        <vers num="2.0" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_95">
        <vers num="0a" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp2" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="4.1.3u1" />
        <vers num="4.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0105" published="1997-03-01" name="CVE-1999-0105" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">finger allows recursive searches by using a long string of @ symbols.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0106" published="1997-03-01" name="CVE-1999-0106" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Finger redirection allows finger bombs.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0107" published="1997-12-30" name="CVE-1999-0107" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a large number of / characters.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="0.8.11" />
        <vers num="0.8.14" />
        <vers num="1.0" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.5" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0108" published="1998-05-01" name="CVE-1999-0108" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The printers program in IRIX has a buffer overflow that gives root access to local users.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0109" published="1997-02-10" name="CVE-1999-0109" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in ffbconfig in Solaris 2.5.1.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/140" source="SUN">00140</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":ppc" />
        <vers num="2.5.1" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="1999-0110" reject="1" published="1999-01-01" name="CVE-1999-0110" modified="2008-09-09">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-0315.  Reason: This candidate's original description had a typo that delayed it from being detected as a duplicate of CVE-1999-0315.  Notes: All CVE users should reference CVE-1999-0315 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0111" published="1997-07-01" name="CVE-1999-0111" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">RIP v1 is susceptible to spoofing.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="3.2" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0112" published="1997-05-01" name="CVE-1999-0112" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in AIX dtterm program for the CDE.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/878" source="XF">dtterm-bo(878)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cde" name="cde">
        <vers num="" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="4.1" />
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0113" published="1994-05-23" name="CVE-1999-0113" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Some implementations of rlogin allow root access if given a -froot parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/458" source="BID">458</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.2.4" />
        <vers num="3.2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0114" published="1998-01-01" name="CVE-1999-0114" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Local users can execute commands as other users, and read other users' files, through the filter command in the Elm elm-2.4 mail package using a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="elm_development_group" name="elm">
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0115" published="1997-09-01" name="CVE-1999-0115" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">AIX bugfiler program allows local users to gain root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1800" source="BID">1800</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.2.4" />
        <vers num="3.2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0116" published="1996-09-19" name="CVE-1999-0116" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service when an attacker sends many SYN packets to create multiple connections without ever sending an ACK to complete the connection, aka SYN flood.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/136" source="SUN">00136</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19961202-01-PX" source="SGI">19961202-01-PX</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="sng">
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="3.2.5" />
        <vers num="4.1" />
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0117" published="1992-03-31" name="CVE-1999-0117" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">AIX passwd allows local users to gain root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="3.1" />
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0118" published="1998-11-01" name="CVE-1999-0118" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">AIX infod allows local users to gain root access through an X display.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91158980826979&amp;w=2" source="BUGTRAQ">19981119 RSI.0011.11-09-98.AIX.INFOD</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="3.2" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0119" published="1999-01-19" name="CVE-1999-0119" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Windows NT 4.0 beta allows users to read and delete shares.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0120" published="1994-03-21" name="CVE-1999-0120" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Sun/Solaris utmp file allows local users to gain root access if it is writable by users other than root.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/126" source="SUN">00126</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="1.1.1a" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0121" published="1999-01-21" name="CVE-1999-0121" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in dtaction command gives root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0122" published="1997-07-21" name="CVE-1999-0122" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in AIX lchangelv gives root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0123" published="1995-12-01" name="CVE-1999-0123" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">Race condition in Linux mailx command allows local users to read user files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0124" published="1993-08-09" name="CVE-1999-0124" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Vulnerabilities in UMN gopher and gopher+ versions 1.12 and 2.0x allow an intruder to read any files that can be accessed by the gopher daemon.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="university_of_minnesota" name="gopherd">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0125" published="1998-01-25" name="CVE-1999-0125" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in SGI IRIX mailx program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19980605-01-PX" source="SGI">19980605-01-PX</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="4.2" />
      </prod>
      <prod vendor="sgi" name="irix">
        <vers num="5.2" />
        <vers num="5.3" />
        <vers num="6.3" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":ppc" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="2.6" edition="hw3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0126" published="1998-05-03" name="CVE-1999-0126" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">SGI IRIX buffer overflow in xterm and Xaw allows root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.ciac.org/ciac/bulletins/j-010.shtml" source="CIAC">J-010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xfree86_project" name="xfree86">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0127" published="1996-12-19" name="CVE-1999-0127" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">swinstall and swmodify commands in SD-UX package in HP-UX systems allow local users to create or overwrite arbitrary files to gain root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0128" published="1996-12-18" name="CVE-1999-0128" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="ibm" name="sng">
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
      <prod vendor="digital" name="osf_1">
        <vers num="1.3.3" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="3.2" />
        <vers num="4.1" />
        <vers num="4.2" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="1.3.0" />
        <vers num="2.0" />
      </prod>
      <prod vendor="sco" name="internet_faststart">
        <vers num="1.0" />
        <vers num="1.1" />
      </prod>
      <prod vendor="sco" name="open_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="sco" name="openserver">
        <vers num="5.0" />
        <vers num="5.0.2" />
      </prod>
      <prod vendor="sco" name="tcp_ip">
        <vers num="1.2.1" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="5.4" edition="" />
        <vers num="5.4" edition=":x86" />
        <vers num="5.5" edition="" />
        <vers num="5.5" edition=":x86" />
        <vers num="5.5.1" edition="" />
        <vers num="5.5.1" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0129" published="1996-12-03" name="CVE-1999-0129" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="eric_allman" name="sendmail">
        <vers num="8.8" />
        <vers num="8.8.1" />
        <vers num="8.8.2" />
        <vers num="8.8.3" />
      </prod>
      <prod vendor="bsdi" name="bsd_os">
        <vers num="2.1" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="2.1.5" />
        <vers num="2.1.6" />
        <vers num="2.1.6.1" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.00" />
        <vers num="10.01" />
        <vers num="10.10" />
        <vers num="10.16" />
        <vers num="10.20" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="3.2" />
        <vers num="4.1" />
        <vers num="4.2" />
      </prod>
      <prod vendor="sco" name="internet_faststart">
        <vers num="1.0" />
        <vers num="1.1" />
      </prod>
      <prod vendor="sco" name="openserver">
        <vers num="5.0" />
        <vers num="5.0.2" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.3" />
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":x86" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="4.1.3u1" />
        <vers num="4.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0130" published="1996-11-16" name="CVE-1999-0130" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Local users can start Sendmail in daemon mode and gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/716" source="BID">716</ref>
    </refs>
    <vuln_soft>
      <prod vendor="caldera" name="network_desktop">
        <vers num="1.0" />
      </prod>
      <prod vendor="eric_allman" name="sendmail">
        <vers num="8.7" />
        <vers num="8.8" />
        <vers num="8.8.1" />
        <vers num="8.8.2" />
      </prod>
      <prod vendor="bsdi" name="bsd_os">
        <vers num="2.1" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="2.1.5" />
        <vers num="2.1.6" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.00" />
        <vers num="10.01" />
        <vers num="10.10" />
        <vers num="10.20" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="4.2" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0131" published="1996-09-11" name="CVE-1999-0131" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/717" source="BID">717</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eric_allman" name="sendmail">
        <vers num="8.6" />
        <vers num="8.7.1" />
        <vers num="8.7.2" />
        <vers num="8.7.3" />
        <vers num="8.7.4" />
        <vers num="8.7.5" />
      </prod>
      <prod vendor="bsdi" name="bsd_os">
        <vers num="2.1" />
      </prod>
      <prod vendor="digital" name="osf_1">
        <vers num="1.3.2" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="2.1.5" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.01" />
        <vers num="10.10" />
        <vers num="10.20" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="3.2" />
        <vers num="4.1" />
        <vers num="4.2" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="3.0.3" />
      </prod>
      <prod vendor="sco" name="internet_faststart">
        <vers num="1.0" />
      </prod>
      <prod vendor="sco" name="openserver">
        <vers num="5.0" />
        <vers num="5.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0132" published="1996-08-15" name="CVE-1999-0132" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Expreserve, as used in vi and ex, allows local users to overwrite arbitrary files and gain root access.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1996-19.html" source="CERT">CA-1996-19</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/401" source="XF">expreserve(401)</ref>
      <ref url="http://www.osvdb.org/11723" source="OSVDB">11723</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10" />
        <vers num="9" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.3c" />
        <vers num="4.1.3u1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0133" published="1996-08-14" name="CVE-1999-0133" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">fm_fls license server for Adobe Framemaker allows local users to overwrite arbitrary files and gain root access.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="adobe" name="framemaker">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0134" published="1996-08-06" name="CVE-1999-0134" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">vold in Solaris 2.x allows local users to gain root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/8159" source="OSVDB">8159</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="5.4" edition="" />
        <vers num="5.4" edition=":x86" />
        <vers num="5.5" edition="" />
        <vers num="5.5" edition=":x86" />
        <vers num="5.5.1" edition="" />
        <vers num="5.5.1" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0135" published="1996-07-25" name="CVE-1999-0135" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">admintool in Solaris allows a local user to write to arbitrary files and gain root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":ppc" />
        <vers num="2.5.1" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0136" published="1996-07-31" name="CVE-1999-0136" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Kodak Color Management System (KCMS) on Solaris allows a local user to write to arbitrary files and gain root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.5" />
        <vers num="2.5.1" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="5.5" edition="" />
        <vers num="5.5" edition=":x86" />
        <vers num="5.5.1" edition="" />
        <vers num="5.5.1" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0137" published="1996-07-09" name="CVE-1999-0137" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The dip program on many Linux systems allows local users to gain root access via a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="fred_n._van_kempen" name="dip">
        <vers num="3.3.7o" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0138" published="1996-06-26" name="CVE-1999-0138" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="apple" name="a_ux">
        <vers num="3.1.1" />
      </prod>
      <prod vendor="digital" name="osf_1">
        <vers num="1.3" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="2.0" />
        <vers num="2.0.5" />
        <vers num="2.1.0" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="10" />
        <vers num="8" />
        <vers num="9" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="3.2.5" />
        <vers num="4" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="1.2.0" />
        <vers num="2.0" />
      </prod>
      <prod vendor="nec" name="asl_ux_4800">
        <vers num="" />
      </prod>
      <prod vendor="nec" name="ews-ux_v">
        <vers num="4.2" />
        <vers num="4.2mp" />
      </prod>
      <prod vendor="nec" name="up-ux_v">
        <vers num="4.2mp" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0139" published="1998-12-12" name="CVE-1999-0139" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Solaris x86 mkcookie allows local users to obtain root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/8205" source="OSVDB">8205</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0140" published="1999-06-30" name="CVE-1999-0140" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service in RAS/PPTP on NT systems.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0141" published="1996-03-29" name="CVE-1999-0141" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">Java Bytecode Verifier allows malicious applets to execute arbitrary commands as the user of the applet.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/134" source="SUN">00134</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="navigator">
        <vers num="2.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0142" published="1996-03-01" name="CVE-1999-0142" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Java Applet Security Manager implementation in Netscape Navigator 2.0 and Java Developer's Kit 1.0 allows an applet to connect to arbitrary hosts.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="netscape" name="navigator">
        <vers num="" />
      </prod>
      <prod vendor="sun" name="java">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0143" published="1996-02-21" name="CVE-1999-0143" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Kerberos 4 key servers allow a user to masquerade as another by breaking and generating session keys.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="4.0" />
        <vers num="5" />
      </prod>
      <prod vendor="process_software" name="multinet">
        <vers num="3.4" />
        <vers num="3.5" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.3" />
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0144" published="1997-06-01" name="CVE-1999-0144" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Denial of service in Qmail by specifying a large number of recipients with the RCPT command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/208.php" source="XF" adv="1">qmail-rcpt</ref>
      <ref url="http://www.securityfocus.com/bid/2237" source="BID">2237</ref>
      <ref url="http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html" source="MISC">http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html</ref>
      <ref url="http://cr.yp.to/qmail/venema.html" source="MISC">http://cr.yp.to/qmail/venema.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319029&amp;w=2" source="BUGTRAQ">19970612 Re: Denial of service (qmail-smtpd)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319024&amp;w=2" source="BUGTRAQ">19970612 qmail-dos-2.c, another denial of service attack</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0145" published="1993-09-30" name="CVE-1999-0145" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Sendmail WIZ command enabled, allowing root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1993-14.html" source="CERT">CA-1993-14</ref>
      <ref url="http://www.cert.org/advisories/CA-1990-11.html" source="CERT">CA-1990-11</ref>
      <ref url="http://www2.dataguard.no/bugtraq/1995_1/0332.html" source="BUGTRAQ">19950206 sendmail wizard thing...</ref>
      <ref url="http://www.alw.nih.gov/Security/Docs/admin-guide-to-cracking.101.html" source="FarmerVenema">Improving the Security of Your Site by Breaking Into it</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eric_allman" name="sendmail">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0146" published="1997-07-15" name="CVE-1999-0146" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The campas CGI program provided with some NCSA web servers allows an attacker to execute arbitrary commands via encoded carriage return characters in the query string, as demonstrated by reading the password file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/298" source="XF">http-cgi-campas(298)</ref>
      <ref url="http://www.securityfocus.com/bid/1975" source="BID">1975</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ncsa" name="campas">
        <vers num="" />
      </prod>
      <prod vendor="ncsa" name="servers">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0147" published="1997-07-01" name="CVE-1999-0147" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The aglimpse CGI program of the Glimpse package allows remote execution of arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="university_of_arizona" name="glimpse_http">
        <vers num="2.0" />
      </prod>
      <prod vendor="university_of_arizona" name="webglimpse">
        <vers prev="1" num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0148" published="1997-09-01" name="CVE-1999-0148" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The handler CGI program in IRIX allows arbitrary command execution.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/380" source="BID">380</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX" source="SGI">19970501-02-PX</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="5.3" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0149" published="1997-04-19" name="CVE-1999-0149" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The wrap CGI program in IRIX allows remote attackers to view arbitrary directory listings via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/290" source="XF">http-sgi-wrap(290)</ref>
      <ref url="http://www.securityfocus.com/bid/373" source="BID">373</ref>
      <ref url="http://www.osvdb.org/247" source="OSVDB">247</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX" source="SGI">19970501-02-PX</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0150" published="1997-07-01" name="CVE-1999-0150" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Perl fingerd program allows arbitrary command execution from remote users.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="gnu" name="fingerd">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0151" published="1995-04-03" name="CVE-1999-0151" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">The SATAN session key may be disclosed if the user points the web browser to other sites, possibly allowing root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="satan" name="satan">
        <vers num="1.0" />
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0152" published="1997-08-11" name="CVE-1999-0152" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The DG/UX finger daemon allows remote command execution through shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="data_general" name="dg_ux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0153" published="1997-07-01" name="CVE-1999-0153" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/1666" source="OSVDB">1666</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_95">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
      <prod vendor="sco" name="openserver">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0154" published="1999-12-31" name="CVE-1999-0154" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="2.0" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0155" published="1995-08-31" name="CVE-1999-0155" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The ghostscript command with the -dSAFER option allows remote attackers to execute commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="aladdin_enterprises" name="ghostscript">
        <vers num="2.6" />
        <vers num="3.22" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0156" published="1997-07-01" name="CVE-1999-0156" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">wu-ftpd FTP daemon allows any user and password combination.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="washington_university" name="wu-ftpd">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0157" published="1998-08-18" name="CVE-1999-0157" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco PIX firewall and CBAC IP fragmentation attack results in a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/1097" source="OSVDB">1097</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="11.2p" />
        <vers num="11.3t" />
        <vers num="12.0" />
        <vers num="12.0t" />
      </prod>
      <prod vendor="cisco" name="pix_firewall">
        <vers num="4.2(1)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0158" published="1998-08-31" name="CVE-1999-0158" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco PIX firewall manager (PFM) on Windows NT allows attackers to connect to port 8080 on the PFM server and retrieve any file whose name and location is known.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/770/pixmgrfile-pub.shtml" source="CISCO" patch="1" adv="1">20010913 Cisco PIX Firewall Manager File Exposure</ref>
      <ref url="http://www.osvdb.org/685" source="OSVDB">685</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="pix_firewall">
        <vers num="4.1(6)" />
        <vers num="4.2(1)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0159" published="1998-08-12" name="CVE-1999-0159" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Attackers can crash a Cisco IOS router or device, provided they can get to an interactive prompt (such as a login).  This applies to some IOS 9.x, 10.x, and 11.x releases.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="11.0(20.3)" />
        <vers num="11.1(15)ca" />
        <vers num="11.1(16)" />
        <vers num="11.1(16)aa" />
        <vers num="11.1(16)ia" />
        <vers num="11.1(17)cc" />
        <vers num="11.1(17)ct" />
        <vers num="11.2(10)" />
        <vers num="11.2(10)bc" />
        <vers num="11.2(8)sa3" />
        <vers num="11.2(9)p" />
        <vers num="11.2(9)xa" />
        <vers num="11.3(1)" />
        <vers num="11.3(1)ed" />
        <vers num="11.3(1)t" />
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0160" published="1997-10-01" name="CVE-1999-0160" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Some classic Cisco IOS devices have a vulnerability in the PPP CHAP authentication to establish unauthorized PPP connections.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/1099" source="OSVDB">1099</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="10.3" />
        <vers num="11.0" />
        <vers num="11.1" />
        <vers num="11.2" />
        <vers num="11.2p" />
        <vers num="4.1" />
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0161" published="1995-07-31" name="CVE-1999-0161" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">In Cisco IOS 10.3, with the tacacs-ds or tacacs keyword, an extended IP access control list could bypass filtering.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/797" source="OSVDB">797</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="10.3(3.4)" />
        <vers num="10.3(4.2)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0162" published="1998-09-01" name="CVE-1999-0162" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The "established" keyword in some Cisco IOS software allowed an attacker to bypass filtering.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="11.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0163" published="1997-01-01" name="CVE-1999-0163" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">In older versions of Sendmail, an attacker could use a pipe character to execute root commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="eric_allman" name="sendmail">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0164" published="1995-08-29" name="CVE-1999-0164" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">A race condition in the Solaris ps command allows an attacker to overwrite critical files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/8346" source="OSVDB">8346</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="5.3" />
        <vers num="5.4" edition="" />
        <vers num="5.4" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0165" published="1997-03-01" name="CVE-1999-0165" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">NFS cache poisoning.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sun" name="nfs">
        <vers num="" />
      </prod>
      <prod vendor="bsdi" name="bsd_os">
        <vers num="" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.20.1" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="1.1" />
        <vers num="1.1.1a" />
        <vers num="1.1.2" />
        <vers num="1.2" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="3.5" />
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0166" published="1997-01-01" name="CVE-1999-0166" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">NFS allows users to use a "cd .." command to access other directories besides the exported file system.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sun" name="nfs">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0167" published="1991-12-06" name="CVE-1999-0167" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">In SunOS, NFS file handles could be guessed, giving unauthorized access to the exported file system.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="4.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0168" published="1992-06-04" name="CVE-1999-0168" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The portmapper may act as a proxy and redirect service requests from an attacker, making the request appear to come from the local host, possibly bypassing authentication that would otherwise have taken place.  For example, NFS file systems could be mounted through the portmapper despite export restrictions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="4.1.3" />
        <vers num="4.1.3c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0169" published="1997-07-01" name="CVE-1999-0169" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">NFS allows attackers to read and write any file on the system by specifying a false UID.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sun" name="nfs">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0170" published="1997-01-01" name="CVE-1999-0170" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Remote attackers can mount an NFS file system in Ultrix or OSF, even if it is denied on the access list.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="digital" name="ultrix">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0171" published="1997-01-01" name="CVE-1999-0171" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Denial of service in syslog by sending it a large number of superfluous messages.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.20.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0172" published="1995-08-02" name="CVE-1999-0172" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">FormMail CGI program allows remote execution of commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="matt_wright" name="formmail">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0173" published="1997-01-01" name="CVE-1999-0173" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">FormMail CGI program can be used by web servers other than the host server that the program resides on.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="matt_wright" name="formmail">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0174" published="1997-02-01" name="CVE-1999-0174" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The view-source CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="netscape" name="communicator">
        <vers num="4.0" />
        <vers num="4.05" />
        <vers num="4.06" />
        <vers num="4.07" />
        <vers num="4.5" />
        <vers num="4.51" />
        <vers num="4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0175" published="1996-07-01" name="CVE-1999-0175" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The convert.bas program in the Novell web server allows a remote attackers to read any file on the system that is internally accessible by the web server.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="novell" name="web_server">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0176" published="1997-07-10" name="CVE-1999-0176" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Webgais program allows a remote user to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="webgais_development_team" name="webgais">
        <vers prev="1" num="1.0b2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0177" published="1997-09-01" name="CVE-1999-0177" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The uploader program in the WebSite web server allows a remote attacker to execute arbitrary programs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="oreilly" name="website">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0178" published="1997-01-01" name="CVE-1999-0178" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the win-c-sample program (win-c-sample.exe) in the WebSite web server 1.1e allows remote attackers to execute arbitrary code via a long query string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/295" source="XF">http-website-winsample(295)</ref>
      <ref url="http://www.securityfocus.com/bid/2078" source="BID">2078</ref>
      <ref url="http://www.osvdb.org/8" source="OSVDB">8</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/1997_1/0021.html" source="BUGTRAQ">19970106 Re: signal handling</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oreilly" name="oreilly_website">
        <vers num="1.1e" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0179" published="1997-01-01" name="CVE-1999-0179" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Windows NT crashes or locks up when a Samba client executes a "cd .." command on a file share.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q140818" source="MSKB">Q140818</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_95">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="3.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0180" published="1997-01-01" name="CVE-1999-0180" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">in.rshd allows users to login with a NULL username and execute commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0181" published="1994-01-01" name="CVE-1999-0181" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The wall daemon can be used for denial of service, social engineering attacks, or to execute remote commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="rpc.walld" name="rpc.walld">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0182" published="1997-09-30" name="CVE-1999-0182" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Samba has a buffer overflow which allows a remote attacker to obtain root access by specifying a long password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ciac.org/ciac/bulletins/h-110.shtml" source="CIAC">H-110</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers prev="1" num="1.9.17" edition="p2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0183" published="1997-09-01" name="CVE-1999-0183" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Linux implementations of TFTP would allow access to files outside the restricted directory.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="tftp" name="tftp">
        <vers num="" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.20.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0184" published="1997-07-01" name="CVE-1999-0184" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">When compiled with the -DALLOW_UPDATES option, bind allows dynamic updates to the DNS server, allowing for malicious modification of DNS records.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="isc" name="bind">
        <vers num="9.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0185" published="1997-10-01" name="CVE-1999-0185" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">In SunOS or Solaris, a remote user could connect from an FTP server's data port to an rlogin server on a host that trusts the FTP server, allowing remote command execution.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/156" source="SUN">00156</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.3" />
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":x86" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="4.1.3u1" />
        <vers num="4.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0186" published="1998-10-01" name="CVE-1999-0186" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">In Solaris, an SNMP subagent has a default community string that allows remote attackers to execute arbitrary commands as root, or modify system parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10080762.htm" source="CONFIRM">http://support.novell.com/cgi-bin/search/searchtid.cgi?/10080762.htm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="1999-0187" reject="1" published="1999-01-01" name="CVE-1999-0187" modified="2008-09-09">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-0022.  Reason: This candidate is a duplicate of CVE-1999-0022.  Notes: All CVE users should reference CVE-1999-0022 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0188" published="1998-12-17" name="CVE-1999-0188" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The passwd command in Solaris can be subjected to a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/182" source="SUN">00182</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.3" />
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0189" published="1997-06-04" name="CVE-1999-0189" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/142" source="SUN">00142</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.3" />
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0190" published="1998-04-08" name="CVE-1999-0190" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Solaris rpcbind can be exploited to overwrite arbitrary files and gain root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/167" source="SUN">00167</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.3" />
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0191" published="1997-09-01" name="CVE-1999-0191" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">IIS newdsn.exe CGI script allows remote users to overwrite files.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/275" source="OSVDB">275</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0192" published="1997-10-18" name="CVE-1999-0192" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" edition="" />
        <vers num="5.2" edition=":i386" />
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":i386" />
      </prod>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="3.5" />
        <vers num="3.6" />
        <vers num="3.9" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0193" published="1997-12-01" name="CVE-1999-0193" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service in Ascend and 3com routers, which can be rebooted by sending a zero length TCP option.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="ascend" name="cascadeview_ux">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0194" published="1999-05-01" name="CVE-1999-0194" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service in in.comsat allows attackers to generate messages.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0195" published="1997-07-01" name="CVE-1999-0195" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service in RPC portmapper allows attackers to register or unregister RPC services or spoof RPC services using a spoofed source IP address such as 127.0.0.1.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.20.1" />
      </prod>
      <prod vendor="sgi" name="irix">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0196" published="1997-07-08" name="CVE-1999-0196" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">websendmail in Webgais 1.0 allows a remote user to access arbitrary files and execute arbitrary code via the receiver parameter ($VAR_receiver variable).</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2077" source="BID">2077</ref>
      <ref url="http://www.osvdb.org/237" source="OSVDB">237</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webgais_development_team" name="webgais">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0197" published="1999-01-01" name="CVE-1999-0197" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">finger 0@host on some systems may print information on some user accounts.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0198" published="1999-01-01" name="CVE-1999-0198" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">finger .@host on some systems may print information on some user accounts.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0200" published="1999-01-01" name="CVE-1999-0200" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Windows NT FTP server (WFTP) with the guest account enabled without a password allows an attacker to log into the FTP server using any username and password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0201" published="1997-01-01" name="CVE-1999-0201" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">A quote cwd command on FTP servers can reveal the full path of the home directory of the "ftp" user.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="ftp" name="ftp">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0202" published="1997-01-01" name="CVE-1999-0202" modified="2010-03-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The GNU tar command, when used in FTP sessions, may allow an attacker to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="university_of_washington" name="wu-ftpd">
        <vers num="2.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0203" published="1995-08-17" name="CVE-1999-0203" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">In Sendmail, attackers can gain root privileges via SMTP by specifying an improper "mail from" address and an invalid "rcpt to" address that would cause the mail to bounce to a program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="eric_allman" name="sendmail">
        <vers num="8.6.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0204" published="1997-01-01" name="CVE-1999-0204" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Sendmail 8.6.9 allows remote attackers to execute root commands, using ident.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="eric_allman" name="sendmail">
        <vers num="8.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0205" published="1999-01-01" name="CVE-1999-0205" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service in Sendmail 8.6.11 and 8.6.12.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="eric_allman" name="sendmail">
        <vers num="8.6.11" />
        <vers num="8.6.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0206" published="1996-10-01" name="CVE-1999-0206" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">MIME buffer overflow in Sendmail 8.8.0 and 8.8.1 gives root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="eric_allman" name="sendmail">
        <vers num="8.8" />
        <vers num="8.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0207" published="1994-06-09" name="CVE-1999-0207" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Remote attacker can execute commands through Majordomo using the Reply-To field and a "lists" command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="great_circle_associates" name="majordomo">
        <vers num="1.90" />
        <vers num="1.91" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0208" published="1995-12-12" name="CVE-1999-0208" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="3.2" />
        <vers num="4.1" />
      </prod>
      <prod vendor="nec" name="asl_ux_4800">
        <vers num="" />
      </prod>
      <prod vendor="nec" name="ews-ux_v">
        <vers num="" />
      </prod>
      <prod vendor="nec" name="up-ux_v">
        <vers num="" />
      </prod>
      <prod vendor="sgi" name="irix">
        <vers num="3" />
        <vers num="4" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0209" published="1990-08-14" name="CVE-1999-0209" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The SunView (SunTools) selection_svc facility allows remote users to read files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/8" source="BID">8</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="3.5" />
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.1" />
        <vers num="4.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0210" published="1997-11-26" name="CVE-1999-0210" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Automount daemon automountd allows local or remote users to gain privileges via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-99-05-statd-automountd.html" source="CERT" patch="1" adv="1">CA-99-05</ref>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9910-104" source="HP">HPSBUX9910-104</ref>
      <ref url="http://www.securityfocus.com/bid/235" source="BID">235</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91547759121289&amp;w=2" source="BUGTRAQ">19990103 SUN almost has a clue! (automountd)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88053459921223&amp;w=2" source="BUGTRAQ">19971126 Solaris 2.5.1 automountd exploit (fwd)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0211" published="1994-02-14" name="CVE-1999-0211" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Extra long export lists over 256 characters in some mount daemons allows NFS directories to be mounted by anyone.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/24" source="BID">24</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.0" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.3c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0212" published="1998-04-29" name="CVE-1999-0212" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Solaris rpc.mountd generates error messages that allow a remote attacker to determine what files are on the server.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ciac.org/ciac/bulletins/i-048.shtml" source="CIAC" patch="1">I-048</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.0" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0213" published="1998-07-15" name="CVE-1999-0213" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">libnsl in Solaris allowed an attacker to perform a denial of service of rpcbind.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.5.1" />
        <vers num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0214" published="1992-07-21" name="CVE-1999-0214" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Denial of service by sending forged ICMP unreachable packets.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0215" published="1998-10-26" name="CVE-1999-0215" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Routed allows attackers to append data to files.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ciac.org/ciac/bulletins/j-012.shtml" source="CIAC">J-012</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19981004-01-PX" source="SGI">19981004-01-PX</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="3" />
        <vers num="4" />
        <vers num="5" />
        <vers num="6.0.1" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0216" published="1997-11-01" name="CVE-1999-0216" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service of inetd on Linux through SYN and RST packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="gnu" name="inet">
        <vers num="5.01" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="10" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.20.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0217" published="1997-01-01" name="CVE-1999-0217" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Malicious option settings in UDP packets could force a reboot in SunOS 4.1.3 systems.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="4.0.3" />
        <vers num="4.0.3c" />
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.3a1" />
        <vers num="4.1psr_a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0218" published="1995-10-01" name="CVE-1999-0218" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Livingston portmaster machines could be rebooted via a series of commands.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="livingston_portmaster" name="portmaster">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0219" published="1997-07-01" name="CVE-1999-0219" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Buffer overflow in FTP Serv-U 2.5 allows remote authenticated users to cause a denial of service (crash) via a long (1) CWD or (2) LS (list) command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/205" source="XF">ftp-servu(205)</ref>
      <ref url="http://www.securityfocus.com/bid/269" source="BID">269</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92582581330282&amp;w=2" source="NTBUGTRAQ">19990504 Re: Buffer overflows in FTP Serv-U 2.5</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92574916930144&amp;w=2" source="NTBUGTRAQ">19990503 Buffer overflows in FTP Serv-U 2.5</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cat_soft" name="serv-u">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0220" published="1999-01-01" name="CVE-1999-0220" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Attackers can do a denial of service of IRC by crashing the server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0221" published="1999-03-01" name="CVE-1999-0221" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service of Ascend routers through port 150 (remote administration).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="lucent" name="ascend_routers">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0222" published="1999-03-01" name="CVE-1999-0222" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service in Cisco IOS web server allows attackers to reboot the router using a long URL.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="cisco" name="router">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0223" published="1999-03-01" name="CVE-1999-0223" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Solaris syslogd crashes when receiving a message from a host that doesn't have an inverse DNS entry.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1878" source="BID">1878</ref>
      <ref url="http://sunsolve.Sun.COM/pub-cgi/retrieve.pl?patchid=103291&amp;collection=fpatches" source="CONFIRM">http://sunsolve.Sun.COM/pub-cgi/retrieve.pl?patchid=103291&amp;collection=fpatches</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0224" published="1999-07-23" name="CVE-1999-0224" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service in Windows NT messenger service through a long username.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0225" published="1998-02-14" name="CVE-1999-0225" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed SMB logon request in which the actual data size does not match the specified size.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.nai.com/nai_labs/asp_set/advisory/25_windows_nt_dos_adv.asp" source="NAI" patch="1" adv="1">19980214 Windows NT Logon Denial of Service</ref>
      <ref url="http://www.microsoft.com/technet/support/kb.asp?ID=180963" source="MSKB">Q180963</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0226" published="1999-01-01" name="CVE-1999-0226" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0227" published="1997-06-01" name="CVE-1999-0227" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Access violation in LSASS.EXE (LSA/LSARPC) program in Windows NT allows a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q154087" source="MSKB">Q154087</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0228" published="1997-02-07" name="CVE-1999-0228" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service in RPCSS.EXE program (RPC Locator) in Windows NT.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q162567" source="MSKB">Q162567</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0229" published="1999-05-12" name="CVE-1999-0229" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service in Windows NT IIS server using ..\..</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0230" published="1997-12-15" name="CVE-1999-0230" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Cisco 7xx routers through the telnet service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/1102" source="OSVDB">1102</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0231" published="1999-01-01" name="CVE-1999-0231" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in IP-Switch IMail and Seattle Labs Slmail 2.6 packages using a long VRFY command, causing a denial of service and possibly remote access.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="seattle_lab_software" name="slmail">
        <vers num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0232" published="1995-02-01" name="CVE-1999-0232" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in NCSA WebServer (version 1.5c) gives remote access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0233" published="1996-02-25" name="CVE-1999-0233" modified="2010-12-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q155056" source="MSKB">Q155056</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q148188" source="MSKB">Q148188</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0234" published="1996-10-08" name="CVE-1999-0234" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Bash treats any character with a value of 255 as a command separator.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="caldera" name="openlinux">
        <vers num="" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="3.0.3" />
      </prod>
      <prod vendor="sgi" name="irix">
        <vers num="" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="4.2" />
      </prod>
      <prod vendor="yggdrasil" name="linux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0235" published="1995-02-17" name="CVE-1999-0235" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in NCSA WebServer (1.4.1 and below) gives remote access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="ncsa" name="ncsa_web_server">
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0236" published="1997-01-01" name="CVE-1999-0236" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="" />
      </prod>
      <prod vendor="ncsa" name="servers">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0237" published="1997-09-01" name="CVE-1999-0237" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Remote execution of arbitrary commands through Guestbook CGI program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="webcom" name="cgi_guestbook">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0238" published="1997-08-01" name="CVE-1999-0238" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">php.cgi allows attackers to read any file on the system.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="2.0b10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0239" published="1998-01-01" name="CVE-1999-0239" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Netscape FastTrack Web server lists files when a lowercase "get" command is used instead of an uppercase GET.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/122" source="OSVDB">122</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="fasttrack_server">
        <vers num="3.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0240" published="1999-01-01" name="CVE-1999-0240" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Some filters or firewalls allow fragmented SYN packets with IP reserved bits in violation of their implemented policy.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0241" published="1995-11-01" name="CVE-1999-0241" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="xfree86_project" name="x11r6">
        <vers num="" />
      </prod>
      <prod vendor="sgi" name="irix">
        <vers num="" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0242" published="1995-03-01" name="CVE-1999-0242" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Remote attackers can access mail files via POP3 in some Linux systems that are using shadow passwords.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0243" published="1999-01-01" name="CVE-1999-0243" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Linux cfingerd could be exploited to gain root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0244" published="1997-12-01" name="CVE-1999-0244" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Livingston RADIUS code has a buffer overflow which can allow remote execution of commands as root.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="livingston" name="radius">
        <vers num="1.x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0245" published="1995-09-07" name="CVE-1999-0245" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Some configurations of NIS+ in Linux allowed attackers to log in as the user "+".</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.20.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0246" published="1996-10-01" name="CVE-1999-0246" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">HP Remote Watch allows a remote user to gain root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0247" published="1997-07-21" name="CVE-1999-0247" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in nnrpd program in INN up to version 1.6 allows remote users to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1443" source="BID" adv="1">1443</ref>
      <ref url="http://www.nai.com/nai_labs/asp_set/advisory/17_inn_avd.asp" source="NAI">19970721 INN news server vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="inn">
        <vers num="1.4" />
        <vers num="1.4sec" />
        <vers num="1.4sec2" />
        <vers num="1.4unoff3" />
        <vers num="1.4unoff4" />
        <vers num="1.5" />
        <vers num="1.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0248" published="1999-01-01" name="CVE-1999-0248" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A race condition in the authentication agent mechanism of sshd 1.2.17 allows an attacker to steal another user's credentials.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.uni-karlsruhe.de/~ig25/ssh-faq/ssh-faq-6.html#ss6.1" source="CONFIRM">http://www.uni-karlsruhe.de/~ig25/ssh-faq/ssh-faq-6.html#ss6.1</ref>
      <ref url="http://oliver.efri.hr/~crv/security/bugs/mUNIXes/ssh2.html" source="MISC">http://oliver.efri.hr/~crv/security/bugs/mUNIXes/ssh2.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ssh" name="ssh">
        <vers num="1.2.27" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0249" published="1997-01-01" name="CVE-1999-0249" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Windows NT RSHSVC program allows remote users to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0250" published="1997-07-01" name="CVE-1999-0250" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Denial of service in Qmail through long SMTP commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html" source="MISC">http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html</ref>
      <ref url="http://cr.yp.to/qmail/venema.html" source="MISC">http://cr.yp.to/qmail/venema.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319024&amp;w=2" source="BUGTRAQ">19970612 qmail-dos-2.c, another denial of service attack</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dan_bernstein" name="qmail">
        <vers prev="1" num="1.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0251" published="1997-01-01" name="CVE-1999-0251" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service in talk program allows remote attackers to disrupt a user's display.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="talkd" name="talkd">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0252" published="1997-01-01" name="CVE-1999-0252" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in listserv allows arbitrary command execution.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="lsoft" name="listserv">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0253" published="1997-01-01" name="CVE-1999-0253" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0254" published="1998-11-02" name="CVE-1999-0254" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A hidden SNMP community string in HP OpenView allows remote attackers to modify MIB tables and obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0255" published="1999-01-01" name="CVE-1999-0255" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in ircd allows arbitrary command execution.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0256" published="1998-02-01" name="CVE-1999-0256" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in War FTP allows remote execution of commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/875" source="OSVDB">875</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jgaa" name="warftpd">
        <vers prev="1" num="1.66" />
      </prod>
      <prod vendor="microsoft" name="windows_95">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0257" published="1998-04-01" name="CVE-1999-0257" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Nestea variation of teardrop IP fragmentation denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.20.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0258" published="1998-02-13" name="CVE-1999-0258" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Bonk variation of teardrop IP fragmentation denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="windows_95">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0259" published="1997-05-23" name="CVE-1999-0259" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">cfingerd lists all users on a system via search.**@target.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="infodrom" name="cfingerd">
        <vers num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0260" published="1996-12-24" name="CVE-1999-0260" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The jj CGI program allows command execution via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="renaud_deraison" name="jj">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0261" published="1999-03-01" name="CVE-1999-0261" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Netmanager Chameleon SMTPd has several buffer overflows that cause a crash.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.insecure.org/sploits/netmanage.chameleon.overflows.html" source="MISC">http://www.insecure.org/sploits/netmanage.chameleon.overflows.html</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0262" published="1998-08-04" name="CVE-1999-0262" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Hylafax faxsurvey CGI script on Linux allows remote attackers to execute arbitrary commands via shell metacharacters in the query string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/1532" source="XF">http-cgi-faxsurvey(1532)</ref>
      <ref url="http://www.securityfocus.com/bid/2056" source="BID">2056</ref>
    </refs>
    <vuln_soft>
      <prod vendor="renaud_deraison" name="faxsurvey">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0263" published="1998-07-16" name="CVE-1999-0263" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Solaris SUNWadmap can be exploited to obtain root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/173" source="SUN">00173</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" edition="hw3" />
        <vers num="2.6" edition="hw3:x86" />
        <vers num="2.6" edition="hw5" />
        <vers num="2.6" edition="hw5:x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0264" published="1998-01-27" name="CVE-1999-0264" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">htmlscript CGI program allows remote read access to files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="miva" name="htmlscript">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0265" published="1997-01-01" name="CVE-1999-0265" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ICMP redirect messages may crash or lock up a host.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q154174" source="MSKB">Q154174</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microware" name="os-9">
        <vers num="" />
      </prod>
      <prod vendor="novell" name="netware">
        <vers num="3.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0266" published="1998-03-01" name="CVE-1999-0266" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The info2www CGI script allows remote file access or remote command execution.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1995" source="BID">1995</ref>
    </refs>
    <vuln_soft>
      <prod vendor="roar_smith" name="info2www">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0267" published="1997-09-23" name="CVE-1999-0267" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in NCSA HTTP daemon v1.3 allows remote command execution.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="ncsa" name="ncsa_httpd">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0268" published="1999-01-01" name="CVE-1999-0268" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">MetaInfo MetaWeb web server allows users to upload, execute, and read scripts.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/3969" source="OSVDB">3969</ref>
      <ref url="http://www.osvdb.org/110" source="OSVDB">110</ref>
    </refs>
    <vuln_soft>
      <prod vendor="metainfo" name="metaweb">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0269" published="1998-08-01" name="CVE-1999-0269" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Netscape Enterprise servers may list files through the PageServices query.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="netscape" name="enterprise_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0270" published="1998-04-03" name="CVE-1999-0270" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in pfdispaly.cgi program (sometimes referred to as "pfdisplay") for SGI's Performer API Search Tool (performer_tools) allows remote attackers to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/810" source="XF">sgi-pfdispaly(810)</ref>
      <ref url="http://www.securityfocus.com/bid/64" source="BID">64</ref>
      <ref url="http://www.osvdb.org/134" source="OSVDB">134</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/i-041.shtml" source="CIAC">I-041</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19980401-01-P" source="SGI">19980401-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0271" published="1998-01-15" name="CVE-1999-0271" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Progressive Networks Real Video server (pnserver) can be crashed remotely.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0272" published="1997-10-01" name="CVE-1999-0272" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service in Slmail v2.5 through the POP3 port.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="slmail" name="slmail">
        <vers num="3.0.2421" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0273" published="1998-01-01" name="CVE-1999-0273" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service through Solaris 2.5.1 telnet by sending ^D characters.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0274" published="1997-01-01" name="CVE-1999-0274" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service in Windows NT DNS servers through malicious packet which contains a response to a query that wasn't made.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0275" published="1997-06-10" name="CVE-1999-0275" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service in Windows NT DNS servers by flooding port 53 with too many characters.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0276" published="1999-01-01" name="CVE-1999-0276" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">mSQL v2.0.1 and below allows remote execution through a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="hughes" name="msql">
        <vers num="2.0." />
        <vers num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0277" published="1996-10-28" name="CVE-1999-0277" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The WorkMan program can be used to overwrite any file to get root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0278" published="1998-06-01" name="CVE-1999-0278" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms98-003.mspx" source="MS">MS98-003</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:913" source="OVAL" sig="1">oval:org.mitre.oval:def:913</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="3.0" />
        <vers num="4.0" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0279" published="1998-01-01" name="CVE-1999-0279" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Excite for Web Servers (EWS) allows remote command execution via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="excite" name="ews">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0280" published="1997-04-01" name="CVE-1999-0280" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Remote command execution in Microsoft Internet Explorer using .lnk and .url files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="3.0" />
        <vers num="3.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0281" published="1997-06-01" name="CVE-1999-0281" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service in IIS using long URLs.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="2.0" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="1999-0282" reject="1" published="1997-09-23" name="CVE-1999-0282" modified="2008-09-09">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-1584, CVE-1999-1586.  Reason: This candidate combined references from one issue with the description from another issue.  Notes: Users should consult CVE-1999-1584 and CVE-1999-1586 to obtain the appropriate name.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <vuln_types>
      <design />
    </vuln_types>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0283" published="1999-01-01" name="CVE-1999-0283" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Java Web Server would allow remote users to obtain the source code for CGI programs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88256790401004&amp;w=2" source="BUGTRAQ">19970716 Viewable .jhtml source with JavaWebServer</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0284" published="1998-01-01" name="CVE-1999-0284" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino_mail_server">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0285" published="1999-01-01" name="CVE-1999-0285" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0286" published="1999-01-01" name="CVE-1999-0286" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">In some NT web servers, appending a space at the end of a URL may allow attackers to read source code for active pages.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0287" published="1999-04-09" name="CVE-1999-0287" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Vulnerability in the Wguest CGI program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="webcom" name="cgi_guestbook">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0288" published="1998-08-01" name="CVE-1999-0288" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP frames to port 137 (NETBIOS Name Service), as demonstrated via a flood of random packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/1233" source="XF">nt-winsupd-fix(1233)</ref>
      <ref url="http://safenetworks.com/Windows/wins.html" source="MISC">http://safenetworks.com/Windows/wins.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0289" published="1999-12-12" name="CVE-1999-0289" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Apache web server for Win32 may provide access to restricted files when a . (dot) is appended to a requested URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0290" published="1998-02-21" name="CVE-1999-0290" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The WinGate telnet proxy allows remote attackers to cause a denial of service via a large number of connections to localhost.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="qbik" name="wingate">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0291" published="1999-02-01" name="CVE-1999-0291" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The WinGate proxy is installed without a password, which allows remote attackers to redirect connections without authentication.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="qbik" name="wingate">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0292" published="1997-04-01" name="CVE-1999-0292" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service through Winpopup using large user names.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0293" published="1998-01-01" name="CVE-1999-0293" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">AAA authentication on Cisco systems allows attackers to execute commands without authorization.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0294" published="1997-10-01" name="CVE-1999-0294" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">All records in a WINS database can be deleted through SNMP for a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="wins">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0295" published="1997-10-01" name="CVE-1999-0295" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Solaris sysdef command allows local users to read kernel memory, potentially leading to root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/157" source="SUN">00157</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.3" />
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":ppc" />
        <vers num="2.5.1" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0296" published="1998-02-01" name="CVE-1999-0296" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Solaris volrmmount program allows attackers to read any file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/162" source="SUN">00162</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0297" published="1996-12-12" name="CVE-1999-0297" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Vixie Cron library up to version 3.0 allows local users to obtain root access via a long environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="paul_vixie" name="vixie_cron">
        <vers num="3.0" />
      </prod>
      <prod vendor="bsdi" name="bsd_os">
        <vers num="2.1" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="2.1.0" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="2.0.4" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0298" published="1997-02-05" name="CVE-1999-0298" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">ypbind with -ypset and -ypsetme options activated in Linux Slackware and SunOS allows local and remote attackers to overwrite files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.nai.com/nai_labs/asp_set/advisory/06_ypbindsetme_adv.asp" source="NAI">19970205 Vulnerabilities in Ypbind when run with -ypset/-ypsetme</ref>
    </refs>
    <vuln_soft>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="4.1.3" />
        <vers num="4.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0299" published="1997-03-05" name="CVE-1999-0299" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in FreeBSD lpd through long DNS hostnames.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/6093" source="OSVDB">6093</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="6.2" edition="stable" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0300" published="1997-10-01" name="CVE-1999-0300" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">nis_cachemgr for Solaris NIS+ allows attackers to add malicious NIS+ servers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/155" source="SUN">00155</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.3" />
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0301" published="1997-08-01" name="CVE-1999-0301" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in SunOS/Solaris ps command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/149" source="SUN">00149</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.3" />
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0302" published="1998-09-01" name="CVE-1999-0302" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SunOS/Solaris FTP clients can be forced to execute arbitrary commands from a malicious FTP server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/176" source="SUN">00176</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.3" />
        <vers num="2.5" />
        <vers num="2.5.1" />
        <vers num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0303" published="1998-05-21" name="CVE-1999-0303" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in BNU UUCP daemon (uucpd) through long hostnames.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="digital" name="osf_1">
        <vers num="1.1" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.3" />
        <vers num="1.3.1" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="" edition=":x86" />
        <vers num="1.1" />
        <vers num="1.1.1a" />
        <vers num="1.1.2" />
        <vers num="1.1.3" edition="u1" />
        <vers num="1.1.4" edition="" />
        <vers num="1.1.4" edition=":jl" />
        <vers num="1.2" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="4.1.3" />
        <vers num="4.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0304" published="1998-02-01" name="CVE-1999-0304" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">mmap function in BSD allows local attackers in the kmem group to modify memory through devices.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="bsdi" name="bsd_os">
        <vers num="3.0" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="2.2" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="2.0.4" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0305" published="1998-02-01" name="CVE-1999-0305" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The system configuration control (sysctl) facility in BSD based operating systems OpenBSD 2.2 and earlier, and FreeBSD 2.2.5 and earlier, does not properly restrict source routed packets even when the (1) dosourceroute or (2) forwarding variables are set, which allows remote attackers to spoof TCP connections.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/736" source="XF">bsd-sourceroute(736)</ref>
      <ref url="http://www.osvdb.org/11502" source="OSVDB">11502</ref>
      <ref url="http://www.openbsd.org/advisories/sourceroute.txt" source="MISC">http://www.openbsd.org/advisories/sourceroute.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bsdi" name="bsd_os">
        <vers num="" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="2.2" />
        <vers num="2.2.5" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0306" published="1997-11-04" name="CVE-1999-0306" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">buffer overflow in HP xlock program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="hp" name="vvos">
        <vers num="10.24" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0307" published="2000-12-20" name="CVE-1999-0307" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in HP-UX cstm program allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.00" />
        <vers num="9.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0308" published="1996-10-01" name="CVE-1999-0308" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">HP-UX gwind program allows users to modify arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9410-018" source="HP">HPSBUX9410-018</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="8" />
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0309" published="1997-02-01" name="CVE-1999-0309" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">HP-UX vgdisplay program gives root access to local users.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9702-056" source="HP">HPSBUX9702-056</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.00" />
        <vers num="10.01" />
        <vers num="10.10" />
        <vers num="10.20" />
        <vers num="10.24" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0310" published="1998-09-01" name="CVE-1999-0310" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SSH 1.2.25 on HP-UX allows access to new user accounts.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="ssh" name="ssh">
        <vers num="1.2.25" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0311" published="1996-11-01" name="CVE-1999-0311" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">fpkg2swpk in HP-UX allows local users to gain root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9612-042" source="HP">HPSBUX9612-042</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0312" published="1993-01-13" name="CVE-1999-0312" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">HP ypbind allows attackers with root privileges to modify NIS data.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0313" published="1998-07-01" name="CVE-1999-0313" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">disk_bandwidth on SGI IRIX 6.4 S2MP for Origin/Onyx2 allows local users to gain root access using relative pathnames.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/1441" source="XF">sgi-disk-bandwidth(1441)</ref>
      <ref url="http://www.securityfocus.com/bid/214" source="BID">214</ref>
      <ref url="http://www.securityfocus.com/bid/213/exploit" source="MISC">http://www.securityfocus.com/bid/213/exploit</ref>
      <ref url="http://www.osvdb.org/936" source="OSVDB">936</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19980701-01-P" source="SGI">19980701-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.4" edition="" />
        <vers num="6.4" edition=":s2mp" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0314" published="1998-07-01" name="CVE-1999-0314" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">ioconfig on SGI IRIX 6.4 S2MP for Origin/Onyx2 allows local users to gain root access using relative pathnames.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/1199" source="XF">sgi-ioconfig(1199)</ref>
      <ref url="http://www.securityfocus.com/bid/213/exploit" source="MISC">http://www.securityfocus.com/bid/213/exploit</ref>
      <ref url="http://www.securityfocus.com/bid/213" source="BID">213</ref>
      <ref url="http://www.osvdb.org/6788" source="OSVDB">6788</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19980701-01-P" source="SGI">19980701-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0315" published="1997-04-01" name="CVE-1999-0315" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Solaris fdformat command gives root access to local users.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/138" source="SUN">00138</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.3" />
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0316" published="1995-12-01" name="CVE-1999-0316" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Linux splitvt command gives root access to local users.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sam_lantinga" name="splitvt">
        <vers prev="1" num="1.6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0317" published="1999-11-25" name="CVE-1999-0317" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Linux su command gives root access to local users.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.20.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0318" published="1997-03-01" name="CVE-1999-0318" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in xmcd 2.0p12 allows local users to gain access through an environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="4" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="6.0" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.5.1" />
        <vers num="2.6" />
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0319" published="1996-10-01" name="CVE-1999-0319" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in xmcd 2.1 allows local users to gain access through a user resource setting.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0320" published="1998-03-01" name="CVE-1999-0320" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">SunOS rpc.cmsd allows attackers to obtain root access by overwriting arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.3" />
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":x86" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="4.1.3u1" />
        <vers num="4.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0321" published="1998-12-01" name="CVE-1999-0321" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Solaris kcms_configure command allows local users to gain root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0322" published="1997-10-29" name="CVE-1999-0322" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The open() function in FreeBSD allows local attackers to write to arbitrary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/6092" source="OSVDB">6092</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="2.1.0" />
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0323" published="1998-02-20" name="CVE-1999-0323" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">FreeBSD mmap function allows users to modify append-only or immutable files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA1998-003.txt.asc" source="NETBSD">1998-003</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bsdi" name="bsd_os">
        <vers num="3.0" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="2.2" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="2.0.4" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0324" published="1996-09-01" name="CVE-1999-0324" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">ppl program in HP-UX allows local users to create root files through symlinks.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9702-053" source="HP">HPSBUX9702-053</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.00" />
        <vers num="10.01" />
        <vers num="10.10" />
        <vers num="10.20" />
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0325" published="1995-12-01" name="CVE-1999-0325" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">vhe_u_mnt program in HP-UX allows local users to create root files through symlinks.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9406-013" source="HP">HPSBUX9406-013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="8" />
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0326" published="1997-10-01" name="CVE-1999-0326" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Vulnerability in HP-UX mediainit program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9710-071" source="HP">HPSBUX9710-071</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.01" />
        <vers num="10.10" />
        <vers num="10.20" />
        <vers num="10.30" />
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0327" published="1997-11-01" name="CVE-1999-0327" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">SGI syserr program allows local users to corrupt files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19971103-01-PX" source="SGI">19971103-01-PX</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="5.3" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0328" published="1997-11-01" name="CVE-1999-0328" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">SGI permissions program allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19971103-01-PX" source="SGI">19971103-01-PX</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="5.0.1" />
        <vers num="5.1" />
        <vers num="5.1.1" />
        <vers num="5.2" />
        <vers num="5.3" edition="" />
        <vers num="5.3" edition=":xfs" />
        <vers num="6.0" />
        <vers num="6.0.1" edition="" />
        <vers num="6.0.1" edition=":xfs" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0329" published="1998-06-01" name="CVE-1999-0329" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">SGI mediad program allows local users to gain root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19980602-01-PX" source="SGI">19980602-01-PX</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="5.1" />
        <vers num="5.1.1" />
        <vers num="5.2" />
        <vers num="5.3" edition="" />
        <vers num="5.3" edition=":xfs" />
        <vers num="6.0" />
        <vers num="6.0.1" edition="" />
        <vers num="6.0.1" edition=":xfs" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0330" published="1998-03-01" name="CVE-1999-0330" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Linux bdash game has a buffer overflow that allows local users to gain root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.20.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0331" published="1998-01-01" name="CVE-1999-0331" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Internet Explorer 4.0(1).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="3.0.2" />
        <vers num="4.0" />
        <vers num="4.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0332" published="1998-12-01" name="CVE-1999-0332" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in NetMeeting allows denial of service and remote command execution.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q184346" source="MSKB">Q184346</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="netmeeting">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0333" published="1998-08-01" name="CVE-1999-0333" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">HP OpenView Omniback allows remote execution of commands as root via spoofing, and local users can gain root access via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0334" published="1993-12-16" name="CVE-1999-0334" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">In Solaris 2.2 and 2.3, when fsck fails on startup, it allows a local user with physical access to obtain root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="" edition=":x86" />
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0335" published="1996-08-01" name="CVE-1999-0335" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">DEPRECATED.  This entry has been deprecated.  It is a duplicate of CVE-1999-0032.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="bsdi" name="bsd_os">
        <vers num="2.1" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.20.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0336" published="1996-11-01" name="CVE-1999-0336" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in mstm in HP-UX allows local users to gain root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0337" published="1994-06-03" name="CVE-1999-0337" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">AIX batch queue (bsh) allows local and remote users to gain additional privileges when network printing is enabled.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="1.2.1" />
        <vers num="1.3" />
        <vers num="2.2.1" />
        <vers num="3.1" />
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0338" published="1994-02-24" name="CVE-1999-0338" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">AIX Licensed Program Product performance tools allow local users to gain root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="3.2.4" />
        <vers num="3.2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0339" published="1998-08-01" name="CVE-1999-0339" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the libauth library in Solaris allows local users to gain additional privileges, possibly root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":ppc" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0340" published="1997-12-01" name="CVE-1999-0340" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Linux Slackware crond program allows local users to gain root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0341" published="1998-01-01" name="CVE-1999-0341" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the Linux mail program "deliver" allows local users to gain root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="1.3.1" />
      </prod>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0342" published="1998-12-01" name="CVE-1999-0342" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">Linux PAM modules allow local users to gain root access using temporary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="pam" name="pam">
        <vers prev="1" num="0.64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0343" published="1998-10-02" name="CVE-1999-0343" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">A malicious Palace server can force a client to execute arbitrary programs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="palace" name="palace_client">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0344" published="1998-08-01" name="CVE-1999-0344" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">NT users can gain debug-level access on a system process using the Sechole exploit.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q190288" source="MSKB">Q190288</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms98-009.mspx" source="MS">MS98-009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="3.5.1" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0345" published="1997-01-01" name="CVE-1999-0345" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Jolt ICMP attack causes a denial of service in Windows 95 and Windows NT systems.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="ibm" name="sng">
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.1.5.1" />
        <vers num="1.2" />
        <vers num="2.0" />
        <vers num="2.0.5" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="3.2" />
        <vers num="4.1" />
        <vers num="4.2" />
      </prod>
      <prod vendor="sco" name="internet_faststart">
        <vers num="1.0" />
        <vers num="1.1" />
      </prod>
      <prod vendor="sco" name="open_desktop">
        <vers num="3" />
      </prod>
      <prod vendor="sco" name="openserver">
        <vers num="5" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0346" published="1997-10-16" name="CVE-1999-0346" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CGI PHP mlog script allows an attacker to read any file on the target server.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/713" source="BID">713</ref>
      <ref url="http://www.osvdb.org/3397" source="OSVDB">3397</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php_fi">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0347" published="1999-01-26" name="CVE-1999-0347" modified="2005-11-02" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Internet Explorer 4.01 allows remote attackers to read local files and spoof web pages via a "%01" character in an "about:" Javascript URL, which causes Internet Explorer to use the domain specified after the character.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91756771207719&amp;w=2" source="NTBUGTRAQ">19990126 Javascript ecurity bug in Internet Explorer</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91745430007021&amp;w=2" source="BUGTRAQ">19990126 Javascript ecurity bug in Internet Explorer</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0348" published="1999-01-27" name="CVE-1999-0348" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IIS ASP caching problem releases sensitive information when two virtual servers share the same physical directory.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q197003" source="MSKB">Q197003</ref>
      <ref url="http://www.osvdb.org/930" source="OSVDB">930</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0349" published="1999-01-27" name="CVE-1999-0349" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">A buffer overflow in the FTP list (ls) command in IIS allows remote attackers to conduct a denial of service and, in some cases, execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.eeye.com/html/Research/Advisories/IIS%20Remote%20FTP%20Exploit/DoS%20Attack.html" source="EEYE">IIS Remote FTP Exploit/DoS Attack</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q188348" source="MSKB">Q188348</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-003.mspx" source="MS">MS99-003</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="3.0" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0350" published="1999-02-08" name="CVE-1999-0350" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">Race condition in the db_loader program in ClearCase gives local users root access by setting SUID bits.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="rational_software" name="clearcase">
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0351" published="1999-02-01" name="CVE-1999-0351" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">FTP PASV "Pizza Thief" denial of service and unauthorized data access.  Attackers can steal data by connecting to a port that was intended for use by a client.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/3389" source="XF">pasv-pizza-thief-dos(3389)</ref>
      <ref url="http://attrition.org/security/advisory/misc/infowar/iw_sec_01.txt" source="MISC">http://attrition.org/security/advisory/misc/infowar/iw_sec_01.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ftp" name="ftp_pasv">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0352" published="1999-01-25" name="CVE-1999-0352" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">ControlIT 4.5 and earlier (aka Remotely Possible) has weak password encryption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0353" published="1999-02-10" name="CVE-1999-0353" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">rpc.pcnfsd in HP gives remote root access by changing the permissions on the main printer spool directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9902-091" source="HP">HPSBUX9902-091</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/j-026.shtml" source="CIAC">J-026</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.01" />
        <vers num="10.10" />
        <vers num="10.20" />
        <vers num="11.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0354" published="1999-11-01" name="CVE-1999-0354" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Internet Explorer 4.x or 5.x with Word 97 allows arbitrary execution of Visual Basic programs to the IE client through the Word 97 template, which doesn't warn the user that the template contains executable content.  Also applies to Outlook when the client views a malicious email message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-002.asp" source="MS">MS99-002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
      <prod vendor="microsoft" name="word">
        <vers num="97" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0355" published="1999-01-01" name="CVE-1999-0355" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Local or remote users can force ControlIT 4.5 to reboot or force a user to log out, resulting in a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="ca" name="controlit">
        <vers num="4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0356" published="1999-01-25" name="CVE-1999-0356" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">ControlIT v4.5 and earlier uses weak encryption to store usernames and passwords in an address book.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0357" published="1999-01-25" name="CVE-1999-0357" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Windows 98 and other operating systems allows remote attackers to cause a denial of service via crafted "oshare" packets, possibly involving invalid fragmentation offsets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0358" published="1999-02-01" name="CVE-1999-0358" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Digital Unix 4.0 has a buffer overflow in the inc program of the mh package.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/12121" source="BUGTRAQ">19990125 Digital Unix 4.0 exploitable buffer overflows</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/j-027.shtml" source="CIAC">J-027</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digital" name="unix">
        <vers num="4.0" />
        <vers num="4.0a" />
        <vers num="4.0b" />
        <vers num="4.0c" />
        <vers num="4.0d" />
        <vers num="4.0e" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0359" published="2001-03-12" name="CVE-1999-0359" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">ptylogin in Unix systems allows users to perform a denial of service by locking out modems, dial out with that modem, or obtain passwords.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="marc_schaefer" name="ptylogin">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0360" published="1999-01-30" name="CVE-1999-0360" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">MS Site Server 2.0 with IIS 4 can allow users to upload content, including ASP, to the target web site, thus allowing them to execute commands remotely.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91763097004101&amp;w=2" source="BUGTRAQ" adv="1">19990130 Security Advisory for Internet Information Server 4 with Site</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="site_server">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0361" published="1999-01-01" name="CVE-1999-0361" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">NetWare version of LaserFiche stores usernames and passwords unencrypted, and allows administrative changes without logging.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0362" published="1999-02-02" name="CVE-1999-0362" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WS_FTP server remote denial of service through cwd command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/217" source="BID">217</ref>
      <ref url="http://www.eeye.com/html/Research/Advisories/AD02021999.html" source="EEYE">AD02021999</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="ws_ftp_server">
        <vers num="1.0.1eval" />
        <vers num="1.0.2eval" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0363" published="1999-02-02" name="CVE-1999-0363" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">SuSE 5.2 PLP lpc program has a buffer overflow that leads to root compromise.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/328" source="BID">328</ref>
    </refs>
    <vuln_soft>
      <prod vendor="plp" name="line_printer_control">
        <vers num="" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0364" published="1999-01-01" name="CVE-1999-0364" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Microsoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to data.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91816470220259&amp;w=2" source="BUGTRAQ">19990204 Microsoft Access 97 Stores Database Password as Plaintext</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fms_inc." name="total_vb_sourcebook">
        <vers num="6.0" />
      </prod>
      <prod vendor="microsoft" name="access">
        <vers num="97" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0365" published="1999-02-04" name="CVE-1999-0365" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The metamail package allows remote command execution using shell metacharacters that are not quoted in a mailcap entry.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="metainfo" name="metaip">
        <vers num="3.1" />
      </prod>
      <prod vendor="metainfo" name="sendmail">
        <vers num="2.0" />
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0366" published="1999-02-08" name="CVE-1999-0366" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q214840" source="MSKB">Q214840</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-004.mspx" source="MS">MS99-004</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="sp4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0367" published="1999-02-09" name="CVE-1999-0367" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">NetBSD netstat command allows local users to access kernel memory.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/7571" source="OSVDB">7571</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netbsd" name="netbsd">
        <vers num="2.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0368" published="1999-02-09" name="CVE-1999-0368" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="proftpd_project" name="proftpd">
        <vers num="1.2_pre1" />
      </prod>
      <prod vendor="washington_university" name="wu-ftpd">
        <vers num="2.4.2_beta18" />
        <vers num="2.4.2_beta18_vr9" />
      </prod>
      <prod vendor="caldera" name="openlinux">
        <vers num="1.3" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.0" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="5.0" />
        <vers num="5.1" />
      </prod>
      <prod vendor="sco" name="openserver">
        <vers num="5.0" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
      </prod>
      <prod vendor="sco" name="unixware">
        <vers num="7.0" />
        <vers num="7.0.1" />
      </prod>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="3.4" />
        <vers num="3.5" />
        <vers num="3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0369" published="1997-02-01" name="CVE-1999-0369" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The Sun sdtcm_convert calendar utility for OpenWindows has a buffer overflow which can gain root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/183" source="SUN">00183</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="" edition=":x86" />
        <vers num="1.1" />
        <vers num="1.1.1a" />
        <vers num="1.1.2" />
        <vers num="1.1.3" edition="u1" />
        <vers num="1.1.4" edition="" />
        <vers num="1.1.4" edition=":jl" />
        <vers num="1.2" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0370" published="1999-02-10" name="CVE-1999-0370" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">In Sun Solaris and SunOS, man and catman contain vulnerabilities that allow overwriting arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/165" source="BID">165</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0371" published="1999-02-11" name="CVE-1999-0371" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">Lynx allows a local user to overwrite sensitive files through /tmp symlinks.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="university_of_kansas" name="lynx">
        <vers prev="1" num="2.7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0372" published="1999-02-12" name="CVE-1999-0372" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q217004" source="MSKB">Q217004</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-005.mspx" source="MS">MS99-005</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="backoffice">
        <vers num="4.0" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0373" published="1999-02-01" name="CVE-1999-0373" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the "Super" utility in Debian GNU/Linux, and other operating systems, allows local users to execute commands as root.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0374" published="1999-02-16" name="CVE-1999-0374" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Debian GNU/Linux cfengine package is susceptible to a symlink attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0375" published="1999-02-16" name="CVE-1999-0375" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in webd in Network Flight Recorder (NFR) 2.0.2-Research allows remote attackers to execute commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="network_flight_recorder" name="network_flight_recorder">
        <vers prev="1" num="2.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0376" published="1999-02-20" name="CVE-1999-0376" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-006.mspx" source="MS">MS99-006</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="3.5.1" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0377" published="1999-02-22" name="CVE-1999-0377" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Process table attack in Unix systems allows a remote attacker to perform a denial of service by filling a machine's process tables through multiple connections to network services.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="unix" name="unix">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0378" published="1999-02-22" name="CVE-1999-0378" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">InterScan VirusWall for Solaris doesn't scan files for viruses when a single HTTP request includes two GET commands.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/6167" source="OSVDB">6167</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="interscan_viruswall">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0379" published="1999-02-22" name="CVE-1999-0379" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Microsoft Taskpads allows remote web sites to execute commands on the visiting user's machine via certain methods that are marked as Safe for Scripting.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/498" source="BID">498</ref>
      <ref url="http://www.osvdb.org/1019" source="OSVDB">1019</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-007.mspx" source="MS">MS99-007</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="backoffice_resource_kit">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0380" published="1999-02-25" name="CVE-1999-0380" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">SLMail 3.1 and 3.2 allows local users to access any file in the NTFS file system when the Remote Administration Service (RAS) is enabled by setting a user's Finger File to point to the target file, then running finger on the user.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5392.php" source="XF">slmail-ras-ntfs-bypass(5392)</ref>
      <ref url="http://www.securityfocus.com/bid/497" source="BID">497</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92110501504997&amp;w=2" source="NTBUGTRAQ">SLmail 3.2 Build 3113 (Web Administration Security Fix)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91999015212415&amp;w=2" source="NTBUGTRAQ">199902225 ALERT: SLMail 3.2 (and 3.1) with the Remote Administration Service</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91996412724720&amp;w=2" source="BUGTRAQ">19990225 ALERT: SLMail 3.2 (and 3.1) with the Remote Administration Service</ref>
    </refs>
    <vuln_soft>
      <prod vendor="seattle_lab_software" name="slmail">
        <vers num="3.0.2421" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0381" published="1999-02-26" name="CVE-1999-0381" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">super 3.11.6 and other versions have a buffer overflow in the syslog utility which allows a local user to gain root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/342" source="BID" adv="1">342</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.3.96.990225011801.12757A-100000@eleet" source="BUGTRAQ">19990225 SUPER buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.0" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.20.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0382" published="1999-03-12" name="CVE-1999-0382" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The screen saver in Windows NT does not verify that its security context has been changed properly, allowing attackers to run programs with elevated privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-008.mspx" source="MS">MS99-008</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="3.5.1" edition="sp1" />
        <vers num="3.5.1" edition="sp2" />
        <vers num="3.5.1" edition="sp3" />
        <vers num="3.5.1" edition="sp4" />
        <vers num="3.5.1" edition="sp5" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0383" published="1999-02-02" name="CVE-1999-0383" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">ACC Tigris allows public access without a login.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/183" source="BID">183</ref>
      <ref url="http://www.osvdb.org/267" source="OSVDB">267</ref>
    </refs>
    <vuln_soft>
      <prod vendor="acc" name="tigris">
        <vers num="10.5.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0384" published="1999-01-01" name="CVE-1999-0384" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's clipboard when the user accesses documents with ActiveX content.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-001.mspx" source="MS">MS99-001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="98" edition="" />
        <vers num="98" edition=":mac" />
      </prod>
      <prod vendor="microsoft" name="outlook">
        <vers num="98" />
      </prod>
      <prod vendor="microsoft" name="project">
        <vers num="98" />
      </prod>
      <prod vendor="microsoft" name="visual_basic">
        <vers num="5.0" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0385" published="1998-12-01" name="CVE-1999-0385" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-009.mspx" source="MS">MS99-009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0386" published="1999-03-01" name="CVE-1999-0386" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Personal Web Server and FrontPage Personal Web Server in some Windows systems allows a remote attacker to read files on the server by using a nonstandard URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/111" source="OSVDB">111</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-010.mspx" source="MS">MS99-010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="frontpage">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="personal_web_server">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0387" published="1999-11-29" name="CVE-1999-0387" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">A legacy credential caching mechanism used in Windows 95 and Windows 98 systems allows attackers to read plaintext network passwords.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/829" source="BID">829</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-052.asp" source="MS">MS99-052</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q168115" source="MSKB">Q168115</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_95">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0388" published="1999-01-01" name="CVE-1999-0388" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">DataLynx suGuard trusts the PATH environment variable to execute the ps command, allowing local users to execute commands as root.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/3186" source="OSVDB">3186</ref>
    </refs>
    <vuln_soft>
      <prod vendor="datalynx" name="suguard">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0389" published="1999-01-03" name="CVE-1999-0389" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the bootp server in the Debian Linux netstd package.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/324" source="BID" adv="1">324</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0390" published="1999-01-04" name="CVE-1999-0390" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Dosemu Slang library in Linux.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/187" source="BID">187</ref>
      <ref url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-006.1.txt" source="CALDERA">CSSA-1999-006.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" edition="" />
        <vers num="5.2" edition=":i386" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="5.0" />
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0391" published="1999-01-05" name="CVE-1999-0391" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and impersonate a user.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="terminal_server">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="3.5.1" edition="sp1" />
        <vers num="3.5.1" edition="sp2" />
        <vers num="3.5.1" edition="sp3" />
        <vers num="3.5.1" edition="sp4" />
        <vers num="3.5.1" edition="sp5" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0392" published="1999-01-10" name="CVE-1999-0392" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Thomas Boutell's cgic library version up to 1.05.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="thomas_boutell" name="cgic_library">
        <vers prev="1" num="1.05" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0393" published="1999-01-01" name="CVE-1999-0393" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Remote attackers can cause a denial of service in Sendmail 8.8.x and 8.9.2 by sending messages with a large number of headers.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91694391227372&amp;w=2" source="BUGTRAQ">19990121 Sendmail 8.8.x/8.9.x bugware</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eric_allman" name="sendmail">
        <vers num="8.8" />
        <vers num="8.9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0394" published="1999-01-01" name="CVE-1999-0394" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">DPEC Online Courseware allows an attacker to change another user's password without knowing the original password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0395" published="1999-01-01" name="CVE-1999-0395" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">A race condition in the BackWeb Polite Agent Protocol allows an attacker to spoof a BackWeb server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/alerts/advise17.php" source="ISS" adv="1">19990118 Vulnerability in the BackWeb Polite Agent Protocol</ref>
    </refs>
    <vuln_soft>
      <prod vendor="backweb_technologies" name="backweb_polite_agent_protocol">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0396" published="1999-02-17" name="CVE-1999-0396" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">A race condition between the select() and accept() calls in NetBSD TCP servers allows remote attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="netbsd" name="netbsd">
        <vers num="2.0.4" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0397" published="1999-01-01" name="CVE-1999-0397" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The demo version of the Quakenbush NT Password Appraiser sends passwords across the network in plaintext.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0398" published="1999-01-01" name="CVE-1999-0398" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">In some instances of SSH 1.2.27 and 2.0.11 on Linux systems, SSH will allow users with expired accounts to login.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="ssh" name="ssh">
        <vers num="1.2.27" />
      </prod>
      <prod vendor="ssh" name="ssh2">
        <vers num="2.0.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0399" published="1999-01-01" name="CVE-1999-0399" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The DCC server command in the Mirc 5.5 client doesn't filter characters from file names properly, allowing remote attackers to place a malicious file in a different location, possibly allowing the attacker to execute commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="khaled_mardam-bey" name="mirc">
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0400" published="1999-01-26" name="CVE-1999-0400" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Denial of service in Linux 2.2.0 running the ldd command on a core file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/344" source="BID" adv="1">344</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0401" published="1999-01-01" name="CVE-1999-0401" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">A race condition in Linux 2.2.1 allows local users to read arbitrary memory from /proc files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0402" published="1999-01-02" name="CVE-1999-0402" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">wget 1.5.3 follows symlinks to change permissions of the target file instead of the symlink itself.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="gnu" name="wget">
        <vers num="1.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0403" published="1999-02-01" name="CVE-1999-0403" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">A bug in Cyrix CPUs on Linux allows local users to perform a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91821080015725&amp;w=2" source="BUGTRAQ">19990204 Cyrix bug: freeze in hell, badboy</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cyrix" name="linux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0404" published="1999-02-14" name="CVE-1999-0404" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the Mail-Max SMTP server for Windows systems allows remote command execution.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="smartmax_software" name="mailmax">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0405" published="1999-02-18" name="CVE-1999-0405" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">A buffer overflow in lsof allows local users to obtain root privilege.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/3163" source="OSVDB">3163</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.0" />
        <vers num="2.0.5" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="2.0" />
        <vers num="2.0.5" />
        <vers num="2.1.0" />
        <vers num="2.1.5" />
        <vers num="2.1.6" />
        <vers num="2.1.7.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.8" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="5.2" edition="" />
        <vers num="5.2" edition=":i386" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="4.2" />
        <vers num="4.3" />
        <vers num="4.4" />
        <vers num="4.4.1" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="5.3" />
        <vers num="6.0" />
        <vers num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0406" published="1999-02-19" name="CVE-1999-0406" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Digital Unix Networker program nsralist has a buffer overflow which allows local users to obtain root privilege.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="digital" name="unix">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0407" published="1999-02-09" name="CVE-1999-0407" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92000623021036&amp;w=2" source="BUGTRAQ">19990209 Re: IIS4 allows proxied password attacks over NetBIOS</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91983486431506&amp;w=2" source="BUGTRAQ">19990209 ALERT: IIS4 allows proxied password attacks over NetBIOS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0408" published="1999-02-25" name="CVE-1999-0408" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Files created from interactive shell sessions in Cobalt RaQ microservers (e.g. .bash_history) are world readable, and thus are accessible from the web server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/337" source="BID">337</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="cobalt_raq">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0409" published="1999-03-04" name="CVE-1999-0409" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in gnuplot in Linux version 3.5 allows local users to obtain root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/319" source="BID">319</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="suse_linux">
        <vers num="3.5" />
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0410" published="1999-03-05" name="CVE-1999-0410" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The cancel command in Solaris 2.6 (i386) has a buffer overflow that allows local users to obtain root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/293" source="BID">293</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0411" published="1999-03-07" name="CVE-1999-0411" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Several startup scripts in SCO OpenServer Enterprise System v 5.0.4p, including S84rpcinit, S95nis, S85tcp, and S89nfs, are vulnerable to a symlink attack, allowing a local user to gain root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sco" name="openserver">
        <vers num="3.0" />
        <vers num="5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0412" published="1999-02-19" name="CVE-1999-0412" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/501" source="BID">501</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0413" published="1999-03-01" name="CVE-1999-0413" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">A buffer overflow in the SGI X server allows local users to gain root access through the X server font path.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19990301-01-PX" source="SGI">19990301-01-PX</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="5.3" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
        <vers num="6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0414" published="1999-03-01" name="CVE-1999-0414" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">In Linux before version 2.0.36, remote attackers can spoof a TCP connection and pass data to the application layer before fully establishing the connection.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.0.30" />
        <vers num="2.0.35" />
        <vers num="2.0.36" />
        <vers num="2.0.37" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0415" published="1999-03-11" name="CVE-1999-0415" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The HTTP server in Cisco 7xx series routers 3.2 through 4.2 is enabled by default, which allows remote attackers to change the router's configuration.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/770/7xxconn-pub.shtml" source="CISCO">19990311 Cisco 7xx TCP and HTTP Vulnerabilities</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/j-034.shtml" source="CIAC">J-034</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="cisco_7xx_routers">
        <vers num="3.2" />
        <vers prev="1" num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0416" published="1999-03-11" name="CVE-1999-0416" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Vulnerability in Cisco 7xx series routers allows a remote attacker to cause a system reload via a TCP connection to the router's TELNET port.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/770/7xxconn-pub.shtml" source="CISCO">19990311 Cisco 7xx TCP and HTTP Vulnerabilities</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/j-034.shtml" source="CIAC">J-034</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="cisco_7xx_routers">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0417" published="1999-03-09" name="CVE-1999-0417" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">64 bit Solaris 7 procfs allows local users to perform a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/448" source="BID">448</ref>
      <ref url="http://www.osvdb.org/1001" source="OSVDB">1001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0418" published="1999-03-08" name="CVE-1999-0418" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Denial of service in SMTP applications such as Sendmail, when a remote attacker (e.g. spammer) uses many "RCPT TO" commands in the same connection.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92100018214316&amp;w=2" source="BUGTRAQ">19990308 SMTP server account probing</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0419" published="1999-03-01" name="CVE-1999-0419" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">When the Microsoft SMTP service attempts to send a message to a server and receives a 4xx error code, it quickly and repeatedly attempts to redeliver the message, causing a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0420" published="1999-03-17" name="CVE-1999-0420" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">umapfs allows local users to gain root privileges by changing their uid through a malicious mount_umap program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="netbsd" name="umapfs">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0421" published="1999-03-17" name="CVE-1999-0421" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">During a reboot after an installation of Linux Slackware 3.6, a remote attacker can obtain root access by logging in to the root account without a password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/338" source="BID" patch="1" adv="1">338</ref>
      <ref url="http://www.osvdb.org/981" source="OSVDB">981</ref>
    </refs>
    <vuln_soft>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0422" published="1999-03-17" name="CVE-1999-0422" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">In some cases, NetBSD 1.3.3 mount allows local users to execute programs in some file systems that have the "noexec" flag set.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0423" published="1994-06-01" name="CVE-1999-0423" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Vulnerability in hpterm on HP-UX 10.20 allows local users to gain additional privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-093" source="HP">HPSBUX9903-093</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0424" published="1999-03-18" name="CVE-1999-0424" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">talkback in Netscape 4.5 allows a local user to overwrite arbitrary files of another user whose Netscape crashes.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="netscape" name="communicator">
        <vers num="4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0425" published="1999-03-18" name="CVE-1999-0425" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">talkback in Netscape 4.5 allows a local user to kill an arbitrary process of another user whose Netscape crashes.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="netscape" name="communicator">
        <vers num="4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0426" published="1999-03-01" name="CVE-1999-0426" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="suse" name="suse_linux">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0427" published="2000-05-01" name="CVE-1999-0427" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Eudora 4.1 allows remote attackers to perform a denial of service by sending attachments with long file names.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="qualcomm" name="eudora">
        <vers num="4.2" />
        <vers num="4.3" />
      </prod>
      <prod vendor="qualcomm" name="eudora_light">
        <vers num="3.0" />
      </prod>
      <prod vendor="qualcomm" name="eudora_pro">
        <vers num="1.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0428" published="1999-03-22" name="CVE-1999-0428" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">OpenSSL and SSLeay allow remote attackers to reuse SSL sessions and bypass access controls.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/3936" source="OSVDB">3936</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openssl" name="openssl">
        <vers num="" />
      </prod>
      <prod vendor="ssleay" name="ssleay">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0429" published="1999-03-01" name="CVE-1999-0429" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Lotus Notes 4.5 client may send a copy of encrypted mail in the clear across the network if the user does not set the "Encrypt Saved Mail" preference.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92249282302994&amp;w=2" source="BUGTRAQ">19990326 Re: Lotus Notes security advisory</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92246997917866&amp;w=2" source="BUGTRAQ">19990326 Lotus Notes Encryption Bug</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92241547418689&amp;w=2" source="BUGTRAQ">19990324 Re: LNotes encryption</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92221437025743&amp;w=2" source="BUGTRAQ">19990323</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_notes">
        <vers num="4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0430" published="1999-03-01" name="CVE-1999-0430" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco Catalyst LAN switches running Catalyst 5000 supervisor software allows remote attackers to perform a denial of service by forcing the supervisor module to reload.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/1103" source="OSVDB">1103</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="catalyst_12xx_supervisor_software">
        <vers num="4.29" />
      </prod>
      <prod vendor="cisco" name="catalyst_29xx_supervisor_software">
        <vers num="1.0" />
        <vers num="2.1.5" />
        <vers num="2.1.501" />
        <vers num="2.1.502" />
      </prod>
      <prod vendor="cisco" name="catalyst_5xxx_supervisor_software">
        <vers num="1.0" />
        <vers num="2.1.5" />
        <vers num="2.1.501" />
        <vers num="2.1.502" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0431" published="1999-03-01" name="CVE-1999-0431" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Linux 2.2.3 and earlier allow a remote attacker to perform an IP fragmentation attack, causing a denial of service.</descript>
    </desc>
    <sols>
      <sol source="nvd">This problem was fixed in Linux kernel 2.2.4 and later releases.</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.1.89" />
        <vers num="2.2.0" />
        <vers num="2.2.10" />
        <vers num="2.2.12" />
        <vers num="2.2.13" />
        <vers num="2.2.14" />
        <vers num="2.2.15" edition="pre16" />
        <vers num="2.2.15_pre20" />
        <vers num="2.2.16" edition="pre6" />
        <vers prev="1" num="2.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0432" published="1999-03-01" name="CVE-1999-0432" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">ftp on HP-UX 11.00 allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-094" source="HP">HPSBUX9903-094</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0433" published="1999-03-21" name="CVE-1999-0433" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">XFree86 startx command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="xfree86_project" name="x11r6">
        <vers num="3.3.3" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.3.2" />
        <vers num="1.3.3" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="5.1" />
        <vers num="5.2" edition="" />
        <vers num="5.2" edition=":i386" />
      </prod>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="3.5" />
        <vers num="3.6" />
        <vers num="4.0" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="6.0" />
        <vers num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0434" published="1999-03-30" name="CVE-1999-0434" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">XFree86 xfs command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/359" source="BID" patch="1" adv="1">359</ref>
    </refs>
    <vuln_soft>
      <prod vendor="caldera" name="openlinux">
        <vers num="1.2" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.0" edition="r5" />
        <vers num="2.1" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.3.3" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="5.1" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0435" published="1999-03-01" name="CVE-1999-0435" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">MC/ServiceGuard and MC/LockManager in HP-UX allows local users to gain privileges through SAM.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.00" />
        <vers num="10.01" />
        <vers num="10.20" />
        <vers num="11.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0436" published="1999-03-01" name="CVE-1999-0436" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Domain Enterprise Server Management System (DESMS) in HP-UX allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-095" source="HP">HPSBUX9903-095</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="desms">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.20" />
        <vers num="11.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0437" published="1999-03-01" name="CVE-1999-0437" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Remote attackers can perform a denial of service in WebRamp systems by sending a malicious string to the HTTP port.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="ramp_networks" name="webramp">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0438" published="1999-03-01" name="CVE-1999-0438" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Remote attackers can perform a denial of service in WebRamp systems by sending a malicious UDP packet to port 5353, changing its IP address.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="ramp_networks" name="webramp_200i">
        <vers num="1.0" />
      </prod>
      <prod vendor="ramp_networks" name="webramp_m3">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0439" published="1999-04-05" name="CVE-1999-0439" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in procmail before version 3.12 allows remote or local attackers to execute commands via expansions in the procmailrc configuration file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="procmail" name="procmail">
        <vers prev="1" num="3.12" />
      </prod>
      <prod vendor="caldera" name="openlinux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0440" published="1999-03-01" name="CVE-1999-0440" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The byte code verifier component of the Java Virtual Machine (JVM) allows remote execution through malicious web pages.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://java.sun.com/pr/1999/03/pr990329-01.html" source="CONFIRM">http://java.sun.com/pr/1999/03/pr990329-01.html</ref>
      <ref url="http://www.securityfocus.com/bid/1939" source="BID">1939</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92333596624452&amp;w=2" source="BUGTRAQ">19990405 Security Hole in Java 2 (and JDK 1.1.x)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="communicator">
        <vers num="4.5" />
      </prod>
      <prod vendor="netscape" name="navigator">
        <vers num="4.0" />
        <vers num="4.01" />
        <vers num="4.02" />
        <vers num="4.03" />
        <vers num="4.04" />
        <vers num="4.05" />
        <vers num="4.06" />
        <vers num="4.07" />
        <vers num="4.08" />
        <vers num="4.5" />
        <vers num="4.61" />
      </prod>
      <prod vendor="sun" name="java">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0441" published="1999-02-22" name="CVE-1999-0441" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Remote attackers can perform a denial of service in WinGate machines using a buffer overflow in the Winsock Redirector Service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/509" source="BID">509</ref>
      <ref url="http://www.eeye.com/html/Research/Advisories/AD02221999.html" source="EEYE">AD02221999</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qbik" name="wingate">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0442" published="1999-01-07" name="CVE-1999-0442" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Solaris ff.core allows local users to modify files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/327" source="BID">327</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0443" published="1999-04-01" name="CVE-1999-0443" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Patrol management software allows a remote attacker to conduct a replay attack to steal the administrator password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/13204" source="BUGTRAQ">19990409 Patrol security bugs</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bmc" name="patrol_agent">
        <vers num="3.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0444" published="1999-04-12" name="CVE-1999-0444" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Remote attackers can perform a denial of service in Windows machines using malicious ARP packets, forcing a message box display for each packet or filling up log files.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="windows_95">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0445" published="1999-04-01" name="CVE-1999-0445" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">In Cisco routers under some versions of IOS 12.0 running NAT, some packets may not be filtered by input access list filters.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/1104" source="OSVDB">1104</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.0" />
        <vers num="12.0(1)w" />
        <vers num="12.0(1)xa3" />
        <vers num="12.0(1)xb" />
        <vers num="12.0(1)xe" />
        <vers num="12.0(2)xc" />
        <vers num="12.0(2)xd" />
        <vers num="12.0(2)xf" />
        <vers num="12.0(2)xg" />
        <vers num="12.0db" />
        <vers num="12.0s" />
        <vers num="12.0t" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0446" published="1999-04-12" name="CVE-1999-0446" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Local users can perform a denial of service in NetBSD 1.3.3 and earlier versions by creating an unusual symbolic link with the ln command, triggering a bug in VFS.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/7051" source="OSVDB">7051</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0447" published="1999-04-01" name="CVE-1999-0447" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Local users can gain privileges using the debug utility in the MPE/iX operating system.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBMP9904-006" source="HP">HPSBMP9904-006</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="mpe_ix">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0448" published="1999-01-01" name="CVE-1999-0448" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0449" published="1999-01-26" name="CVE-1999-0449" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The ExAir sample site in IIS 4 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to the (1) advsearch.asp, (2) query.asp, or (3) search.asp scripts.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/193" source="BID">193</ref>
      <ref url="http://www.osvdb.org/4" source="OSVDB">4</ref>
      <ref url="http://www.osvdb.org/3" source="OSVDB">3</ref>
      <ref url="http://www.osvdb.org/2" source="OSVDB">2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0450" published="1999-01-26" name="CVE-1999-0450" modified="2009-06-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/194" source="BID">194</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0451" published="1999-01-19" name="CVE-1999-0451" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Denial of service in Linux 2.0.36 allows local users to prevent any server from listening on any non-privileged port.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/343" source="BID" adv="1">343</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.0" />
        <vers num="2.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0452" published="1999-01-01" name="CVE-1999-0452" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A service or application has a backdoor password that was placed there by the developer.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0453" published="1999-01-01" name="CVE-1999-0453" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">An attacker can identify a CISCO device by sending a SYN packet to port 1999, which is for the Cisco Discovery Protocol (CDP).</descript>
      <descript source="nvd">Please see the following link for more information:

http://seclists.org/bugtraq/1999/Jan/0215.html</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="cisco" name="router">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0454" published="1999-01-01" name="CVE-1999-0454" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A remote attacker can sometimes identify the operating system of a host based on how it reacts to some IP or ICMP packets, using a tool such as nmap or queso.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0455" published="1999-12-25" name="CVE-1999-0455" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Expression Evaluator sample application in ColdFusion allows remote attackers to read or delete files on the server via exprcalc.cfm, which does not restrict access to the server properly.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/115" source="BID" adv="1">115</ref>
    </refs>
    <vuln_soft>
      <prod vendor="allaire" name="coldfusion_server">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0457" published="1999-01-17" name="CVE-1999-0457" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Linux ftpwatch program allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/317" source="BID">317</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0458" published="1999-01-06" name="CVE-1999-0458" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">L0phtcrack 2.5 used temporary files in the system TEMP directory which could contain password information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/915" source="OSVDB">915</ref>
    </refs>
    <vuln_soft>
      <prod vendor="l0pht" name="l0phtcrack">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0459" published="1999-02-01" name="CVE-1999-0459" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Local users can perform a denial of service in Alpha Linux, using MILO to force a reboot.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0460" published="1999-02-19" name="CVE-1999-0460" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Buffer overflow in Linux autofs module through long directory names allows local users to perform a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/312" source="BID" adv="1">312</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0461" published="1999-01-28" name="CVE-1999-0461" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Versions of rpcbind including Linux, IRIX, and Wietse Venema's rpcbind allow a remote attacker to insert and delete entries by spoofing a source address.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.20.1" />
      </prod>
      <prod vendor="sgi" name="irix">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0462" published="1999-03-17" name="CVE-1999-0462" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">suidperl in Linux Perl does not check the nosuid mount option on file systems, allowing local users to gain root access by placing a setuid script in a mountable file system, e.g. a CD-ROM or floppy disk.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/339" source="BID" patch="1" adv="1">339</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="suse_linux">
        <vers num="5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0463" published="1998-12-01" name="CVE-1999-0463" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Remote attackers can perform a denial of service using IRIX fcagent.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19981201-01-PX" source="SGI">19981201-01-PX</ref>
    </refs>
    <vuln_soft>
      <prod vendor="l0pht" name="l0phtcrack">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0464" published="1999-01-04" name="CVE-1999-0464" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Local users can perform a denial of service in Tripwire 1.2 and earlier using long filenames.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91592136122066&amp;w=2" source="CONFIRM" adv="1">http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91592136122066&amp;w=2</ref>
      <ref url="http://www.osvdb.org/6609" source="OSVDB">6609</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91553066310826&amp;w=2" source="BUGTRAQ">19990104 Tripwire mess..</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tripwire" name="tripwire">
        <vers prev="1" num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0465" published="1999-01-01" name="CVE-1999-0465" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Remote attackers can crash Lynx and Internet Explorer using an IMG tag with a large width parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0466" published="1999-04-21" name="CVE-1999-0466" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The SVR4 /dev/wabi special device file in NetBSD 1.3.3 and earlier allows a local user to read or write arbitrary files on the disk associated with that device.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/905" source="OSVDB">905</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0467" published="1999-04-01" name="CVE-1999-0467" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Webcom CGI Guestbook programs wguest.exe and rguest.exe allow a remote attacker to read arbitrary files using the "template" parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="webcom" name="cgi_guestbook">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0468" published="1999-04-09" name="CVE-1999-0468" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Internet Explorer 5.0 allows a remote server to read arbitrary files on the client's file system using the Microsoft Scriptlet Component.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-012.asp" source="MS" adv="1">MS99-012</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0469" published="1999-04-01" name="CVE-1999-0469" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Internet Explorer 5.0 allows window spoofing, allowing a remote attacker to spoof a legitimate web site and capture information from the client.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0470" published="1999-04-09" name="CVE-1999-0470" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">A weak encryption algorithm is used for passwords in Novell Remote.NLM, allowing them to be easily decrypted.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/482" source="BID">482</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="netware">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0471" published="1999-04-09" name="CVE-1999-0471" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The remote proxy server in Winroute allows a remote attacker to reconfigure the proxy without authentication through the "cancel" button.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="winroute" name="winroute">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0472" published="1999-04-07" name="CVE-1999-0472" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The SNMP default community name "public" is not properly removed in NetApps C630 Netcache, even if the administrator tries to disable it.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="snmp" name="snmp">
        <vers num="" />
      </prod>
      <prod vendor="network_appliance" name="netcache">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0473" published="1999-04-07" name="CVE-1999-0473" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The rsync command before rsync 2.3.1 may inadvertently change the permissions of the client's working directory to the permissions of the directory being transferred.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/145" source="BID">145</ref>
    </refs>
    <vuln_soft>
      <prod vendor="andrew_tridgell" name="rsync">
        <vers prev="1" num="2.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0474" published="1999-04-05" name="CVE-1999-0474" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The ICQ Webserver allows remote attackers to use .. to access arbitrary files outside of the user's personal directory.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="mirabilis" name="icq">
        <vers num="99a_2.13build1700" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0475" published="1999-04-05" name="CVE-1999-0475" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">A race condition in how procmail handles .procmailrc files allows a local user to read arbitrary files available to the user who is running procmail.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="procmail" name="procmail">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0476" published="1999-03-01" name="CVE-1999-0476" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">A weak encryption algorithm is used for passwords in SCO TermVision, allowing them to be easily decrypted by a local user.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sco" name="openserver">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0477" published="1999-12-25" name="CVE-1999-0477" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Expression Evaluator in the ColdFusion Application Server allows a remote attacker to upload files to the server via openfile.cfm, which does not restrict access to the server properly.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/115" source="BID" patch="1" adv="1">115</ref>
    </refs>
    <vuln_soft>
      <prod vendor="allaire" name="coldfusion_server">
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="3.01" />
        <vers num="3.11" />
        <vers num="3.12" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0478" published="1998-12-01" name="CVE-1999-0478" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service in HP-UX sendmail 8.8.6 related to accepting connections.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9904-097" source="HP">HPSBUX9904-097</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sendmail" name="sendmail">
        <vers prev="1" num="8.9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0479" published="1999-03-01" name="CVE-1999-0479" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service Netscape Enterprise Server with VirtualVault on HP-UX VVOS systems.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-092" source="HP">HPSBUX9903-092</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="enterprise_server">
        <vers num="3.6" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.24" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0480" published="1999-04-01" name="CVE-1999-0480" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Local attackers can conduct a denial of service in Midnight Commander 4.x with a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="midnight_commander" name="midnight_commander">
        <vers num="4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0481" published="1999-03-22" name="CVE-1999-0481" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service in "poll" in OpenBSD.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/7556" source="OSVDB">7556</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0482" published="1999-03-21" name="CVE-1999-0482" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">OpenBSD kernel crash through TSS handling, as caused by the crashme program.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/7557" source="OSVDB">7557</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0483" published="1999-02-25" name="CVE-1999-0483" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">OpenBSD crash using nlink value in FFS and EXT2FS filesystems.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/6129" source="OSVDB">6129</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0484" published="1999-02-23" name="CVE-1999-0484" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Buffer overflow in OpenBSD ping.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/6130" source="OSVDB">6130</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0485" published="1999-02-19" name="CVE-1999-0485" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Remote attackers can cause a system crash through ipintr() in ipq in OpenBSD.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/7558" source="OSVDB">7558</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0486" published="1998-02-01" name="CVE-1999-0486" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service in AOL Instant Messenger when a remote attacker sends a malicious hyperlink to the receiving client, potentially causing a system crash.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="aol" name="instant_messenger">
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0487" published="1999-05-01" name="CVE-1999-0487" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">The DHTML Edit ActiveX control in Internet Explorer allows remote attackers to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-011.mspx" source="MS">MS99-011</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0488" published="1999-04-21" name="CVE-1999-0488" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Internet Explorer 4.0 and 5.0 allows a remote attacker to execute security scripts in a different security context using malicious URLs, a variant of the "cross frame" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-012.asp" source="MS" patch="1" adv="1">MS99-012</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.0" />
        <vers num="4.0.1" edition="sp1" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0489" published="1999-05-17" name="CVE-1999-0489" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in MS:MS98-013.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-015.asp" source="MS" patch="1" adv="1">MS99-015</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0490" published="1999-04-21" name="CVE-1999-0490" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to learn information about a local user's files via an IMG SRC tag.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-012.asp" source="MS" patch="1" adv="1">MS99-012</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0491" published="1999-04-20" name="CVE-1999-0491" modified="2011-08-08" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The prompt parsing in bash allows a local user to execute commands as another user by creating a directory with the name of the command to execute.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/119" source="BID">119</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="bash">
        <vers num="1.14.0" />
        <vers num="1.14.1" />
        <vers num="1.14.2" />
        <vers num="1.14.3" />
        <vers num="1.14.4" />
        <vers num="1.14.5" />
        <vers num="1.14.6" />
        <vers num="1.14.7" />
        <vers num="2.0" />
        <vers num="2.01" />
        <vers num="2.01.1" />
        <vers num="2.02" />
        <vers num="2.02.1" />
        <vers num="2.03" />
        <vers num="2.04" />
        <vers num="2.05" edition="a" />
        <vers num="2.05" edition="b" />
        <vers num="2.05b" />
        <vers num="3.0" />
        <vers num="3.0.16" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.2.48" />
        <vers num="4.0" edition="rc1" />
        <vers num="4.1" />
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0492" published="1999-04-23" name="CVE-1999-0492" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The ffingerd 1.19 allows remote attackers to identify users on the target system based on its responses.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0493" published="1999-06-07" name="CVE-1999-0493" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">rpc.statd allows remote attackers to forward RPC calls to the local operating system via the SM_MON and SM_NOTIFY commands, which in turn could be used to remotely exploit other bugs such as in automountd.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-99-05-statd-automountd.html" source="CERT" patch="1" adv="1">CA-99-05</ref>
      <ref url="http://www.securityfocus.com/bid/450" source="BID">450</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/j-045.shtml" source="CIAC">J-045</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/186&amp;type=0&amp;nav=sec.sba" source="SUN">00186</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91547759121289&amp;w=2" source="BUGTRAQ">19990103 SUN almost has a clue! (automountd)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.3" />
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0494" published="1998-07-01" name="CVE-1999-0494" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service in WinGate proxy through a buffer overflow in POP3.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="wingate" name="wingate">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0495" published="1999-01-01" name="CVE-1999-0495" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A remote attacker can gain access to a file system using ..  (dot dot) when accessing SMB shares.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0496" published="1997-01-01" name="CVE-1999-0496" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">A Windows NT 4.0 user can gain administrative rights by forcing NtOpenProcessToken to succeed regardless of the user's permissions, aka GetAdmin.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q146965" source="MSKB">Q146965</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0497" published="1999-01-01" name="CVE-1999-0497" modified="2007-07-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)" CVSS_score="0.0" CVSS_impact_subscore="0.0" CVSS_exploit_subscore="10.0" CVSS_base_score="0.0">
    <desc>
      <descript source="cve">Anonymous FTP is enabled.</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">Anonymous FTP is an unsecured protocol for Internet facing systems and should only be used on a limited basis to provide a specific functional requirement, otherwise disabled.  The software should be patched and configured properly.</sol>
    </sols>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0498" published="1991-09-27" name="CVE-1999-0498" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">TFTP is not running in a restricted directory, allowing a remote attacker to access sensitive information such as password files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0499" published="1997-01-01" name="CVE-1999-0499" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">NETBIOS share information may be published through SNMP registry keys in NT.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0501" published="1998-06-01" name="CVE-1999-0501" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">A Unix account has a guessable password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0502" published="1998-03-01" name="CVE-1999-0502" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">A Unix account has a default, null, blank, or missing password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.20" />
        <vers num="11" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="6.0" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.5.1" />
        <vers num="2.6" />
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0503" published="1997-01-01" name="CVE-1999-0503" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">A Windows NT local user or administrator account has a guessable password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0504" published="1997-01-01" name="CVE-1999-0504" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">A Windows NT local user or administrator account has a default, null, blank, or missing password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0505" published="1998-10-01" name="CVE-1999-0505" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">A Windows NT domain user or administrator account has a guessable password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0506" published="1998-10-01" name="CVE-1999-0506" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">A Windows NT domain user or administrator account has a default, null, blank, or missing password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0507" published="1998-04-01" name="CVE-1999-0507" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">An account on a router, firewall, or other network device has a guessable password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0508" published="1998-06-01" name="CVE-1999-0508" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">An account on a router, firewall, or other network device has a default, null, blank, or missing password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0509" published="1996-05-29" name="CVE-1999-0509" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Perl, sh, csh, or other shell interpreters are installed in the cgi-bin directory on a WWW site, which allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0510" published="1997-01-01" name="CVE-1999-0510" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">A router or firewall allows source routed packets from arbitrary hosts.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0511" published="1997-01-01" name="CVE-1999-0511" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">IP forwarding is enabled on a machine which is not a router or firewall.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0512" published="1999-01-01" name="CVE-1999-0512" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A mail server is explicitly configured to allow SMTP mail relay, which allows abuse by spammers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0513" published="1998-01-05" name="CVE-1999-0513" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="digital" name="unix">
        <vers num="3.2g" />
        <vers num="4.0" />
        <vers num="4.0a" />
        <vers num="4.0b" />
        <vers num="4.0c" />
        <vers num="4.0d" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="1.1.5.1" />
        <vers num="2.0.5" />
        <vers num="2.1.0" />
        <vers num="2.1.5" />
        <vers num="2.1.6" />
        <vers num="2.1.7.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.20" />
        <vers num="11.00" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.2.4" />
        <vers num="3.2.5" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.2" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":ppc" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0514" published="1998-03-01" name="CVE-1999-0514" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">UDP messages to broadcast addresses are allowed, allowing for a Fraggle attack that can cause a denial of service by flooding the target.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0515" published="1999-01-01" name="CVE-1999-0515" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">An unrestricted remote trust relationship for Unix systems has been set up, e.g. by using a + sign in /etc/hosts.equiv.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0516" published="1998-08-01" name="CVE-1999-0516" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">An SNMP community name is guessable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0517" published="1997-01-01" name="CVE-1999-0517" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">An SNMP community name is the default (e.g. public), null, or missing.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10" />
        <vers num="11.00" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0518" published="1997-01-01" name="CVE-1999-0518" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">A NETBIOS/SMB share password is guessable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="windows_95">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0519" published="1997-01-01" name="CVE-1999-0519" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">A NETBIOS/SMB share password is the default, null, or missing.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="outlook">
        <vers num="2000" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_95">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0520" published="1999-01-01" name="CVE-1999-0520" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">A system-critical NETBIOS/SMB share has inappropriate access control.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0521" published="1997-01-01" name="CVE-1999-0521" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">An NIS domain name is easily guessable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0522" published="1996-05-28" name="CVE-1999-0522" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The permissions for a system-critical NIS+ table (e.g. passwd) are inappropriate.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0523" published="1999-01-01" name="CVE-1999-0523" modified="2010-12-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)" CVSS_score="0.0" CVSS_impact_subscore="0.0" CVSS_exploit_subscore="10.0" CVSS_base_score="0.0">
    <desc>
      <descript source="cve">ICMP echo (ping) is allowed from arbitrary hosts.</descript>
    </desc>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0524" published="1997-08-01" name="CVE-1999-0524" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:N)" CVSS_score="0.0" CVSS_impact_subscore="0.0" CVSS_exploit_subscore="3.9" CVSS_base_score="0.0">
    <desc>
      <descript source="cve">ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.</descript>
    </desc>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/322" source="XF">icmp-timestamp(322)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/306" source="XF">icmp-netmask(306)</ref>
      <ref url="http://www.osvdb.org/95" source="OSVDB">95</ref>
      <ref url="http://kb.vmware.com/selfservice/microsites/search.do?cmd=displayKC&amp;externalId=1434" source="MISC">http://kb.vmware.com/selfservice/microsites/search.do?cmd=displayKC&amp;externalId=1434</ref>
      <ref url="http://descriptions.securescout.com/tc/11011" source="MISC">http://descriptions.securescout.com/tc/11011</ref>
      <ref url="http://descriptions.securescout.com/tc/11010" source="MISC">http://descriptions.securescout.com/tc/11010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os">
        <vers num="" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="ios">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="tru64">
        <vers num="" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="" />
      </prod>
      <prod vendor="ibm" name="os2">
        <vers num="" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="all_windows">
        <vers num="abstract_cpe" />
      </prod>
      <prod vendor="novell" name="netware">
        <vers num="" />
      </prod>
      <prod vendor="santa_cruz_operation" name="sco_unix">
        <vers num="" />
      </prod>
      <prod vendor="windriver" name="bsdos">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0525" published="1997-01-01" name="CVE-1999-0525" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">IP traceroute is allowed from arbitrary hosts.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0526" published="1997-07-01" name="CVE-1999-0526" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">An X server's access control is disabled (e.g. through an "xhost +" command) and allows anyone to connect to the server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/704969" source="CERT-VN">VU#704969</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x.org" name="x11">
        <vers num="7.1_1.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0527" published="1999-01-01" name="CVE-1999-0527" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The permissions for system-critical data in an anonymous FTP account are inappropriate.  For example, the root directory is writeable by world, a real password file is obtainable, or executable commands such as "ls" can be overwritten.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0528" published="1999-01-01" name="CVE-1999-0528" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">A router or firewall forwards external packets that claim to come from inside the network that the router/firewall is in front of.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0529" published="1999-01-01" name="CVE-1999-0529" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">A router or firewall forwards packets that claim to come from IANA reserved or private addresses, e.g. 10.x.x.x, 127.x.x.x, 217.x.x.x, etc.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0530" published="1999-01-01" name="CVE-1999-0530" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A system is operating in "promiscuous" mode which allows it to perform packet sniffing.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" seq="1999-0531" reject="1" published="1999-01-01" name="CVE-1999-0531" modified="2008-08-01">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "An SMTP service supports EXPN, VRFY, HELP, ESMTP, and/or EHLO."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">This functionality should be disabled, because these commands can be used for attack reconnaissance.</sol>
    </sols>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0532" published="1997-07-01" name="CVE-1999-0532" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)" CVSS_score="0.0" CVSS_impact_subscore="0.0" CVSS_exploit_subscore="10.0" CVSS_base_score="0.0">
    <desc>
      <descript source="cve">A DNS server allows zone transfers.</descript>
    </desc>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0533" published="1997-07-01" name="CVE-1999-0533" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">A DNS server allows inverse queries.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0534" published="1997-01-01" name="CVE-1999-0534" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">A Windows NT user has inappropriate rights or privileges, e.g. Act as System, Add Workstation, Backup, Change System Time, Create Pagefile, Create Permanent Object, Create Token Name, Debug, Generate Security Audit, Increase Priority, Increase Quota, Load Driver, Lock Memory, Profile Single Process, Remote Shutdown, Replace Process Token, Restore, System Environment, Take Ownership, or Unsolicited Input.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0535" published="1997-01-01" name="CVE-1999-0535" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A Windows NT account policy for passwords has inappropriate, security-critical settings, e.g. for password length, password age, or uniqueness.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0537" published="1998-04-01" name="CVE-1999-0537" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">A configuration in a web browser such as Internet Explorer or Netscape Navigator allows execution of active content such as ActiveX, Java, Javascript, etc.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0.2900" />
      </prod>
      <prod vendor="netscape" name="communicator">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0539" published="1999-01-01" name="CVE-1999-0539" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A trust relationship exists between two Unix hosts.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0541" published="1997-07-01" name="CVE-1999-0541" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">A password for accessing a WWW URL is guessable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0546" published="1998-10-01" name="CVE-1999-0546" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The Windows NT guest account is enabled.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0547" published="1999-01-01" name="CVE-1999-0547" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">An SSH server allows authentication through the .rhosts file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0548" published="1999-01-01" name="CVE-1999-0548" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A superfluous NFS server is running, but it is not importing or exporting any file systems.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0549" published="1999-01-01" name="CVE-1999-0549" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Windows NT automatically logs in an administrator upon rebooting.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0550" published="1997-01-01" name="CVE-1999-0550" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">A router's routing tables can be obtained from arbitrary hosts.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0551" published="1998-04-01" name="CVE-1999-0551" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">HP OpenMail can be misconfigured to allow users to run arbitrary commands using malicious print requests.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9804-078" source="HP">HPSBUX9804-078</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openmail">
        <vers num="4.1" />
        <vers num="5.1" />
        <vers num="5.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0554" published="1999-01-01" name="CVE-1999-0554" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">NFS exports system-critical data to the world, e.g. / or a password file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0555" published="1999-01-01" name="CVE-1999-0555" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A Unix account with a name other than "root" has UID 0, i.e. root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0556" published="1999-01-01" name="CVE-1999-0556" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Two or more Unix accounts have the same UID.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0559" published="1999-01-01" name="CVE-1999-0559" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A system-critical Unix file or directory has inappropriate permissions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0560" published="1999-01-01" name="CVE-1999-0560" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A system-critical Windows NT file or directory has inappropriate permissions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0561" published="1999-01-01" name="CVE-1999-0561" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">IIS has the #exec function enabled for Server Side Include (SSI) files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0562" published="1997-01-01" name="CVE-1999-0562" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The registry in Windows NT can be accessed remotely by users who are not administrators.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1023" source="OVAL" sig="1">oval:org.mitre.oval:def:1023</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0564" published="1999-01-01" name="CVE-1999-0564" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">An attacker can force a printer to print arbitrary documents (e.g. if the printer doesn't require a password) or to become disabled.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0565" published="1999-01-01" name="CVE-1999-0565" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A Sendmail alias allows input to be piped to a program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0566" published="1997-08-01" name="CVE-1999-0566" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">An attacker can write to syslog files from any location, causing a denial of service by filling up the logs, and hiding activities.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0568" published="1999-01-01" name="CVE-1999-0568" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">rpc.admind in Solaris is not running in a secure mode.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0569" published="1999-01-01" name="CVE-1999-0569" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A URL for a WWW directory allows auto-indexing, which provides a list of all files in that directory if it does not contain an index.html file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0570" published="1999-01-01" name="CVE-1999-0570" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Windows NT is not using a password filter utility, e.g. PASSFILT.DLL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0571" published="1999-01-01" name="CVE-1999-0571" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A router's configuration service or management interface (such as a web server or telnet) is configured to allow connections from arbitrary hosts.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0572" published="1997-01-01" name="CVE-1999-0572" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">.reg files are associated with the Windows NT registry editor (regedit), making the registry susceptible to Trojan Horse attacks.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0575" published="1997-01-01" name="CVE-1999-0575" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">A Windows NT system's user audit policy does not log an event success or failure, e.g. for Logon and Logoff, File and Object Access, Use of User Rights, User and Group Management, Security Policy Changes, Restart, Shutdown, and System, and Process Tracking.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0576" published="1997-01-01" name="CVE-1999-0576" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">A Windows NT system's file audit policy does not log an event success or failure for security-critical files or directories.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0577" published="1999-01-01" name="CVE-1999-0577" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0578" published="1999-01-01" name="CVE-1999-0578" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">A Windows NT system's registry audit policy does not log an event success or failure for security-critical registry keys.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0579" published="1999-01-01" name="CVE-1999-0579" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A Windows NT system's registry audit policy does not log an event success or failure for non-critical registry keys.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0580" published="1999-01-01" name="CVE-1999-0580" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The HKEY_LOCAL_MACHINE key in a Windows NT system has inappropriate, system-critical permissions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0581" published="1999-01-01" name="CVE-1999-0581" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0582" published="1997-01-01" name="CVE-1999-0582" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">A Windows NT account policy has inappropriate, security-critical settings for lockout, e.g. lockout duration, lockout after bad logon attempts, etc.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0583" published="1999-01-01" name="CVE-1999-0583" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">There is a one-way or two-way trust relationship between Windows NT domains.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0584" published="1999-01-01" name="CVE-1999-0584" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A Windows NT file system is not NTFS.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0585" published="2000-07-01" name="CVE-1999-0585" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">A Windows NT administrator account has the default name of Administrator.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="3.5.1" edition="sp1" />
        <vers num="3.5.1" edition="sp2" />
        <vers num="3.5.1" edition="sp3" />
        <vers num="3.5.1" edition="sp5" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0586" published="1999-01-01" name="CVE-1999-0586" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A network service is running on a nonstandard port.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0587" published="1999-01-01" name="CVE-1999-0587" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A WWW server is not running in a restricted file system, e.g. through a chroot, thus allowing access to system-critical data.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0588" published="1999-01-01" name="CVE-1999-0588" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">A filter in a router or firewall allows unusual fragmented packets.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0589" published="1999-01-01" name="CVE-1999-0589" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A system-critical Windows NT registry key has inappropriate permissions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0590" published="2000-06-01" name="CVE-1999-0590" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A system does not present an appropriate legal message or warning to a user who is accessing it.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="apple" name="mac_os">
        <vers num="" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.20.1" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_95">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="3.5.1" edition="sp1" />
        <vers num="3.5.1" edition="sp2" />
        <vers num="3.5.1" edition="sp3" />
        <vers num="3.5.1" edition="sp5" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0591" published="1999-01-01" name="CVE-1999-0591" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">An event log in Windows NT has inappropriate access permissions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0592" published="1999-01-01" name="CVE-1999-0592" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Logon box of a Windows NT system displays the name of the last user who logged in.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0593" published="1999-01-01" name="CVE-1999-0593" modified="2009-10-31" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The default setting for the Winlogon key entry ShutdownWithoutLogon in Windows NT allows users with physical access to shut down a Windows NT system without logging in.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/1291" source="XF">nt-shutdown-without-logon(1291)</ref>
      <ref url="http://www.microsoft.com/technet/archive/winntas/deploy/confeat/06wntpcc.mspx?mfr=true" source="MISC">http://www.microsoft.com/technet/archive/winntas/deploy/confeat/06wntpcc.mspx?mfr=true</ref>
      <ref url="http://technet.microsoft.com/en-us/library/cc722469.aspx" source="CONFIRM">http://technet.microsoft.com/en-us/library/cc722469.aspx</ref>
      <ref url="http://osvdb.org/59333" source="OSVDB">59333</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0594" published="1999-01-01" name="CVE-1999-0594" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A Windows NT system does not restrict access to removable media drives such as a floppy disk drive or CDROM drive.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0595" published="2000-01-20" name="CVE-1999-0595" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">A Windows NT system does not clear the system page file during shutdown, which might allow sensitive information to be recorded.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="3.5.1" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0596" published="1999-01-01" name="CVE-1999-0596" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A Windows NT log file has an inappropriate maximum size or retention period.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0597" published="1999-01-01" name="CVE-1999-0597" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A Windows NT account policy does not forcibly disconnect remote users from the server when their logon hours expire.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0598" published="1999-01-01" name="CVE-1999-0598" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A network intrusion detection system (IDS) does not properly handle packets that are sent out of order, allowing an attacker to escape detection.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0599" published="1999-01-01" name="CVE-1999-0599" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A network intrusion detection system (IDS) does not properly handle packets with improper sequence numbers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0600" published="1999-01-01" name="CVE-1999-0600" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A network intrusion detection system (IDS) does not verify the checksum on a packet.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0601" published="1999-01-01" name="CVE-1999-0601" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A network intrusion detection system (IDS) does not properly handle data within TCP handshake packets.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0602" published="1999-01-01" name="CVE-1999-0602" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A network intrusion detection system (IDS) does not properly reassemble fragmented packets.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0603" published="1999-01-01" name="CVE-1999-0603" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">In Windows NT, an inappropriate user is a member of a group, e.g. Administrator, Backup Operators, Domain Admins, Domain Guests, Power Users, Print Operators, Replicators, System Operators, etc.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0604" published="1999-04-20" name="CVE-1999-0604" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">An incorrect configuration of the WebStore 1.0 shopping cart CGI program "web_store.cgi" could disclose private information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92462991805485&amp;w=2" source="BUGTRAQ">19990420 Shopping Carts exposing CC data</ref>
    </refs>
    <vuln_soft>
      <prod vendor="selena_sol" name="selena_sol_webstore">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0605" published="1999-04-01" name="CVE-1999-0605" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">An incorrect configuration of the Order Form 1.0 shopping cart CGI program could disclose private information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92462991805485&amp;w=2" source="BUGTRAQ">19990420 Shopping Carts exposing CC data</ref>
    </refs>
    <vuln_soft>
      <prod vendor="austin_contract_computing" name="merchant_order_form">
        <vers num="1.0" />
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0606" published="1999-04-01" name="CVE-1999-0606" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">An incorrect configuration of the EZMall 2000 shopping cart CGI program "mall2000.cgi" could disclose private information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92462991805485&amp;w=2" source="BUGTRAQ">19990420 Shopping Carts exposing CC data</ref>
    </refs>
    <vuln_soft>
      <prod vendor="seaside_enterprises" name="ezmall">
        <vers num="2000" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0607" published="1999-04-20" name="CVE-1999-0607" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">quikstore.cgi in QuikStore shopping cart stores quikstore.cfg under the web document root with insufficient access control, which allows remote attackers to obtain the cleartext administrator password and gain privileges.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92462991805485&amp;w=2" source="BUGTRAQ">19990420 Shopping Carts exposing CC data</ref>
    </refs>
    <vuln_soft>
      <prod vendor="i-soft" name="quikstore">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0608" published="1999-04-01" name="CVE-1999-0608" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">An incorrect configuration of the PDG Shopping Cart CGI program "shopper.cgi" could disclose private information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.pdgsoft.com/Security/security.html." source="CONFIRM">http://www.pdgsoft.com/Security/security.html.</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/3857" source="XF">pdgsoftcart-misconfig(3857)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92462991805485&amp;w=2" source="BUGTRAQ">19990420 Shopping Carts exposing CC data</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pdgsoft" name="pdg_shopping_cart">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0609" published="1999-04-01" name="CVE-1999-0609" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">An incorrect configuration of the SoftCart CGI program "SoftCart.exe" could disclose private information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92462991805485&amp;w=2" source="BUGTRAQ">19990420 Shopping Carts exposing CC data</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mercantec" name="softcart">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0610" published="1999-04-01" name="CVE-1999-0610" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">An incorrect configuration of the Webcart CGI program could disclose private information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92462991805485&amp;w=2" source="BUGTRAQ">19990420 Shopping Carts exposing CC data</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mountain_network_systems" name="webcart">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0611" published="1999-01-01" name="CVE-1999-0611" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A system-critical Windows NT registry key has an inappropriate value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0612" published="1997-03-01" name="CVE-1999-0612" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)" CVSS_score="0.0" CVSS_impact_subscore="0.0" CVSS_exploit_subscore="10.0" CVSS_base_score="0.0">
    <desc>
      <descript source="cve">A version of finger is running that exposes valid user information to any entity on the network.</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">The FTP Service should be disabled because it could reveal information about a host's users, which could be used as reconnaissance information for attacks. </sol>
    </sols>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="gnu" name="finger_service">
        <vers num="" />
      </prod>
      <prod vendor="gnu" name="fingerd">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0613" published="1999-01-01" name="CVE-1999-0613" modified="2007-07-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)" CVSS_score="0.0" CVSS_impact_subscore="0.0" CVSS_exploit_subscore="10.0" CVSS_base_score="0.0">
    <desc>
      <descript source="cve">The rpc.sprayd service is running.</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">rpc.sprayd is an unsecured protocol for Internet facing systems and should only be used on a trusted network segment, otherwise disabled.  The software should be patched and configured properly.  </sol>
    </sols>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" seq="1999-0614" reject="1" published="1999-01-01" name="CVE-1999-0614" modified="2008-08-01">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "The FTP service is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">The FTP Service is an unsecured protocol for Internet facing systems and should only be used on a limited basis to provide a specific functional requirement, otherwise disabled.  Secure alternatives that encrypt communications are available.  The software should be patched and configured properly.</sol>
    </sols>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" seq="1999-0615" reject="1" published="1999-01-01" name="CVE-1999-0615" modified="2008-08-01">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "The SNMP service is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">SNMPv3 is a secure protocol for management of networked systems, provided the cryptographic security mechanisms are used.  SNMPv1 and SNMPv2 are unsecured protocols for Internet facing systems and should  only be used on a trusted network segment.  For all versions, the software should be patched and configured properly.</sol>
    </sols>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" seq="1999-0616" reject="1" published="1999-01-01" name="CVE-1999-0616" modified="2008-08-01">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "The TFTP service is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">The TFTP Service is an unsecured protocol and it should used only on a limited basis on rare occasion to provide a specific functional requirement, otherwise disabled.  Secure alternatives are available. </sol>
    </sols>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" seq="1999-0617" reject="1" published="1999-01-01" name="CVE-1999-0617" modified="2008-08-01">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "The SMTP service is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">The SMTP Service is an unsecured protocol for Internet facing systems (e.g., user authentication not required, communications not encrypted) and should only be used on a limited basis to provide a specific functional requirement, otherwise disabled.  The software should be patched and configured properly.</sol>
    </sols>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0618" published="1999-01-01" name="CVE-1999-0618" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The rexec service is running.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" seq="1999-0619" reject="1" published="1999-01-01" name="CVE-1999-0619" modified="2008-08-01">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "The Telnet service is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">The Telnet Service is an unsecured and obsolete protocol and it should be disabled.  Secure alternatives such as SSH are available.  </sol>
    </sols>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" seq="1999-0620" reject="1" published="1999-01-01" name="CVE-1999-0620" modified="2008-08-01">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "A component service related to NIS is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">These protocols, such as RPC ypbind, yppasswd, ypserv, ypupdated, and ypxfrd, are unsecured protocols for Internet facing systems and should only be used on a trusted network segment, otherwise disabled.  The software should be patched and configured properly.</sol>
    </sols>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" seq="1999-0621" reject="1" published="1999-01-01" name="CVE-1999-0621" modified="2008-08-01">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "A component service related to NETBIOS is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">This component service should not be allowed to communicate over untrusted networks, such as the Internet, because it is an unsecured protocol (e.g., communications not encrypted).   The software should be patched and configured properly.</sol>
    </sols>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1024" source="OVAL" sig="1">oval:org.mitre.oval:def:1024</ref>
    </refs>
  </entry>
  <entry type="CVE" seq="1999-0622" reject="1" published="1999-01-01" name="CVE-1999-0622" modified="2008-08-01">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "A component service related to DNS service is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">DNS is a critical network service.  It should be fully patched and properly configured for Internet facing servers to avoid common attacks such as DNS spoofing, poisoning, and unauthorized zone transfers.</sol>
    </sols>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" seq="1999-0623" reject="1" published="1999-01-01" name="CVE-1999-0623" modified="2008-08-01">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "The X Windows service is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">The XWindows service is an unsecured protocol for Internet facing system and should only be used on a trusted network segment, otherwise disabled.  The software should be patched and configured properly.</sol>
    </sols>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0624" published="1999-01-01" name="CVE-1999-0624" modified="2007-07-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)" CVSS_score="0.0" CVSS_impact_subscore="0.0" CVSS_exploit_subscore="10.0" CVSS_base_score="0.0">
    <desc>
      <descript source="cve">The rstat/rstatd service is running.</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">These are unsecured and obsolete protocols and they should be disabled.  </sol>
    </sols>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0625" published="1999-01-01" name="CVE-1999-0625" modified="2007-07-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)" CVSS_score="0.0" CVSS_impact_subscore="0.0" CVSS_exploit_subscore="10.0" CVSS_base_score="0.0">
    <desc>
      <descript source="cve">The rpc.rquotad service is running.</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">rpc.rquotad is an unsecured and obsolete protocol and it should be disabled.  </sol>
    </sols>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0626" published="1997-01-01" name="CVE-1999-0626" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)" CVSS_score="0.0" CVSS_impact_subscore="0.0" CVSS_exploit_subscore="10.0" CVSS_base_score="0.0">
    <desc>
      <descript source="cve">A version of rusers is running that exposes valid user information to any entity on the network.</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">rusers is an unsecured and obsolete protocol and it should be disabled. </sol>
    </sols>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sun" name="rpc.ruserd">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0627" published="1992-03-01" name="CVE-1999-0627" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)" CVSS_score="0.0" CVSS_impact_subscore="0.0" CVSS_exploit_subscore="10.0" CVSS_base_score="0.0">
    <desc>
      <descript source="cve">The rexd service is running, which uses weak authentication that can allow an attacker to execute commands.</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">The rexd service is an unsecured protocol for Internet facing systems and should only be used on a trusted network segment, otherwise disabled.  The software should be patched and configured properly.</sol>
    </sols>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="3.1" />
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0628" published="1997-07-01" name="CVE-1999-0628" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The rwho/rwhod service is running, which exposes machine status and user information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="6.2" edition="stable" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="4.2" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.20.1" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="2.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0629" published="1999-01-01" name="CVE-1999-0629" modified="2010-12-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)" CVSS_score="0.0" CVSS_impact_subscore="0.0" CVSS_exploit_subscore="10.0" CVSS_base_score="0.0">
    <desc>
      <descript source="cve">The ident/identd service is running.</descript>
    </desc>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0630" published="1999-01-01" name="CVE-1999-0630" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The NT Alerter and Messenger services are running.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" seq="1999-0631" reject="1" published="1999-01-01" name="CVE-1999-0631" modified="2008-08-01">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "The NFS service is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">NFS Service is an unsecured protocol for Internet facing systems (e.g., user authentication not required, communications not encrypted) and should only be used on a trusted managed network, otherwise disabled.  The software should be patched and configured properly.</sol>
    </sols>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0632" published="1999-01-01" name="CVE-1999-0632" modified="2007-07-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)" CVSS_score="0.0" CVSS_impact_subscore="0.0" CVSS_exploit_subscore="10.0" CVSS_base_score="0.0">
    <desc>
      <descript source="cve">The RPC portmapper service is running.</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">The RPC portmapper service is an unsecured protocol for Internet facing systems and should only be used on a trusted network segment, otherwise disabled.  The software should be patched and configured properly. </sol>
    </sols>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" seq="1999-0633" reject="1" published="1999-01-01" name="CVE-1999-0633" modified="2008-08-01">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "The HTTP/WWW service is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">The software should be patched and configured properly.  SSL/TLS should be used to protect transmissions of sensitive data.  The presence of HTTP may be an indication that an web application server is running on the system.</sol>
    </sols>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" seq="1999-0634" reject="1" published="1999-01-01" name="CVE-1999-0634" modified="2008-08-01">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "The SSH service is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">SSH is a secure protocol, provided it is fully patched, properly configured, and uses FIPS approved algorithms.  SSH version 2 is preferred over SSH version 1 because of known flaws in version 1.</sol>
    </sols>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0635" published="1999-01-01" name="CVE-1999-0635" modified="2007-07-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)" CVSS_score="0.0" CVSS_impact_subscore="0.0" CVSS_exploit_subscore="10.0" CVSS_base_score="0.0">
    <desc>
      <descript source="cve">The echo service is running.</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">The Echo Service is an unsecured and obsolete protocol and it should be disabled.  Historically it has been used to perform denial of service attacks.</sol>
    </sols>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18514" source="SECUNIA" adv="1">18514</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041434.html" source="FULLDISC">20060116 ACT P202S VoIP wireless phone multiple undocumented ports/services</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0636" published="1999-01-01" name="CVE-1999-0636" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The discard service is running.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0637" published="1999-01-01" name="CVE-1999-0637" modified="2007-07-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)" CVSS_score="0.0" CVSS_impact_subscore="0.0" CVSS_exploit_subscore="10.0" CVSS_base_score="0.0">
    <desc>
      <descript source="cve">The systat service is running.</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">The systat service is an unsecured and obsolete protocol and it should be disabled because it can reveal information about a host's operations.  </sol>
    </sols>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0638" published="1999-01-01" name="CVE-1999-0638" modified="2007-07-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)" CVSS_score="0.0" CVSS_impact_subscore="0.0" CVSS_exploit_subscore="10.0" CVSS_base_score="0.0">
    <desc>
      <descript source="cve">The daytime service is running.</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">The daytime service is an unsecured and obsolete protocol and it should be disabled.</sol>
    </sols>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0639" published="1999-01-01" name="CVE-1999-0639" modified="2007-07-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)" CVSS_score="0.0" CVSS_impact_subscore="0.0" CVSS_exploit_subscore="10.0" CVSS_base_score="0.0">
    <desc>
      <descript source="cve">The chargen service is running.</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">chargen service is an unsecured and obsolete protocol and it should be disabled.  Historically it has been used to perform denial of service attacks.  Ping and traceroute can be used to provide the same functionality.</sol>
    </sols>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0640" published="1999-01-01" name="CVE-1999-0640" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Gopher service is running.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0641" published="1999-01-01" name="CVE-1999-0641" modified="2007-07-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)" CVSS_score="0.0" CVSS_impact_subscore="0.0" CVSS_exploit_subscore="10.0" CVSS_base_score="0.0">
    <desc>
      <descript source="cve">The UUCP service is running.</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">The UUCP Service is an unsecured and obsolete protocol and it should be disabled.  </sol>
    </sols>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" seq="1999-0642" reject="1" published="1999-01-01" name="CVE-1999-0642" modified="2008-08-01">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "A POP service is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">POP3 is an unsecured protocol for Internet facing systems that does not encrypt its transmissions.  POP3 should be tunneled over SSL/TLS or another encrypted tunnel.  The software should be patched and configured properly.  Earlier versions of POP, such as POP2, are unsecured and obsolete, and should be disabled.</sol>
    </sols>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" seq="1999-0643" reject="1" published="1999-01-01" name="CVE-1999-0643" modified="2008-08-01">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "The IMAP service is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">IMAP Service is an unsecured protocol for Internet facing systems that does not encrypt its transmissions.  IMAP should be tunneled over SSL/TLS or another encrypted tunnel.  The software should be patched and configured properly.</sol>
    </sols>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" seq="1999-0644" reject="1" published="1999-01-01" name="CVE-1999-0644" modified="2008-08-01">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "The NNTP news service is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">NNTP news service is an unsecured protocol for Internet facing systems (e.g., user authentication not required, communications not encrypted).  It could be tunneled over SSL/TLS.  The software should be patched and configured properly.</sol>
    </sols>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" seq="1999-0645" reject="1" published="1999-01-01" name="CVE-1999-0645" modified="2008-08-01">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "The IRC service is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">IRC Service is an unsecured protocol that typically does not authenticate the identity of users and does not encrypt its network communications.  IRC is not commonly deployed on enterprise networks.  If an organization decides to use it, it should be patched and configured properly, otherwise it should be disabled.</sol>
    </sols>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" seq="1999-0646" reject="1" published="1999-01-01" name="CVE-1999-0646" modified="2008-08-01">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "The LDAP service is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">The software should be patched and configured properly to prevent information disclosure.  It can be tunneled over SSL/TLS.</sol>
    </sols>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" seq="1999-0647" reject="1" published="1999-01-01" name="CVE-1999-0647" modified="2008-08-01">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "The bootparam (bootparamd) service is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">The bootparam service is an unsecured protocol for Internet facing systems and should only be used on a trusted network segment, otherwise disabled.  The software should be patched and configured properly.  </sol>
    </sols>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" seq="1999-0648" reject="1" published="1999-01-01" name="CVE-1999-0648" modified="2008-08-01">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "The X25 service is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">X25 is an unsecured protocol for Internet facing systems and should only be used on a limited basis to provide a specific functional requirement, otherwise disabled.  The software should be patched and configured properly.</sol>
    </sols>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" seq="1999-0649" reject="1" published="1999-01-01" name="CVE-1999-0649" modified="2008-08-01">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "The FSP service is running."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0650" published="1999-01-01" name="CVE-1999-0650" modified="2006-06-15" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The netstat service is running, which provides sensitive information to remote attackers.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0651" published="1999-01-01" name="CVE-1999-0651" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The rsh/rlogin service is running.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" seq="1999-0652" reject="1" published="1999-01-01" name="CVE-1999-0652" modified="2008-08-01">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "A database service is running, e.g. a SQL server, Oracle, or mySQL."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">The software should be patched and configured properly to prevent information leakage and unauthorized access.</sol>
    </sols>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0653" published="1999-01-01" name="CVE-1999-0653" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A component service related to NIS+ is running.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0654" published="1999-01-01" name="CVE-1999-0654" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The OS/2 or POSIX subsystem in NT is enabled.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" seq="1999-0655" reject="1" published="1999-01-01" name="CVE-1999-0655" modified="2008-08-01">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is not about any specific product, protocol, or design, so it is out of scope of CVE.  Notes: the former description is: "A service may include useful information in its banner or help function (such as the name and version), making it useful for information gathering activities."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0656" published="1999-01-01" name="CVE-1999-0656" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The ugidd RPC interface, by design, allows remote attackers to enumerate valid usernames by specifying arbitrary UIDs that ugidd maps to local user and group names.</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/348" source="XF">linux-ugidd(348)</ref>
      <ref url="http://ca.com/au/securityadvisor/vulninfo/Vuln.aspx?ID=1638" source="MISC">http://ca.com/au/securityadvisor/vulninfo/Vuln.aspx?ID=1638</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0657" published="1999-01-01" name="CVE-1999-0657" modified="2007-07-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)" CVSS_score="0.0" CVSS_impact_subscore="0.0" CVSS_exploit_subscore="10.0" CVSS_base_score="0.0">
    <desc>
      <descript source="cve">WinGate is being used.</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" seq="1999-0658" reject="1" published="1999-01-01" name="CVE-1999-0658" modified="2008-08-01">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "DCOM is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" seq="1999-0659" reject="1" published="1999-01-01" name="CVE-1999-0659" modified="2008-08-01">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "A Windows NT Primary Domain Controller (PDC) or Backup Domain Controller (BDC) is present."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" seq="1999-0660" reject="1" published="1999-01-01" name="CVE-1999-0660" modified="2008-08-01">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is not about any specific product, protocol, or design, so it is out of scope of CVE.  It might be more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "A hacker utility, back door, or Trojan Horse is installed on a system, e.g. NetBus, Back Orifice, Rootkit, etc."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0661" published="1999-01-01" name="CVE-1999-0661" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A system is running a version of software that was replaced with a Trojan Horse at one of its distribution points, such as (1) TCP Wrappers 7.6, (2) util-linux 2.9g, (3) wuarchive ftpd (wuftpd) 2.2 and 2.1f, (4) IRC client (ircII) ircII 2.2.9, (5) OpenSSH 3.4p1, or (6) Sendmail 8.12.6.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2002-28.html" source="CERT">CA-2002-28</ref>
      <ref url="http://www.cert.org/advisories/CA-1999-02.html" source="CERT">CA-1999-02</ref>
      <ref url="http://www.cert.org/advisories/CA-1999-01.html" source="CERT">CA-1999-01</ref>
      <ref url="http://www.cert.org/advisories/CA-1994-14.html" source="CERT">CA-1994-14</ref>
      <ref url="http://www.cert.org/advisories/CA-1994-07.html" source="CERT">CA-1994-07</ref>
      <ref url="http://www.securityfocus.com/bid/5921" source="BID">5921</ref>
      <ref url="http://www.iss.net/security_center/static/10313.php" source="XF">sendmail-backdoor(10313)</ref>
      <ref url="http://online.securityfocus.com/archive/1/294539" source="BUGTRAQ">20021009 Re: CERT Advisory CA-2002-28 Trojan Horse Sendmail</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=102821663814127&amp;w=2" source="BUGTRAQ">20020801 OpenSSH Security Advisory:  Trojaned Distribution Files</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=102820843403741&amp;w=2" source="BUGTRAQ">20020801 trojan horse in recent openssh (version 3.4 portable 1)</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0662" published="1999-01-01" name="CVE-1999-0662" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A system-critical program or library does not have the appropriate patch, hotfix, or service pack installed, or is outdated or obsolete.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0663" published="1999-01-01" name="CVE-1999-0663" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A system-critical program, library, or file has a checksum or other integrity measurement that indicates that it has been modified.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0664" published="1999-01-01" name="CVE-1999-0664" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">An application-critical Windows NT registry key has inappropriate permissions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0665" published="1999-01-01" name="CVE-1999-0665" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">An application-critical Windows NT registry key has an inappropriate value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0667" published="1997-09-19" name="CVE-1999-0667" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The ARP protocol allows any host to spoof ARP replies and poison the ARP cache to conduct IP address spoofing or a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="arp_protocol" name="arp_protocol">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0668" published="1999-08-21" name="CVE-1999-0668" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">The scriptlet.typelib ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-032.asp" source="MS" patch="1">MS99-032</ref>
      <ref url="http://www.securityfocus.com/bid/598" source="BID">598</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q240308" source="MSKB">Q240308</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/j-064.shtml" source="CIAC">J-064</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0669" published="1999-09-01" name="CVE-1999-0669" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.9" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">The Eyedog ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/j-064.shtml" source="CIAC" adv="1">J-064</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0670" published="1999-09-01" name="CVE-1999-0670" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.9" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Buffer overflow in the Eyedog ActiveX control allows a remote attacker to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-032.asp" source="MS">MS99-032</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/j-064.shtml" source="CIAC">J-064</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0671" published="1999-08-03" name="CVE-1999-0671" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in ToxSoft NextFTP client through CWD command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/572" source="BID">572</ref>
    </refs>
    <vuln_soft>
      <prod vendor="toxsoft" name="nextftp">
        <vers num="1.82" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0672" published="1999-08-01" name="CVE-1999-0672" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in Fujitsu Chocoa IRC client via IRC channel topics.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/573" source="BID">573</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fujitsu" name="chocoa">
        <vers num="1.0beta7r" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0673" published="1999-08-08" name="CVE-1999-0673" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in ALMail32 POP3 client via From: or To: headers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/574" source="BID">574</ref>
    </refs>
    <vuln_soft>
      <prod vendor="crear" name="almail32">
        <vers num="1.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0674" published="1999-08-09" name="CVE-1999-0674" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The BSD profil system call allows a local user to modify the internal data space of a program via profiling and execve.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/570" source="BID" patch="1" adv="1">570</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/j-067.shtml" source="CIAC">J-067</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.4" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0675" published="1999-08-09" name="CVE-1999-0675" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Check Point FireWall-1 can be subjected to a denial of service via UDP packets that are sent through VPN-1 to port 0 of a host.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/576" source="BID">576</ref>
      <ref url="http://www.securityfocus.com/archive/1/23615" source="BUGTRAQ">19990809 FW1 UDP Port 0 DoS</ref>
      <ref url="http://www.osvdb.org/1038" source="OSVDB">1038</ref>
    </refs>
    <vuln_soft>
      <prod vendor="checkpoint" name="firewall-1">
        <vers num="3.0" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0676" published="1999-08-09" name="CVE-1999-0676" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">sdtcm_convert in Solaris 2.6 allows a local user to overwrite sensitive files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=19990809134220.A1191@hades.chaoz.org" source="BUGTRAQ">19990808 sdtcm_convert</ref>
      <ref url="http://www.securityfocus.com/bid/575" source="BID">575</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0677" published="1999-08-03" name="CVE-1999-0677" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The WebRamp web administration utility has a default password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/577" source="BID">577</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ramp_networks" name="webramp_200i">
        <vers num="1.0" />
      </prod>
      <prod vendor="ramp_networks" name="webramp_m3">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0678" published="1999-01-17" name="CVE-1999-0678" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the entire server.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/318" source="BID">318</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0679" published="1999-08-13" name="CVE-1999-0679" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in hybrid-6 IRC server commonly used on EFnet allows remote attackers to execute commands via m_invite invite option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.efnet.org/archive/servers/hybrid/ChangeLog" source="CONFIRM">http://www.efnet.org/archive/servers/hybrid/ChangeLog</ref>
      <ref url="http://www.securityfocus.com/bid/581" source="BID">581</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hybrid_network" name="hybrid_ircd">
        <vers num="5.03p7" />
        <vers prev="1" num="6.0beta58" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0680" published="1999-08-09" name="CVE-1999-0680" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Windows NT Terminal Server performs extra work when a client opens a new connection but before it is authenticated, allowing for a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/571" source="BID" patch="1" adv="1">571</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-028.mspx" source="MS" patch="1">MS99-028</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/j-057.shtml" source="CIAC">J-057</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q238600" source="MSKB">Q238600</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="terminal_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0681" published="2001-03-12" name="CVE-1999-0681" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft FrontPage Server Extensions (PWS) 3.0.2.926 on Windows 95, and possibly other versions, allows remote attackers to cause a denial of service via a long URL.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3117.php" source="XF" adv="1">frontpage-pws-dos</ref>
      <ref url="http://www.securityfocus.com/bid/568" source="BID" adv="1">568</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/1999-q3/0381.html" source="BUGTRAQ" adv="1">19990807 Crash FrontPage Remotely...</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="frontpage">
        <vers num="97" />
        <vers num="98" />
      </prod>
      <prod vendor="microsoft" name="personal_web_server">
        <vers num="1.0" />
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0682" published="1999-08-06" name="CVE-1999-0682" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Exchange 5.5 allows a remote attacker to relay email (i.e. spam) using encapsulated SMTP addresses, even if the anti-relaying features are enabled.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/567" source="BID">567</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-027.mspx" source="MS">MS99-027</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/j-056.shtml" source="CIAC">J-056</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q237927" source="MSKB">Q237927</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="5.5" edition="sp1" />
        <vers num="5.5" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0683" published="1999-07-30" name="CVE-1999-0683" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service in Gauntlet Firewall via a malformed ICMP packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/556" source="BID" patch="1" adv="1">556</ref>
      <ref url="http://www.osvdb.org/1029" source="OSVDB">1029</ref>
    </refs>
    <vuln_soft>
      <prod vendor="network_associates" name="gauntlet_firewall">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0684" published="1999-04-19" name="CVE-1999-0684" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service in Sendmail 8.8.6 in HPUX.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="hp" name="sendmail">
        <vers num="8.8.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0685" published="1999-09-02" name="CVE-1999-0685" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in Netscape Communicator via EMBED tags in the pluginspage option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/618" source="BID">618</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="communicator">
        <vers num="4.06" />
        <vers num="4.5" />
        <vers num="4.51" />
        <vers num="4.6" />
        <vers num="4.61" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0686" published="1999-05-07" name="CVE-1999-0686" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service in Netscape Enterprise Server (NES) in HP Virtual Vault (VVOS) via a long URL.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9906-098" source="HP">HPSBUX9906-098</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/j-046.shtml" source="CIAC">J-046</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="enterprise_server">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.24" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0687" published="1999-09-13" name="CVE-1999-0687" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9909-103" source="HP">HPSBUX9909-103</ref>
      <ref url="http://www.securityfocus.com/bid/637" source="BID">637</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/k-001.shtml" source="CIAC">K-001</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/192" source="SUN">00192</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cde" name="cde">
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.120" />
      </prod>
      <prod vendor="digital" name="unix">
        <vers num="4.0d" />
        <vers num="4.0f" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
        <vers num="4.2" />
        <vers num="4.2.1" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.2" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.3" />
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="4.1.3u1" />
        <vers num="4.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0688" published="1999-07-01" name="CVE-1999-0688" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflows in HP Software Distributor (SD) for HPUX 10.x and 11.x.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9907-101" source="HP">HPSBUX9907-101</ref>
      <ref url="http://www.securityfocus.com/bid/545" source="BID">545</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.24" />
        <vers num="11.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0689" published="1999-09-13" name="CVE-1999-0689" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9909-103" source="HP">HPSBUX9909-103</ref>
      <ref url="http://www.securityfocus.com/bid/636" source="BID">636</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/192" source="SUN">00192</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1880" source="OVAL" sig="1">oval:org.mitre.oval:def:1880</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cde" name="cde">
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.120" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0690" published="1999-07-01" name="CVE-1999-0690" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">HP CDE program includes the current directory in root's PATH variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <env />
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.ciac.org/ciac/bulletins/j-053.shtml" source="CIAC" adv="1">J-053</ref>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9907-100" source="HP">HPSBUX9907-100</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cde" name="cde">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0691" published="1999-09-13" name="CVE-1999-0691" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9909-103" source="HP">HPSBUX9909-103</ref>
      <ref url="http://www.securityfocus.com/bid/635" source="BID">635</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/192" source="SUN">00192</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3078" source="OVAL" sig="1">oval:org.mitre.oval:def:3078</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cde" name="cde">
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
      <prod vendor="digital" name="unix">
        <vers num="4.0d" />
        <vers num="4.0e" />
        <vers num="4.0f" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
        <vers num="4.2" />
        <vers num="4.2.1" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.2" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0692" published="1999-07-19" name="CVE-1999-0692" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The default configuration of the Array Services daemon (arrayd) disables authentication, allowing remote users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ciac.org/ciac/bulletins/j-052.shtml" source="CIAC">J-052</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19990701-01-P" source="SGI">19990701-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cray" name="unicos">
        <vers num="" />
      </prod>
      <prod vendor="sgi" name="irix">
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
        <vers num="6.5.3" />
        <vers num="6.5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0693" published="2000-03-02" name="CVE-1999-0693" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in TT_SESSION environment variable in ToolTalk shared library allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9909-103" source="HP">HPSBUX9909-103</ref>
      <ref url="http://www.securityfocus.com/bid/641" source="BID">641</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/192" source="SUN">00192</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4374" source="OVAL" sig="1">oval:org.mitre.oval:def:4374</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10" />
        <vers num="11" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="4" />
      </prod>
      <prod vendor="sco" name="unixware">
        <vers num="7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0694" published="1999-08-11" name="CVE-1999-0694" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Denial of service in AIX ptrace system call allows local users to crash the system.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.ciac.org/ciac/bulletins/j-055.shtml" source="CIAC" patch="1" adv="1">J-055</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.2" />
        <vers num="4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0695" published="2000-04-11" name="CVE-1999-0695" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Sybase PowerDynamo personal web server allows attackers to read arbitrary files through a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/620" source="BID">620</ref>
      <ref url="http://www.osvdb.org/1064" source="OSVDB">1064</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sybase" name="powerdynamo">
        <vers num="3.0.652" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0696" published="1999-07-01" name="CVE-1999-0696" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in CDE Calendar Manager Service Daemon (rpc.cmsd).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9908-102" source="HP">HPSBUX9908-102</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/j-051.shtml" source="CIAC">J-051</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/188" source="SUN">00188</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.24" />
        <vers num="11.00" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" />
        <vers num="2.6" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="4.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0697" published="1999-09-09" name="CVE-1999-0697" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">SCO Doctor allows local users to gain root privileges through a Tools option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/621" source="BID">621</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="openserver">
        <vers num="5.0.4" />
        <vers num="5.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0698" published="1999-01-01" name="CVE-1999-0698" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Denial of service in IP protocol logger (ippl) on Red Hat and Debian Linux.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0699" published="2000-04-11" name="CVE-1999-0699" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Bluestone Sapphire web server allows session hijacking via easily guessable session IDs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/623" source="BID">623</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bluestone" name="sapphire_web">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0700" published="1999-07-29" name="CVE-1999-0700" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-026.mspx" source="MS">MS99-026</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q237185" source="MSKB">Q237185</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0701" published="2000-04-11" name="CVE-1999-0701" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">After an unattended installation of Windows NT 4.0, an installation file could include sensitive information such as the local Administrator password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/626" source="BID">626</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-036.mspx" source="MS">MS99-036</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q173039" source="MSKB">Q173039</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0702" published="1999-09-10" name="CVE-1999-0702" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Internet Explorer 5.0 and 5.01 allows remote attackers to modify or execute files via the Import/Export Favorites feature, aka the "ImportExportFavorites" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/627" source="BID">627</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-037.mspx" source="MS">MS99-037</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q241361" source="MSKB">Q241361</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.0.1" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0703" published="1999-08-03" name="CVE-1999-0703" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">OpenBSD, BSDI, and other Unix operating systems allow users to set chflags and fchflags on character and block devices.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.ciac.org/ciac/bulletins/j-066.shtml" source="CIAC">J-066</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bsdi" name="bsd_os">
        <vers num="3.2" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.2" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0704" published="1999-09-16" name="CVE-1999-0704" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in Berkeley automounter daemon (amd) logging facility provided in the Linux am-utils package and others.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/614" source="BID">614</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bsdi" name="bsd_os">
        <vers num="3.1" />
        <vers num="4.0.1" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" edition="" />
        <vers num="5.2" edition=":i386" />
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0705" published="1999-09-01" name="CVE-1999-0705" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in INN inews program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/616" source="BID">616</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="inn">
        <vers num="" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0706" published="2000-04-27" name="CVE-1999-0706" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Linux xmonisdn package allows local users to gain root privileges by modifying the IFS or PATH environmental variables.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/583" source="BID">583</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="inn">
        <vers num="1.5.1" />
        <vers num="1.7" />
        <vers num="1.7.2" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" edition="" />
        <vers num="5.2" edition=":i386" />
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0707" published="1999-07-01" name="CVE-1999-0707" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The default FTP configuration in HP Visualize Conference allows conference users to send a file to other participants without authorization.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ciac.org/ciac/bulletins/j-050.shtml" source="CIAC" adv="1">J-050</ref>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9906-099" source="HP">HPSBUX9906-099</ref>
      <ref url="http://www.securityfocus.com/bid/493" source="BID">493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="visualize_conference_ftp">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0708" published="1999-09-21" name="CVE-1999-0708" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in cfingerd allows local users to gain root privileges via a long GECOS field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/651" source="BID">651</ref>
    </refs>
    <vuln_soft>
      <prod vendor="infodrom" name="cfingerd">
        <vers num="1.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0710" published="1999-07-25" name="CVE-1999-0710" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, installs cachemgr.cgi in a public web directory, which allows remote attackers to use it as an intermediary to connect to other systems.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/2385" source="XF">http-cgi-cachemgr(2385)</ref>
      <ref url="http://www.securityfocus.com/bid/2059" source="BID">2059</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-489.html" source="REDHAT">RHSA-2005:489</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-1999-025.html" source="REDHAT">RHSA-1999:025</ref>
      <ref url="http://www.redhat.com/support/errata/archives/rh52-errata-general.html#squid" source="CONFIRM">http://www.redhat.com/support/errata/archives/rh52-errata-general.html#squid</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2005-May/msg00025.html" source="FEDORA">FEDORA-2005-373</ref>
      <ref url="http://www.debian.org/security/2004/dsa-576" source="DEBIAN">DSA-576</ref>
      <ref url="http://fedoranews.org/updates/FEDORA--.shtml" source="FEDORA">FLSA-2006:152809</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="5.2" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0711" published="1999-04-29" name="CVE-1999-0711" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The oratclsh interpreter in Oracle 8.x Intelligent Agent for Unix allows local users to execute Tcl commands as root.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?t=92550157100002&amp;w=2&amp;r=1" source="BUGTRAQ">19990430 *Huge* security hole in Oracle 8.0.5 with Intellegent agent installed</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92609807906778&amp;w=2" source="BUGTRAQ">19990506 Oracle Security Followup, patch and FAQ: setuid on oratclsh</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="oracle8i">
        <vers num="8.0.3" />
        <vers num="8.0.4" />
        <vers num="8.0.5" />
        <vers num="8.0.5.1" />
        <vers num="8.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0712" published="1999-04-27" name="CVE-1999-0712" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">A vulnerability in Caldera Open Administration System (COAS) allows the /etc/shadow password file to be made world-readable.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="caldera" name="coas">
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
      </prod>
      <prod vendor="caldera" name="openlinux">
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0713" published="1999-06-11" name="CVE-1999-0713" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The dtlogin program in Compaq Tru64 UNIX allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.ciac.org/ciac/bulletins/j-044.shtml" source="CIAC">J-044</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cde" name="cde">
        <vers num="" />
      </prod>
      <prod vendor="mit" name="kerberos">
        <vers num="5" />
      </prod>
      <prod vendor="transarc" name="afs">
        <vers num="" />
      </prod>
      <prod vendor="digital" name="unix">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0714" published="1999-02-15" name="CVE-1999-0714" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Vulnerability in Compaq Tru64 UNIX edauth command.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="digital" name="unix">
        <vers num="3.2g" />
        <vers num="4.0" />
        <vers num="4.0a" />
        <vers num="4.0b" />
        <vers num="4.0c" />
        <vers num="4.0d" />
        <vers num="4.0e" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0715" published="1999-05-20" name="CVE-1999-0715" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in Remote Access Service (RAS) client allows an attacker to execute commands or cause a denial of service via a malformed phonebook entry.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q230677" source="MSKB">Q230677</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-016.mspx" source="MS">MS99-016</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0716" published="1999-05-17" name="CVE-1999-0716" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in Windows NT 4.0 help file utility via a malformed help file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-015.asp" source="MS" patch="1" adv="1">MS99-015</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q231605" source="MSKB">Q231605</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0717" published="1999-05-07" name="CVE-1999-0717" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">A remote attacker can disable the virus warning mechanism in Microsoft Excel 97.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q231304" source="MSKB">Q231304</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-014.mspx" source="MS">MS99-014</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_95">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0718" published="2001-03-12" name="CVE-1999-0718" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">IBM GINA, when used for OS/2 domain authentication of Windows NT users, allows local users to gain administrator privileges by changing the GroupMapping registry key.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3166.php" source="XF" patch="1" adv="1">ibm-gina-group-add</ref>
      <ref url="http://www.securityfocus.com/bid/608" source="BID" patch="1" adv="1">608</ref>
      <ref url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind9908&amp;L=ntbugtraq&amp;F=&amp;S=&amp;P=5534" source="NTBUGTRAQ">19990823 IBM Gina security warning</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="gina">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0719" published="1999-08-05" name="CVE-1999-0719" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The Guile plugin for the Gnumeric spreadsheet package allows attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/563" source="BID">563</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="gnumeric">
        <vers num="0.27" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0720" published="1999-08-23" name="CVE-1999-0720" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The pt_chown command in Linux allows local users to modify TTY terminal devices that belong to other users.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=lcamtuf.4.05.9907041223290.355-300000@nimue.ids.pl" source="BUGTRAQ">19990823 [Linux] glibc 2.1.x / wu-ftpd &lt;=2.5 / BeroFTPD / lynx / vlock / mc / glibc 2.0.x</ref>
      <ref url="http://www.securityfocus.com/bid/597" source="BID">597</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.20.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0721" published="1999-07-20" name="CVE-1999-0721" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Denial of service in Windows NT Local Security Authority (LSA) through a malformed LSA request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-020.mspx" source="MS" patch="1">MS99-020</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/j-049.shtml" source="CIAC">J-049</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q231457" source="MSKB">Q231457</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0722" published="1999-08-08" name="CVE-1999-0722" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The default configuration of Cobalt RaQ2 servers allows remote users to install arbitrary software packages.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/558" source="BID">558</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="cobalt_raq_2">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0723" published="1999-06-23" name="CVE-1999-0723" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The Windows NT Client Server Runtime Subsystem (CSRSS) can be subjected to a denial of service when all worker threads are waiting for user input.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-021.mspx" source="MS" patch="1">MS99-021</ref>
      <ref url="http://www.securityfocus.com/bid/478" source="BID">478</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/j-049.shtml" source="CIAC">J-049</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q233323" source="MSKB">Q233323</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="sp5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0724" published="1999-08-12" name="CVE-1999-0724" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in OpenBSD procfs and fdescfs file systems via uio_offset in the readdir() function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/6128" source="OSVDB">6128</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0725" published="1999-08-19" name="CVE-1999-0725" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:N/A:N)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. "Double Byte Code Page".</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <env />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/2302" source="XF">iis-double-byte-code-page(2302)</ref>
      <ref url="http://www.securityfocus.com/bid/477" source="BID">477</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-022.mspx" source="MS">MS99-022</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q233335" source="MSKB">Q233335</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="3.0" edition="unknown" />
        <vers num="3.0" edition="unknown:unknown" />
        <vers num="3.0" edition="unknown:unknown:japanese" />
        <vers num="3.0" edition="unknown:unknown:chinese" />
        <vers num="3.0" edition="unknown:unknown:korean" />
        <vers num="4.0" edition="unknown" />
        <vers num="4.0" edition="unknown:unknown" />
        <vers num="4.0" edition="unknown:unknown:korean" />
        <vers num="4.0" edition="unknown:unknown:japanese" />
        <vers num="4.0" edition="unknown:unknown:chinese" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0726" published="1999-06-30" name="CVE-1999-0726" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">An attacker can conduct a denial of service in Windows NT by executing a program with a malformed file image header.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/499" source="BID">499</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-023.mspx" source="MS">MS99-023</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q234557" source="MSKB">Q234557</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition="sp4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0727" published="1999-08-06" name="CVE-1999-0727" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">A kernel leak in the OpenBSD kernel allows IPsec packets to be sent unencrypted.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/6127" source="OSVDB">6127</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0728" published="1999-07-06" name="CVE-1999-0728" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">A Windows NT user can disable the keyboard or mouse by directly calling the IOCTLs which control them.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <access />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-024.mspx" source="MS" patch="1">MS99-024</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q236359" source="MSKB">Q236359</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:enterprise" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0729" published="2001-03-12" name="CVE-1999-0729" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Lotus Notes LDAP (NLDAP) allows an attacker to conduct a denial of service through the ldap_search request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/alerts/advise34.php" source="ISS" adv="1">19990823 Denial of Service Attack against Lotus Notes Domino Server 4.6</ref>
      <ref url="http://www.securityfocus.com/bid/601" source="BID" adv="1">601</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/j-061.shtml" source="CIAC" adv="1">J-061</ref>
      <ref url="http://www.osvdb.org/1057" source="OSVDB">1057</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino_server">
        <vers num="4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0730" published="1999-06-12" name="CVE-1999-0730" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The zsoelim program in the Debian man-db package allows local users to overwrite files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0731" published="1999-06-23" name="CVE-1999-0731" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The KDE klock program allows local users to unlock a session using malformed input.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/489" source="BID">489</ref>
    </refs>
    <vuln_soft>
      <prod vendor="caldera" name="openlinux">
        <vers num="1.3" />
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0732" published="1999-08-19" name="CVE-1999-0732" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The logging facilitity of the Debian smtp-refuser package allows local users to delete arbitrary files using symbolic links.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0733" published="1999-06-26" name="CVE-1999-0733" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in VMWare 1.0.1 for Linux via a long HOME environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/490" source="BID">490</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="workstation">
        <vers num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0734" published="1999-08-19" name="CVE-1999-0734" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">A default configuration of CiscoSecure Access Control Server (ACS) allows remote users to modify the server database without authentication.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="cisco" name="ciscosecure">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0735" published="2000-01-04" name="CVE-1999-0735" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">KDE K-Mail allows local users to gain privileges via a symlink attack in temporary user directories.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/300" source="BID" patch="1">300</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA1999015_01.html" source="REDHAT">RHSA-1999:015-01</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="k-mail">
        <vers prev="1" num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0736" published="1999-05-07" name="CVE-1999-0736" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The showcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-013.asp" source="MS" patch="1" adv="1">MS99-013</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:932" source="OVAL" sig="1">oval:org.mitre.oval:def:932</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0737" published="1999-05-07" name="CVE-1999-0737" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The viewcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-013.asp" source="MS" patch="1" adv="1">MS99-013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0738" published="1999-05-07" name="CVE-1999-0738" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The code.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-013.asp" source="MS" patch="1" adv="1">MS99-013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0739" published="1999-05-07" name="CVE-1999-0739" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The codebrws.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-013.asp" source="MS" patch="1" adv="1">MS99-013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0740" published="1999-08-19" name="CVE-1999-0740" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Remote attackers can cause a denial of service on Linux in.telnetd telnet daemon through a malformed TERM environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/594" source="BID">594</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="4.2" />
        <vers num="5.2" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0741" published="1999-08-19" name="CVE-1999-0741" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">QMS CrownNet Unix Utilities for 2060 allows root to log on without a password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/593" source="BID">593</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qms" name="crownnet_unix_utilities">
        <vers num="2060" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0742" published="1999-06-22" name="CVE-1999-0742" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Debian mailman package uses weak authentication, which allows attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/480" source="BID">480</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0743" published="1999-08-20" name="CVE-1999-0743" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Trn allows local users to overwrite other users' files via symlinks.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/3144" source="XF">trn-symlinks(3144)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0744" published="2000-01-04" name="CVE-1999-0744" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Netscape Enterprise Server and FastTrask Server allows remote attackers to gain privileges via a long HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/603" source="BID">603</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="enterprise_server">
        <vers num="" />
      </prod>
      <prod vendor="netscape" name="fasttrack_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0745" published="1999-08-18" name="CVE-1999-0745" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Source Code Browser Program Database Name Server Daemon (pdnsd) for the IBM AIX C Set ++ compiler.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/590" source="BID">590</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/j-059.shtml" source="CIAC">J-059</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="2.2.1" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.2.4" />
        <vers num="3.2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0746" published="1999-08-16" name="CVE-1999-0746" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">A default configuration of in.identd in SuSE Linux waits 120 seconds between requests, allowing a remote attacker to conduct a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/587" source="BID">587</ref>
    </refs>
    <vuln_soft>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="3.2" />
        <vers num="3.6" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="4.4" />
        <vers num="4.4.1" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="5.3" />
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0747" published="1999-08-18" name="CVE-1999-0747" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Denial of service in BSDi Symmetric Multiprocessing (SMP) when an fstat call is made when the system has a high CPU load.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.BSI.4.10.9908170253560.19291-100000@saturn.psn.net" source="BUGTRAQ">19990816 Symmetric Multiprocessing (SMP) Vulnerbility in BSDi 4.0.1</ref>
      <ref url="http://www.securityfocus.com/bid/589" source="BID">589</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bsdi" name="bsd_os">
        <vers num="4.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0748" published="1999-06-24" name="CVE-1999-0748" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflows in Red Hat net-tools package.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0749" published="1999-08-16" name="CVE-1999-0749" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Telnet client in Windows 95 and Windows 98 via a malformed Telnet argument.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/586" source="BID">586</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-033.mspx" source="MS">MS99-033</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_95">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0750" published="1999-09-13" name="CVE-1999-0750" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Hotmail allows Javascript to be executed via the HTML STYLE tag, allowing remote attackers to execute commands on the user's Hotmail account.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/630" source="BID">630</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="hotmail">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0751" published="1999-09-13" name="CVE-1999-0751" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Accept command in Netscape Enterprise Server 3.6 with the SSL Handshake Patch.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/3256" source="XF">netscape-accept-bo(3256)</ref>
      <ref url="http://www.securityfocus.com/bid/631" source="BID">631</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="enterprise_server">
        <vers num="3.5.1" />
        <vers num="3.6" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0752" published="1999-07-06" name="CVE-1999-0752" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service in Netscape Enterprise Server via a buffer overflow in the SSL handshake.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="netscape" name="enterprise_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0753" published="1999-08-17" name="CVE-1999-0753" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The w3-msql CGI script provided with Mini SQL allows remote attackers to view restricted directories.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/591" source="BID">591</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hughes" name="msql">
        <vers num="2.0" />
        <vers num="2.0.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0754" published="1999-05-11" name="CVE-1999-0754" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The INN inndstart program allows local users to gain privileges by specifying an alternate configuration file using the INNCONF environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/corp/support/errata/inn99_05_22.html" source="MISC" patch="1" adv="1">http://www.redhat.com/corp/support/errata/inn99_05_22.html</ref>
      <ref url="http://www.securityfocus.com/bid/255" source="BID">255</ref>
      <ref url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-011.0.txt" source="CALDERA">CSSA-1999-011.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="inn">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0755" published="1999-05-27" name="CVE-1999-0755" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Windows NT RRAS and RAS clients cache a user's password even if the user has not selected the "Save password" option.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-017.mspx" source="MS">MS99-017</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q230681" source="MSKB">Q230681</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0756" published="2001-03-12" name="CVE-1999-0756" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ColdFusion Administrator with Advanced Security enabled allows remote users to stop the ColdFusion server via the Start/Stop utility.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2207.php" source="XF" patch="1" adv="1">coldfusion-admin-dos(2207)</ref>
      <ref url="http://www.allaire.com/handlers/index.cfm?ID=10968&amp;Method=Full" source="ALLAIRE" adv="1">ASB99-07</ref>
    </refs>
    <vuln_soft>
      <prod vendor="allaire" name="coldfusion_server">
        <vers num="4.0" />
        <vers num="4.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0757" published="2001-03-12" name="CVE-1999-0757" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The ColdFusion CFCRYPT program for encrypting CFML templates has weak encryption, allowing attackers to decrypt the templates.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2208.php" source="XF" adv="1">coldfusion-encryption</ref>
      <ref url="http://www.allaire.com/handlers/index.cfm?ID=10969&amp;Method=Full" source="ALLAIRE" adv="1">ASB99-08</ref>
    </refs>
    <vuln_soft>
      <prod vendor="allaire" name="coldfusion_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0758" published="2001-03-12" name="CVE-1999-0758" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Netscape Enterprise 3.5.1 and FastTrack 3.01 servers allow a remote attacker to view source code to scripts by appending a %20 to the script's URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="netscape" name="enterprise_server">
        <vers num="3.5.1" />
      </prod>
      <prod vendor="netscape" name="fasttrack_server">
        <vers num="3.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0759" published="1999-09-13" name="CVE-1999-0759" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in FuseMAIL POP service via long USER and PASS commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.crosswinds.net/~fuseware/faq.html#8" source="CONFIRM">http://www.crosswinds.net/~fuseware/faq.html#8</ref>
      <ref url="http://www.securityfocus.com/bid/634" source="BID">634</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fuseware" name="fusemail">
        <vers num="2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0760" published="2001-03-12" name="CVE-1999-0760" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Undocumented ColdFusion Markup Language (CFML) tags and functions in the ColdFusion Administrator allow users to gain additional privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/550" source="BID" patch="1" adv="1">550</ref>
      <ref url="http://xforce.iss.net/static/3288.php" source="XF" adv="1">coldfusion-server-cfml-tags</ref>
      <ref url="http://www.allaire.com/handlers/index.cfm?ID=11714&amp;Method=Full" source="ALLAIRE">ASB99-10</ref>
    </refs>
    <vuln_soft>
      <prod vendor="allaire" name="coldfusion_server">
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.1" />
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers num="4.0" />
        <vers num="4.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0761" published="2000-09-16" name="CVE-1999-0761" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in FreeBSD fts library routines allows local user to modify arbitrary files via the periodic program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/644" source="BID">644</ref>
      <ref url="http://www.osvdb.org/1074" source="OSVDB">1074</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="1.1.5.1" />
        <vers num="2.0" />
        <vers num="2.0.5" />
        <vers num="2.1.0" />
        <vers num="2.1.5" />
        <vers num="2.1.7.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.8" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0762" published="1999-05-24" name="CVE-1999-0762" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">When Javascript is embedded within the TITLE tag, Netscape Communicator allows a remote attacker to use the "about" protocol to gain access to browser information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="netscape" name="communicator">
        <vers num="4.6" edition="" />
        <vers num="4.6" edition=":windows_95" />
        <vers num="4.x" />
      </prod>
      <prod vendor="netscape" name="navigator">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0763" published="1999-05-01" name="CVE-1999-0763" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">NetBSD on a multi-homed host allows ARP packets on one network to modify ARP entries on another connected network.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/6540" source="OSVDB">6540</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0764" published="1999-05-01" name="CVE-1999-0764" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">NetBSD allows ARP packets to overwrite static ARP entries.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/6539" source="OSVDB">6539</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0765" published="1999-05-19" name="CVE-1999-0765" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SGI IRIX midikeys program allows local users to modify arbitrary files via a text editor.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/262" source="BID">262</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19990501-01-A" source="SGI">19990501-01-A</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0766" published="1999-10-21" name="CVE-1999-0766" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The Microsoft Java Virtual Machine allows a malicious Java applet to execute arbitrary commands outside of the sandbox environment.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/600" source="BID">600</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-031.mspx" source="MS">MS99-031</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q240346" source="MSKB">Q240346</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="java_virtual_machine">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0767" published="1999-09-08" name="CVE-1999-0767" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Solaris libc, ufsrestore, and rcp via LC_MESSAGES environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0768" published="1999-08-25" name="CVE-1999-0768" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Vixie Cron on Red Hat systems via the MAILTO environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/602" source="BID">602</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="4.2" />
        <vers num="5.2" edition="" />
        <vers num="5.2" edition=":i386" />
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":i386" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="6.0" />
        <vers num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0769" published="1999-08-25" name="CVE-1999-0769" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vixie Cron on Linux systems allows local users to set parameters of sendmail commands via the MAILTO environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/611" source="BID">611</ref>
    </refs>
    <vuln_soft>
      <prod vendor="paul_vixie" name="vixie_cron">
        <vers num="3.0_pl1" />
      </prod>
      <prod vendor="caldera" name="openlinux">
        <vers num="2.2" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" edition="" />
        <vers num="5.2" edition=":i386" />
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0770" published="1999-07-29" name="CVE-1999-0770" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Firewall-1 sets a long timeout for connections that begin with ACK or other packets except SYN, allowing an attacker to conduct a denial of service via a large number of connection attempts to unresponsive systems.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/549" source="BID" patch="1" adv="1">549</ref>
      <ref url="http://www.osvdb.org/1027" source="OSVDB">1027</ref>
    </refs>
    <vuln_soft>
      <prod vendor="checkpoint" name="firewall-1">
        <vers num="3.0" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0771" published="1999-05-26" name="CVE-1999-0771" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The web components of Compaq Management Agents and the Compaq Survey Utility allow a remote attacker to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="compaq" name="insight_management_agent">
        <vers num="" />
      </prod>
      <prod vendor="compaq" name="power_management">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0772" published="1999-06-01" name="CVE-1999-0772" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Denial of service in Compaq Management Agents and the Compaq Survey Utility via a long string sent to port 2301.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="compaq" name="insight_management_agent">
        <vers num="" />
      </prod>
      <prod vendor="compaq" name="power_management">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0773" published="1999-05-11" name="CVE-1999-0773" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Solaris lpset program allows local users to gain root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.netspace.org/cgi-bin/wa?A2=ind9905B&amp;L=bugtraq&amp;P=R2017" source="BUGTRAQ">19990511 Solaris2.6 and 2.7 lpset overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0774" published="1999-08-31" name="CVE-1999-0774" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflows in Mars NetWare Emulation (NWE, mars_nwe) package via long directory names.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/617" source="BID">617</ref>
    </refs>
    <vuln_soft>
      <prod vendor="martin_stover" name="mars_nwe">
        <vers num="0.99" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0775" published="1999-06-10" name="CVE-1999-0775" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Cisco Gigabit Switch routers running IOS allow remote attackers to forward unauthorized packets due to improper handling of the "established" keyword in an access list.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="11.2(14)gs2" />
        <vers num="11.2(15)g" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0776" published="1999-05-12" name="CVE-1999-0776" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Alibaba HTTP server allows remote attackers to read files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind9905&amp;L=NTBUGTRAQ&amp;P=R1533" source="NTBUGTRAQ" adv="1">19990506 ".."-hole in Alibaba 2.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="computer_software_manufaktur" name="alibaba">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0777" published="1999-09-23" name="CVE-1999-0777" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">IIS FTP servers may allow a remote attacker to read or delete files on the server, even if they have "No Access" permissions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/658" source="BID">658</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-039.asp" source="MS">MS99-039</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q242559" source="MSKB">Q242559</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q241407" source="MSKB">Q241407</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="commercial_internet_system">
        <vers num="2.5" />
      </prod>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0778" published="1999-06-25" name="CVE-1999-0778" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Xi Graphics Accelerated-X server allows local users to gain root access via a long display or query parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/488" source="BID">488</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xi_graphics" name="accelerated-x_server">
        <vers num="4" />
        <vers num="5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0779" published="1998-09-03" name="CVE-1999-0779" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service in HP-UX SharedX recserv program.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9810-086" source="HP">HPSBUX9810-086</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.01" />
        <vers num="10.10" />
        <vers num="10.20" />
        <vers num="11.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0780" published="1998-11-18" name="CVE-1999-0780" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">KDE klock allows local users to kill arbitrary processes by specifying an arbitrary PID in the .kss.pid file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91141486301691&amp;w=2" source="BUGTRAQ">19981118 Multiple KDE security vulnerabilities (root compromise)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="6.2" edition="stable" />
      </prod>
      <prod vendor="kde" name="kde">
        <vers num="1.0" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.20.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0781" published="1998-11-18" name="CVE-1999-0781" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">KDE allows local users to execute arbitrary commands by setting the KDEDIR environmental variable to modify the search path that KDE uses to locate its executables.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91141486301691&amp;w=2" source="BUGTRAQ">19981118 Multiple KDE security vulnerabilities (root compromise)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="6.2" edition="stable" />
      </prod>
      <prod vendor="kde" name="kde">
        <vers num="1.0" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.20.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0782" published="1998-11-18" name="CVE-1999-0782" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">KDE kppp allows local users to create a directory in an arbitrary location via the HOME environmental variable.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91141486301691&amp;w=2" source="BUGTRAQ">19981118 Multiple KDE security vulnerabilities (root compromise)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="6.2" edition="stable" />
      </prod>
      <prod vendor="kde" name="kde">
        <vers num="1.0" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.20.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0783" published="1998-06-16" name="CVE-1999-0783" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">FreeBSD allows local users to conduct a denial of service by creating a hard link from a device special file to a file on an NFS file system.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/6090" source="OSVDB">6090</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/i-057.shtml" source="CIAC">I-057</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0784" published="2001-03-12" name="CVE-1999-0784" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service in Oracle TNSLSNR SQL*Net Listener via a malformed string to the listener port, aka NERP.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/1998/msg00536.html" source="NTBUGTRAQ">19980827 NERP DoS attack possible in Oracle</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/1999_1/0056.html" source="BUGTRAQ" adv="1">19990104 Re: Fw:"NERP" DoS attack possible in Oracle</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/1998_4/0764.html" source="BUGTRAQ" adv="1">19981228 Oracle8 TNSLSNR DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="7.1.4" />
        <vers num="7.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0785" published="1999-05-11" name="CVE-1999-0785" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The INN inndstart program allows local users to gain root privileges via the "pathrun" parameter in the inn.conf file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/254" source="BID">254</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="inn">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0786" published="1999-09-22" name="CVE-1999-0786" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The dynamic linker in Solaris allows a local user to create arbitrary files via the LD_PROFILE environmental variable and a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/659" source="BID">659</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0787" published="1999-09-17" name="CVE-1999-0787" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The SSH authentication agent follows symlinks via a UNIX domain socket.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/660" source="BID">660</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93832856804415&amp;w=2" source="BUGTRAQ">19990924 [Fwd: Truth about ssh 1.2.27 vulnerability]</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93760201002154&amp;w=2" source="BUGTRAQ">19990917 A few bugs...</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ssh" name="ssh">
        <vers num="1.2.27" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0788" published="1999-09-26" name="CVE-1999-0788" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Arkiea nlservd allows remote attackers to conduct a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/662" source="BID">662</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93837184228248&amp;w=2" source="BUGTRAQ">19990924 Multiple vendor Knox Arkiea local root/remote DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="knox_software" name="arkeia">
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0789" published="1999-09-28" name="CVE-1999-0789" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in AIX ftpd in the libc library.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/679" source="BID">679</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/j-072.shtml" source="CIAC">J-072</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0790" published="2000-04-01" name="CVE-1999-0790" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">A remote attacker can read information from a Netscape user's cache via JavaScript.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://home.netscape.com/security/notes/jscachebrowsing.html" source="MISC">http://home.netscape.com/security/notes/jscachebrowsing.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="communicator">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0791" published="1999-10-06" name="CVE-1999-0791" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Hybrid Network cable modems do not include an authentication mechanism for administration, allowing remote attackers to compromise the system through the HSMP protocol.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/695" source="BID">695</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hybrid_network" name="hsmp">
        <vers num="" />
      </prod>
      <prod vendor="hybrid_network" name="cable_modem">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0792" published="1998-09-01" name="CVE-1999-0792" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ROUTERmate has a default SNMP community name which allows remote attackers to modify its configuration.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www2.merton.ox.ac.uk/~security/rootshell/0022.html" source="MISC">http://www2.merton.ox.ac.uk/~security/rootshell/0022.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="osicom" name="routermate">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0793" published="1999-11-17" name="CVE-1999-0793" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Internet Explorer allows remote attackers to read files by redirecting data to a Javascript applet.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-043.mspx" source="MS">MS99-043</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.0.1" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0794" published="1999-10-01" name="CVE-1999-0794" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Microsoft Excel does not warn a user when a macro is present in a Symbolic Link (SYLK) format file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-044.mspx" source="MS">MS99-044</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q241902" source="MSKB">Q241902</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q241901" source="MSKB">Q241901</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q241900" source="MSKB">Q241900</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0795" published="1998-03-01" name="CVE-1999-0795" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The NIS+ rpc.nisd server allows remote attackers to execute certain RPC calls without authentication to obtain system information, disable logging, or modify caches.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0796" published="1998-05-01" name="CVE-1999-0796" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">FreeBSD T/TCP Extensions for Transactions can be subjected to spoofing attacks.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/6089" source="OSVDB">6089</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="2.1.0" />
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0797" published="1998-06-29" name="CVE-1999-0797" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">NIS finger allows an attacker to conduct a denial of service via a large number of finger requests, resulting in a large number of NIS queries.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <env />
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ciac.org/ciac/bulletins/i-070.shtml" source="CIAC">I-070</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0798" published="1998-12-04" name="CVE-1999-0798" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in bootpd on OpenBSD, FreeBSD, and Linux systems via a malformed header type.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91278867118128&amp;w=2" source="BUGTRAQ" adv="1">19981204 bootpd remote vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bsdi" name="bsd_os">
        <vers num="" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="6.2" edition="stable" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.3" />
        <vers num="2.4" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="sco" name="internet_faststart">
        <vers num="" />
      </prod>
      <prod vendor="sco" name="openserver">
        <vers num="" />
      </prod>
      <prod vendor="sco" name="unixware">
        <vers num="7.0" />
        <vers num="7.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0799" published="1997-06-01" name="CVE-1999-0799" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in bootpd 2.4.3 and earlier via a long boot file location.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="cmu" name="bootpd">
        <vers prev="1" num="2.4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0800" published="2001-03-12" name="CVE-1999-0800" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The GetFile.cfm file in Allaire Forums allows remote attackers to read files through a parameter to GetFile.cfm.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.allaire.com/handlers/index.cfm?ID=9602&amp;Method=Full" source="ALLAIRE" patch="1" adv="1">ASB99-05</ref>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/1998-1999/msg00332.html" source="NTBUGTRAQ" adv="1">19990211 ACFUG List: Alert: Allaire Forums GetFile bug</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/1748" source="XF">allaire-forums-file-read(1748)</ref>
      <ref url="http://www.osvdb.org/944" source="OSVDB">944</ref>
    </refs>
    <vuln_soft>
      <prod vendor="allaire" name="forums">
        <vers prev="1" num="2.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0801" published="1999-04-09" name="CVE-1999-0801" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">BMC Patrol allows remote attackers to gain access to an agent by spoofing frames.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/13204" source="BUGTRAQ">19990409 Patrol security bugs</ref>
      <ref url="http://www.iss.net/security_center/static/2075.php" source="XF">bmc-patrol-frames(2075)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bmc" name="patrol_agent">
        <vers num="3.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0802" published="1999-05-27" name="CVE-1999-0802" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Buffer overflow in Internet Explorer 5 allows remote attackers to execute commands via a malformed Favorites icon.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-018.mspx" source="MS">MS99-018</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q231450" source="MSKB">Q231450</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0803" published="1999-05-25" name="CVE-1999-0803" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The fwluser script in AIX eNetwork Firewall allows local users to write to arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/962" source="OSVDB">962</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92765973207648&amp;w=2" source="BUGTRAQ">19990525 IBM eNetwork Firewall for AIX</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix_enetwork_firewall">
        <vers num="3.2" />
        <vers num="3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0804" published="1999-06-01" name="CVE-1999-0804" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service in Linux 2.2.x kernels via malformed ICMP packets containing unusual types, codes, and IP header lengths.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/302" source="BID">302</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.1" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.2.0" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":i386" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0805" published="2001-03-12" name="CVE-1999-0805" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Novell NetWare Transaction Tracking System (TTS) in Novell 4.11 and earlier allows remote attackers to cause a denial of service via a large number of requests.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2184.php" source="XF" adv="1">novell-tts-dos</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/1999_2/0439.html" source="BUGTRAQ" adv="1">19990512 DoS with Netware 4.x's TTS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="netware">
        <vers prev="1" num="4.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0806" published="1999-05-10" name="CVE-1999-0806" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Solaris dtprintinfo program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/6552" source="OSVDB">6552</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0807" published="1999-05-01" name="CVE-1999-0807" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The Netscape Directory Server installation procedure leaves sensitive information in a file that is accessible to local users.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="netscape" name="directory_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0808" published="1999-12-31" name="CVE-1999-0808" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in ISC DHCP Distribution server (dhcpd) 1.0 and 2.0 allow a remote attacker to cause a denial of service (crash) and possibly execute arbitrary commands via long options.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/i-053.shtml" source="CIAC" patch="1" adv="1">I-053</ref>
      <ref url="ftp://ftp.isc.org/isc/dhcp/dhcp-1.0-history/dhcp-1.0.0-1.0pl1.diff.gz" source="MISC" patch="1">ftp://ftp.isc.org/isc/dhcp/dhcp-1.0-history/dhcp-1.0.0-1.0pl1.diff.gz</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101925960&amp;w=2" source="BUGTRAQ">19980518 DHCP 1.0 and 2.0 SECURITY ALERT! (fwd)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="dhcp_client">
        <vers num="1.0" />
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0809" published="1999-07-09" name="CVE-1999-0809" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Netscape Communicator 4.x with Javascript enabled does not warn a user of cookie settings, even if they have selected the option to "Only accept cookies originating from the same server as the page being viewed".</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="netscape" name="communicator">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0810" published="1999-07-21" name="CVE-1999-0810" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Denial of service in Samba NETBIOS name service daemon (nmbd).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="2.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0811" published="1999-07-21" name="CVE-1999-0811" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Samba smbd program via a malformed message command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/536" source="BID">536</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="2.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0812" published="2000-07-12" name="CVE-1999-0812" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Race condition in Samba smbmnt allows local users to mount file systems in arbitrary locations.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="2.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0813" published="1999-08-10" name="CVE-1999-0813" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Cfingerd with ALLOW_EXECUTION enabled does not properly drop privileges when it executes a program on behalf of the user, allowing local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="infodrom" name="cfingerd">
        <vers prev="1" num="1.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0814" published="1999-08-11" name="CVE-1999-0814" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Red Hat pump DHCP client allows remote attackers to gain root access in some configurations.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-1999-027.html" source="REDHAT">RHSA-1999:027</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0815" published="1999-12-31" name="CVE-1999-0815" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Memory leak in SNMP agent in Windows NT 4.0 before SP5 allows remote attackers to conduct a denial of service (memory exhaustion) via a large number of queries.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/support/kb/articles/q196/2/70.asp" source="MSKB" patch="1" adv="1">Q196270</ref>
      <ref url="http://xforce.iss.net/static/1974.php" source="XF">nt-snmpagent-leak(1974)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:952" source="OVAL" sig="1">oval:org.mitre.oval:def:952</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers prev="1" num="4.0" edition="" />
        <vers prev="1" num="4.0" edition=":server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0816" published="1998-05-10" name="CVE-1999-0816" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Motorola CableRouter allows any remote user to connect to and configure the router on port 1024.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.netspace.org/cgi-bin/wa?A2=ind9805B&amp;L=bugtraq&amp;P=R1621" source="BUGTRAQ" adv="1">19980510 Security Vulnerability in Motorola CableRouters</ref>
    </refs>
    <vuln_soft>
      <prod vendor="motorola" name="motorola_cablerouter">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0817" published="1999-09-15" name="CVE-1999-0817" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Lynx WWW client allows a remote attacker to specify command-line parameters which Lynx uses when calling external programs to handle certain protocols, e.g. telnet.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="university_of_kansas" name="lynx">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0818" published="1999-11-20" name="CVE-1999-0818" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Solaris kcms_configure via a long NETPATH environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/831" source="BID">831</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=38433B7F5A.53F4SHADOWPENGUIN@fox.nightland.net" source="BUGTRAQ">19991130 another hole of Solaris7 kcms_configure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0819" published="1999-12-01" name="CVE-1999-0819" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">NTMail does not disable the VRFY command, even if the administrator has explicitly disabled it.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94398141118586&amp;w=2" source="BUGTRAQ">19991130 NTmail and VRFY</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0820" published="1999-12-01" name="CVE-1999-0820" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">FreeBSD seyon allows users to gain privileges via a modified PATH variable for finding the xterm and seyon-emu commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/838" source="BID">838</ref>
      <ref url="http://www.osvdb.org/5996" source="OSVDB">5996</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0821" published="1999-11-08" name="CVE-1999-0821" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">FreeBSD seyon allows local users to gain privileges by providing a malicious program in the -emulator argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/838" source="BID">838</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0822" published="1999-11-30" name="CVE-1999-0822" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Qpopper (qpop) 3.0 allows remote root access via AUTH command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/830" source="BID">830</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qualcomm" name="qpopper">
        <vers num="3.0" />
        <vers num="3.0b20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0823" published="1999-12-01" name="CVE-1999-0823" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in FreeBSD xmindpath allows local users to gain privileges via -f argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/839" source="BID">839</ref>
      <ref url="http://www.osvdb.org/1150" source="OSVDB">1150</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0824" published="1999-11-30" name="CVE-1999-0824" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">A Windows NT user can use SUBST to map a drive letter to a folder, which is not unmapped after the user logs off, potentially allowing that user to modify the location of folders accessed by later users.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/833" source="BID">833</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0825" published="1999-12-03" name="CVE-1999-0825" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">The default permissions for UnixWare /var/mail allow local users to read and modify other users' mail.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/849" source="BID">849</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="unixware">
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0826" published="1999-12-01" name="CVE-1999-0826" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in FreeBSD angband allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/840" source="BID">840</ref>
      <ref url="http://www.osvdb.org/1151" source="OSVDB">1151</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0827" published="1999-11-01" name="CVE-1999-0827" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="3.0" />
        <vers num="3.0.2" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="4.0" edition="a_mac_os" />
        <vers num="4.0.1" edition="sp2" />
        <vers num="4.1" />
        <vers num="4.5" />
        <vers num="5.0" />
      </prod>
      <prod vendor="netscape" name="navigator">
        <vers prev="1" num="4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0828" published="1999-12-02" name="CVE-1999-0828" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">UnixWare pkg commands such as pkginfo, pkgcat, and pkgparam allow local users to read arbitrary files via the dacread permission.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/853" source="BID">853</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="unixware">
        <vers num="7.0" />
        <vers num="7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0829" published="1999-11-01" name="CVE-1999-0829" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">HP Secure Web Console uses weak encryption.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="hp" name="secure_web_console">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0830" published="1999-11-01" name="CVE-1999-0830" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in SCO UnixWare Xsco command via a long argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sco" name="unixware">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0831" published="1999-11-19" name="CVE-1999-0831" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service in Linux syslogd via a large number of connections.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/809" source="BID">809</ref>
      <ref url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-035.0.txt" source="CALDERA">CSSA-1999-035.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cobalt" name="qube">
        <vers num="1.0" />
        <vers num="2.0" />
      </prod>
      <prod vendor="sun" name="cobalt_raq">
        <vers num="1.1" />
      </prod>
      <prod vendor="sun" name="cobalt_raq_2">
        <vers num="" />
      </prod>
      <prod vendor="sun" name="cobalt_raq_3i">
        <vers num="" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.2" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="6.2" />
        <vers num="6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0832" published="1999-11-09" name="CVE-1999-0832" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in NFS server on Linux allows attackers to execute commands via a long pathname.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.20.9911091058140.12964-100000@mail.zigzag.pl" source="BUGTRAQ">19991109 undocumented bugs - nfsd</ref>
      <ref url="http://www.securityfocus.com/bid/782" source="BID">782</ref>
      <ref url="http://www.redhat.com/support/errata/rh42-errata-general.html#NFS" source="REDHAT">RHSA-1999:053-01</ref>
      <ref url="http://www.novell.com/linux/security/advisories/suse_security_announce_29.html" source="SUSE">19991110 Security hole in nfs-server &lt; 2.2beta47 within nkita</ref>
      <ref url="http://www.debian.org/security/1999/19991111" source="DEBIAN">19991111 buffer overflow in nfs server</ref>
      <ref url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-033.0.txt" source="CALDERA">CSSA-1999-033.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.1" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="5.2" edition="" />
        <vers num="5.2" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0833" published="1999-11-10" name="CVE-1999-0833" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in BIND 8.2 via NXT records.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/788" source="BID">788</ref>
      <ref url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt" source="CALDERA">CSSA-1999-034.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="bind">
        <vers num="8.2" />
        <vers num="8.2.1" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0834" published="1999-12-01" name="CVE-1999-0834" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in RSAREF2 via the encryption and decryption functions in the RSAREF library.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/843" source="BID">843</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rsa" name="rsaref">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0835" published="1999-11-10" name="CVE-1999-0835" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Denial of service in BIND named via malformed SIG records.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/788" source="BID">788</ref>
      <ref url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt" source="CALDERA">CSSA-1999-034.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.3" />
      </prod>
      <prod vendor="sco" name="openserver">
        <vers num="5" />
      </prod>
      <prod vendor="sco" name="unixware">
        <vers num="2" />
        <vers num="7" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0836" published="1998-12-02" name="CVE-1999-0836" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">UnixWare uidadmin allows local users to modify arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=19991202160111.20553.qmail@nwcst282.netaddress.usa.net" source="BUGTRAQ">19991202 UnixWare 7 uidadmin exploit + discussion</ref>
      <ref url="http://www.securityfocus.com/bid/842" source="BID">842</ref>
      <ref url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.22a" source="SCO">SB-99.22a</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="unixware">
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.1" />
        <vers num="7.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0837" published="1999-11-10" name="CVE-1999-0837" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Denial of service in BIND by improperly closing TCP sessions via so_linger.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/788" source="BID">788</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/194" source="SUN">00194</ref>
      <ref url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt" source="CALDERA">CSSA-1999-034.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="bind">
        <vers num="8.2" />
        <vers num="8.2.1" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0838" published="1999-12-01" name="CVE-1999-0838" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Serv-U FTP 2.5 allows remote users to conduct a denial of service via the SITE command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/859" source="BID">859</ref>
    </refs>
    <vuln_soft>
      <prod vendor="deerfield" name="serv-u_ftp-server">
        <vers num="2.5a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0839" published="1999-11-29" name="CVE-1999-0839" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Windows NT Task Scheduler installed with Internet Explorer 5 allows a user to gain privileges by modifying the job after it has been scheduled.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/828" source="BID">828</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-051.mspx" source="MS">MS99-051</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q246972" source="MSKB">Q246972</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5" edition="" />
        <vers num="5" edition=":windows_nt_4.0" />
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":windows_98" />
        <vers num="5.0" edition=":windows_95" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0840" published="1999-11-30" name="CVE-1999-0840" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in CDE dtmail and dtmailpr programs allows local users to gain privileges via a long -f option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/832" source="BID">832</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/3580" source="XF">solaris-dtmailpr-overflow(3580)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/3579" source="XF">solaris-dtmail-overflow(3579)</ref>
      <ref url="http://www.security-express.com/archives/bugtraq/1999-q4/0122.html" source="BUGTRAQ">19991129 Solaris7 dtmail/dtmailpr/mailtool Buffer Overflow</ref>
      <ref url="http://www.securiteam.com/exploits/3J5QQPPQ0O.html" source="MISC">http://www.securiteam.com/exploits/3J5QQPPQ0O.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0841" published="1999-11-30" name="CVE-1999-0841" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in CDE mailtool allows local users to gain root privileges via a long MIME Content-Type.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/832" source="BID">832</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/3732" source="XF">cde-mailtool-bo(3732)</ref>
      <ref url="http://www.security-express.com/archives/bugtraq/1999-q4/0122.html" source="BUGTRAQ">19991129 Solaris7 dtmail/dtmailpr/mailtool Buffer Overflow</ref>
      <ref url="http://www.securiteam.com/exploits/3J5QQPPQ0O.html" source="MISC">http://www.securiteam.com/exploits/3J5QQPPQ0O.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0842" published="1999-11-29" name="CVE-1999-0842" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Symantec Mail-Gear 1.0 web interface server allows remote users to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=NCBBKFKDOLAGKIAPMILPCEAFCBAA.labs@ussrback.com" source="BUGTRAQ">19991129 Symantec Mail-Gear 1.0 Web interface Server Directory Traversal Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/827" source="BID">827</ref>
      <ref url="http://www.osvdb.org/1144" source="OSVDB">1144</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="mail-gear">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0843" published="1999-11-04" name="CVE-1999-0843" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service in Cisco routers running NAT via a PORT command from an FTP client to a Telnet port.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="cisco" name="router">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0844" published="1999-11-24" name="CVE-1999-0844" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service in MDaemon WorldClient and WebConfig services via a long URL.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/823" source="BID">823</ref>
      <ref url="http://www.securityfocus.com/bid/820" source="BID">820</ref>
    </refs>
    <vuln_soft>
      <prod vendor="deerfield" name="mdaemon">
        <vers num="2.8.5" />
        <vers num="2.8.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0845" published="1999-11-25" name="CVE-1999-0845" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in SCO su program allows local users to gain root access via a long username.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sco" name="unixware">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0846" published="1999-12-01" name="CVE-1999-0846" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service in MDaemon 2.7 via a large number of connection attempts.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="deerfield" name="mdaemon">
        <vers num="2.8.5" />
        <vers num="2.8.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0847" published="1999-11-29" name="CVE-1999-0847" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in free internet chess server (FICS) program, xboard.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="freechess.org" name="fics_program">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0848" published="1999-11-10" name="CVE-1999-0848" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service in BIND named via consuming more than "fdmax" file descriptors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/788" source="BID">788</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/194" source="SUN">00194</ref>
      <ref url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt" source="CALDERA">CSSA-1999-034.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="bind">
        <vers num="8.2" />
        <vers num="8.2.1" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0849" published="1999-11-10" name="CVE-1999-0849" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service in BIND named via maxdname.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/788" source="BID">788</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/194" source="SUN">00194</ref>
      <ref url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt" source="CALDERA">CSSA-1999-034.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="bind">
        <vers num="4.9.5" edition="p1" />
        <vers num="4.9.6" />
        <vers num="4.9.7" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.2" edition="p1" />
        <vers num="8.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0850" published="1999-12-02" name="CVE-1999-0850" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">The default permissions for Endymion MailMan allow local users to read email or modify files.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/845" source="BID">845</ref>
    </refs>
    <vuln_soft>
      <prod vendor="endymion" name="mailman_webmail">
        <vers num="3.0.18" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0851" published="1999-11-10" name="CVE-1999-0851" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Denial of service in BIND named via naptr.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/788" source="BID">788</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/194" source="SUN">00194</ref>
      <ref url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt" source="CALDERA">CSSA-1999-034.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.3" />
      </prod>
      <prod vendor="sco" name="openserver">
        <vers num="5" />
      </prod>
      <prod vendor="sco" name="unixware">
        <vers num="2" />
        <vers num="7" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0852" published="1999-12-02" name="CVE-1999-0852" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">IBM WebSphere sets permissions that allow a local user to modify a deinstallation script or its data files stored in /usr/bin.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/844" source="BID">844</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0853" published="1999-12-01" name="CVE-1999-0853" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Netscape Enterprise Server and Netscape FastTrack Server allows remote attackers to gain privileges via the HTTP Basic Authentication procedure.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/847" source="BID">847</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="enterprise_server">
        <vers num="3.5.1" />
        <vers num="3.6" edition="sp2" />
      </prod>
      <prod vendor="netscape" name="fasttrack_server">
        <vers num="3.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0854" published="1999-11-01" name="CVE-1999-0854" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Ultimate Bulletin Board stores data files in the cgi-bin directory, allowing remote attackers to view the data if an error occurs when the HTTP server attempts to execute the file.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ultimatebb.com/home/versions.shtml" source="CONFIRM">http://www.ultimatebb.com/home/versions.shtml</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-22&amp;msg=NDBBLKOPOLNKELHPDEFKIEPGCAAA.renzo.toma@veronica.nl" source="BUGTRAQ">20000225 FW: Important UBB News For Licensed Users</ref>
    </refs>
    <vuln_soft>
      <prod vendor="infopop" name="ultimate_bulletin_board">
        <vers num="5.07" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0855" published="1999-12-01" name="CVE-1999-0855" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in FreeBSD gdc program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/834" source="BID">834</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0856" published="1999-12-01" name="CVE-1999-0856" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">login in Slackware 7.0 allows remote attackers to identify valid users on the system by reporting an encryption error when an account is locked or does not exist.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0857" published="1999-12-01" name="CVE-1999-0857" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">FreeBSD gdc program allows local users to modify files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/835" source="BID">835</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0858" published="1999-12-02" name="CVE-1999-0858" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Internet Explorer 5 allows a remote attacker to modify the IE client's proxy configuration via a malicious Web Proxy Auto-Discovery (WPAD) server.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/846" source="BID">846</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-054.mspx" source="MS">MS99-054</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q247333" source="MSKB">Q247333</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0859" published="1999-12-01" name="CVE-1999-0859" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Solaris arp allows local users to read files via the -f parameter, which lists lines in the file that do not parse properly.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/837" source="BID">837</ref>
      <ref url="http://www.osvdb.org/6994" source="OSVDB">6994</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":ppc" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="2.6" edition="hw3" />
        <vers num="2.6" edition="hw3:x86" />
        <vers num="2.6" edition="hw5" />
        <vers num="2.6" edition="hw5:x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0860" published="1999-12-01" name="CVE-1999-0860" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Solaris chkperm allows local users to read files owned by bin via the VMSYS environmental variable and a symlink attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/837" source="BID">837</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":ppc" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="2.6" edition="hw3" />
        <vers num="2.6" edition="hw3:x86" />
        <vers num="2.6" edition="hw5" />
        <vers num="2.6" edition="hw5:x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0861" published="1999-08-11" name="CVE-1999-0861" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-053.mspx" source="MS">MS99-053</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q244613" source="MSKB">Q244613</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="commercial_internet_system">
        <vers num="2.0" />
        <vers num="2.5" />
      </prod>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
      </prod>
      <prod vendor="microsoft" name="site_server">
        <vers num="3.0" />
      </prod>
      <prod vendor="microsoft" name="site_server_commerce">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0862" published="1999-12-02" name="CVE-1999-0862" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Insecure directory permissions in RPM distribution for PostgreSQL allows local users to gain privileges by reading a plaintext password file.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="postgresql" name="postgresql">
        <vers num="6.3.2" />
        <vers num="6.5.3" />
        <vers num="6.5.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0863" published="1999-11-08" name="CVE-1999-0863" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in FreeBSD seyon via HOME environmental variable, -emulator argument, -modems argument, or the GUI.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0864" published="1999-12-03" name="CVE-1999-0864" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">UnixWare programs that dump core allow a local user to modify files via a symlink attack on the ./core.pid file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=19991203020720.13115.qmail@nwcst289.netaddress.usa.net" source="BUGTRAQ">19991202 UnixWare coredumps follow symlinks</ref>
      <ref url="http://www.securityfocus.com/bid/851" source="BID">851</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94606167110764&amp;w=2" source="BUGTRAQ">19991223 FYI, SCO Security patches available.</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94581379905584&amp;w=2" source="BUGTRAQ">19991220 SCO OpenServer Security Status</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94530783815434&amp;w=2" source="BUGTRAQ">19991215 Recent postings about SCO UnixWare 7</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="unixware">
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.1" />
        <vers num="7.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0865" published="1999-12-03" name="CVE-1999-0865" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in CommuniGatePro via a long string to the HTTP configuration port.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/860" source="BID">860</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94454565726775&amp;w=2" source="NTBUGTRAQ">19991203 CommuniGatePro 3.1 for NT Buffer Overflow</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94426440413027&amp;w=2" source="BUGTRAQ">19991203 CommuniGatePro 3.1 for NT DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stalker" name="communigate_pro">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0866" published="1999-12-03" name="CVE-1999-0866" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in UnixWare xauto program allows local users to gain root privilege.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/848" source="BID">848</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94606167110764&amp;w=2" source="BUGTRAQ">19991223 FYI, SCO Security patches available.</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94581379905584&amp;w=2" source="BUGTRAQ">19991220 SCO OpenServer Security Status</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94530783815434&amp;w=2" source="BUGTRAQ">19991215 Recent postings about SCO UnixWare 7</ref>
      <ref url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.24a" source="SCO">SB-99.24a</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="unixware">
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.1" />
        <vers num="7.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0867" published="1999-08-11" name="CVE-1999-0867" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/579" source="BID">579</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-029.mspx" source="MS">MS99-029</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/j-058.shtml" source="CIAC">J-058</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q238349" source="MSKB">Q238349</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="commercial_internet_system">
        <vers num="2.0" />
        <vers num="2.5" />
      </prod>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
      </prod>
      <prod vendor="microsoft" name="site_server">
        <vers num="3.0" edition="unknown" />
        <vers num="3.0" edition="unknown:commerce" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0868" published="1997-02-20" name="CVE-1999-0868" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">ucbmail allows remote attackers to execute commands via shell metacharacters that are passed to it from INN.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="isc" name="inn">
        <vers num="1.5.1" />
      </prod>
      <prod vendor="netscape" name="news_server">
        <vers num="1.1" />
      </prod>
      <prod vendor="nec" name="goah_intrasv">
        <vers num="r1.1" />
      </prod>
      <prod vendor="nec" name="goah_networksv">
        <vers num="r1.2" />
        <vers num="r2.2" />
        <vers num="r3.1" />
      </prod>
      <prod vendor="sun" name="sparc">
        <vers num="" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0869" published="1998-12-01" name="CVE-1999-0869" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Internet Explorer 3.x to 4.01 allows a remote attacker to insert malicious content into a frame of another web site, aka frame spoofing.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms98-020.mspx" source="MS">MS98-020</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.2" />
        <vers num="4.0" />
        <vers num="4.0.1" />
      </prod>
      <prod vendor="netscape" name="navigator">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0870" published="1998-10-01" name="CVE-1999-0870" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Internet Explorer 4.01 allows remote attackers to read arbitrary files by pasting a file name into the file upload control, aka untrusted scripted paste.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms98-015.mspx" source="MS">MS98-015</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.0.1" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0871" published="1998-09-04" name="CVE-1999-0871" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Internet Explorer 4.0 and 4.01 allow a remote attacker to read files via IE's cross frame security, aka the "Cross Frame Navigate" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/3668" source="XF">ie-crossframe-file-read(3668)</ref>
      <ref url="http://www.osvdb.org/7837" source="OSVDB">7837</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms98-013.mspx" source="MS">MS98-013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.0" />
        <vers num="4.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0872" published="1999-08-25" name="CVE-1999-0872" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment variable in a crontab file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/759" source="BID">759</ref>
      <ref url="http://www.securityfocus.com/bid/611" source="BID">611</ref>
    </refs>
    <vuln_soft>
      <prod vendor="paul_vixie" name="vixie_cron">
        <vers num="3.0_pl1" />
      </prod>
      <prod vendor="caldera" name="openlinux">
        <vers num="2.2" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" edition="" />
        <vers num="5.2" edition=":i386" />
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0873" published="1999-10-30" name="CVE-1999-0873" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Skyfull mail server via MAIL FROM command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/759" source="BID">759</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sky_communications" name="skyfull">
        <vers num="1.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0874" published="1999-06-16" name="CVE-1999-0874" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-019.asp" source="MS" patch="1">MS99-019</ref>
      <ref url="http://www.eeye.com/html/Research/Advisories/AD06081999.html" source="EEYE">AD06081999</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/j-048.shtml" source="CIAC">J-048</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q234905" source="MSKB">Q234905</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:915" source="OVAL" sig="1">oval:org.mitre.oval:def:915</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0875" published="1999-08-11" name="CVE-1999-0875" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">DHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify their default routes.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/578" source="BID">578</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q216141" source="MSKB">Q216141</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_95">
        <vers num="0a" />
        <vers num="0b" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0876" published="2000-01-04" name="CVE-1999-0876" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Internet Explorer 4.0 via EMBED tag.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/support/kb/articles/q176/6/97.asp" source="MSKB">Q176697</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q185959" source="MSKB">Q185959</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":mac_os" />
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":mac_os" />
        <vers num="4.0" edition="a" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0877" published="1999-10-01" name="CVE-1999-0877" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Internet Explorer 5 allows remote attackers to read files via an ExecCommand method called on an IFRAME.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-042.mspx" source="MS">MS99-042</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q243638" source="MSKB">Q243638</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.01" edition="sp1" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0878" published="1999-08-22" name="CVE-1999-0878" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via MAPPING_CHDIR.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/599" source="BID">599</ref>
    </refs>
    <vuln_soft>
      <prod vendor="beroftpd" name="beroftpd">
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
      </prod>
      <prod vendor="washington_university" name="wu-ftpd">
        <vers num="2.4.2_beta18_vr10" />
        <vers num="2.4.2_beta18_vr11" />
        <vers num="2.4.2_beta18_vr12" />
        <vers num="2.4.2_beta18_vr13" />
        <vers num="2.4.2_beta18_vr14" />
        <vers num="2.4.2_beta18_vr15" />
        <vers num="2.4.2_beta18_vr4" />
        <vers num="2.4.2_beta18_vr5" />
        <vers num="2.4.2_beta18_vr6" />
        <vers num="2.4.2_beta18_vr8" />
        <vers num="2.4.2_beta18_vr9" />
        <vers num="2.4.2_vr16" />
        <vers num="2.4.2_vr17" />
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0879" published="1999-10-01" name="CVE-1999-0879" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via macro variables in a message file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="bsdi" name="bsd_os">
        <vers num="2.1" />
        <vers num="3.0" />
      </prod>
      <prod vendor="caldera" name="openlinux">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0880" published="1999-10-01" name="CVE-1999-0880" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service in WU-FTPD via the SITE NEWER command, which does not free memory properly.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="bsdi" name="bsd_os">
        <vers num="2.1" />
        <vers num="3.0" />
      </prod>
      <prod vendor="caldera" name="openlinux">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0881" published="1999-10-26" name="CVE-1999-0881" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Falcon web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/743" source="BID">743</ref>
      <ref url="http://www.osvdb.org/1127" source="OSVDB">1127</ref>
    </refs>
    <vuln_soft>
      <prod vendor="blueface" name="falcon_web_server">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0882" published="1999-10-28" name="CVE-1999-0882" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Falcon web server allows remote attackers to determine the absolute path of the web root via long file names.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="falcon" name="falcon_web_server">
        <vers num="1.0.0.1006" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0883" published="1999-10-25" name="CVE-1999-0883" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Zeus web server allows remote attackers to read arbitrary files by specifying the file name in an option to the search engine.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/3380" source="XF">zeus-remote-root(3380)</ref>
      <ref url="http://www.securityfocus.com/bid/742" source="BID">742</ref>
      <ref url="http://www.osvdb.org/1126" source="OSVDB">1126</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zeus_technologies" name="zeus_web_server">
        <vers num="3.3.1" />
        <vers num="3.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0884" published="1999-10-25" name="CVE-1999-0884" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Zeus web server administrative interface uses weak encryption for its passwords.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/3833" source="XF">zeus-weak-password(3833)</ref>
      <ref url="http://www.securityfocus.com/bid/742" source="BID">742</ref>
      <ref url="http://www.osvdb.org/8186" source="OSVDB">8186</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zeus_technologies" name="zeus_web_server">
        <vers num="3.3.1" />
        <vers num="3.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0885" published="1999-11-03" name="CVE-1999-0885" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Alibaba web server allows remote attackers to execute commands via a pipe character in a malformed URL.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/770" source="BID">770</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-11-01&amp;msg=01BF261F.928821E0.kerb@fnusa.com" source="BUGTRAQ">19991103 More Alibaba Web Server problems...</ref>
    </refs>
    <vuln_soft>
      <prod vendor="computer_software_manufaktur" name="alibaba">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0886" published="1999-09-17" name="CVE-1999-0886" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/645" source="BID">645</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-041.mspx" source="MS">MS99-041</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q242294" source="MSKB">Q242294</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0887" published="1999-11-04" name="CVE-1999-0887" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">FTGate web interface server allows remote attackers to read files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/1137" source="OSVDB">1137</ref>
      <ref url="http://www.eeye.com/html/Research/Advisories/AD05261999.html" source="EEYE">AD05261999</ref>
    </refs>
    <vuln_soft>
      <prod vendor="floosietek" name="ftgate">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0888" published="1999-08-16" name="CVE-1999-0888" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">dbsnmp in Oracle Intelligent Agent allows local users to gain privileges by setting the ORACLE_HOME environmental variable, which dbsnmp uses to find the nmiconf.tcl script.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/585" source="BID">585</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="7.3.3" />
        <vers num="7.3.4" />
      </prod>
      <prod vendor="oracle" name="oracle8i">
        <vers num="8.0.3" />
        <vers num="8.0.4" />
        <vers num="8.0.5" />
        <vers num="8.0.5.1" />
        <vers num="8.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0889" published="1999-07-01" name="CVE-1999-0889" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cisco 675 routers running CBOS allow remote attackers to establish telnet sessions if an exec or superuser password has not been set.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/39" source="OSVDB">39</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="675_router">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0890" published="1999-09-16" name="CVE-1999-0890" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">iHTML Merchant allows remote attackers to obtain sensitive information or execute commands via a code parsing error.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <env />
      <config />
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ihtmlmerchant.com/support_patches_feedback.htm" source="CONFIRM" patch="1">http://www.ihtmlmerchant.com/support_patches_feedback.htm</ref>
      <ref url="http://www.securityfocus.com/bid/694" source="BID">694</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ihtml_merchant" name="ihtml_merchant">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0891" published="1999-09-01" name="CVE-1999-0891" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The "download behavior" in Internet Explorer 5 allows remote attackers to read arbitrary files via a server-side redirect.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/37828" source="CERT-VN">VU#37828</ref>
      <ref url="http://www.securityfocus.com/bid/674" source="BID">674</ref>
      <ref url="http://www.osvdb.org/11274" source="OSVDB">11274</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-040.mspx" source="MS">MS99-040</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/k-002.shtml" source="CIAC">K-002</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q242542" source="MSKB">Q242542</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0892" published="1999-12-24" name="CVE-1999-0892" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in Netscape Communicator before 4.7 via a dynamic font whose length field is less than the size of the font.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="netscape" name="communicator">
        <vers num="4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0893" published="1999-10-11" name="CVE-1999-0893" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">userOsa in SCO OpenServer allows local users to corrupt files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sco" name="openserver">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0894" published="2000-01-04" name="CVE-1999-0894" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Red Hat Linux screen program does not use Unix98 ptys, allowing local users to write to other terminals.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0895" published="1999-10-20" name="CVE-1999-0895" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Firewall-1 does not properly restrict access to LDAP attributes.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=19991020150002.21047.qmail@tarjan.mediaways.net" source="BUGTRAQ">19991020 Checkpoint FireWall-1 V4.0: possible bug in LDAP authentication</ref>
      <ref url="http://www.securityfocus.com/bid/725" source="BID">725</ref>
      <ref url="http://www.osvdb.org/1117" source="OSVDB">1117</ref>
    </refs>
    <vuln_soft>
      <prod vendor="checkpoint" name="firewall-1">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0896" published="1999-11-04" name="CVE-1999-0896" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in RealNetworks RealServer administration utility allows remote attackers to execute arbitrary commands via a long username and password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://service.real.com/help/faq/servg260.html" source="MISC">http://service.real.com/help/faq/servg260.html</ref>
      <ref url="http://www.securityfocus.com/bid/767" source="BID">767</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realserver_g2">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0897" published="1998-09-09" name="CVE-1999-0897" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">iChat ROOMS Webserver allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90538488231977&amp;w=2" source="BUGTRAQ">19980908 bug in iChat 3.0 (maybe others)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="ichat_server">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0898" published="1999-11-04" name="CVE-1999-0898" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflows in Windows NT 4.0 print spooler allow remote attackers to gain privileges or cause a denial of service via a malformed spooler request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/768" source="BID">768</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-047.mspx" source="MS">MS99-047</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q243649" source="MSKB">Q243649</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0899" published="1999-11-04" name="CVE-1999-0899" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The Windows NT 4.0 print spooler allows a local user to execute arbitrary commands due to inappropriate permissions that allow the user to specify an alternate print provider.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/769" source="BID">769</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-047.mspx" source="MS">MS99-047</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q243649" source="MSKB">Q243649</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0900" published="1999-10-23" name="CVE-1999-0900" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in rpc.yppasswdd allows a local user to gain privileges via MD5 hash generation.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="linux-nis" name="rpc.yppasswdd">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0901" published="1999-10-23" name="CVE-1999-0901" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">ypserv allows a local user to modify the GECOS and login shells of other users.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="linux-nis" name="ypserv">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0902" published="1999-10-23" name="CVE-1999-0902" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">ypserv allows local administrators to modify password tables.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="linux-nis" name="ypserv">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0903" published="1999-10-26" name="CVE-1999-0903" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">genfilt in the AIX Packet Filtering Module does not properly filter traffic to destination ports greater than 32767.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0904" published="1999-11-03" name="CVE-1999-0904" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in BFTelnet allows remote attackers to cause a denial of service via a long username.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/771" source="BID">771</ref>
    </refs>
    <vuln_soft>
      <prod vendor="byte_fusion" name="bftelnet">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0905" published="1999-10-21" name="CVE-1999-0905" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service in Axent Raptor firewall via malformed zero-length IP options.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/736" source="BID">736</ref>
      <ref url="http://www.osvdb.org/1121" source="OSVDB">1121</ref>
    </refs>
    <vuln_soft>
      <prod vendor="axent" name="raptor_firewall">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0906" published="1999-09-23" name="CVE-1999-0906" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in sccw allows local users to gain root access via the HOME environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/656" source="BID">656</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="suse_linux">
        <vers num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0907" published="1999-09-16" name="CVE-1999-0907" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">sccw allows local users to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="steven_j._merrifield" name="soundcard_cw">
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":linux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0908" published="1999-09-23" name="CVE-1999-0908" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service in Solaris TCP streams driver via a malicious connection that causes the server to panic as a result of recursive calls to mutex_enter.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/655" source="BID">655</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0909" published="1999-09-20" name="CVE-1999-0909" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multihomed Windows systems allow a remote attacker to bypass IP source routing restrictions via a malformed packet with IP options, aka the "Spoofed Route Pointer" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-038.mspx" source="MS" patch="1">MS99-038</ref>
      <ref url="http://www.securityfocus.com/bid/646" source="BID">646</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q238453" source="MSKB">Q238453</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="terminal_server">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_95">
        <vers num="0a" />
        <vers num="0b" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0910" published="1999-09-10" name="CVE-1999-0910" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Site Server and Commercial Internet System (MCIS) do not set an expiration for a cookie, which could then be cached by a proxy and inadvertently used by a different user.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-035.asp" source="MS" patch="1" adv="1">MS99-035</ref>
      <ref url="http://www.securityfocus.com/bid/625" source="BID">625</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="commercial_internet_system">
        <vers num="2.0" />
        <vers num="2.5" />
      </prod>
      <prod vendor="microsoft" name="site_server">
        <vers num="3.0" />
      </prod>
      <prod vendor="microsoft" name="site_server_commerce">
        <vers num="3.0" edition="alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0911" published="1999-08-27" name="CVE-1999-0911" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in ProFTPD, wu-ftpd, and beroftpd allows remote attackers to gain root access via a series of MKD and CWD commands that create nested directories.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/612" source="BID">612</ref>
      <ref url="http://www.debian.org/security/1999/19990210" source="DEBIAN">19990210</ref>
    </refs>
    <vuln_soft>
      <prod vendor="proftpd_project" name="proftpd">
        <vers num="1.2_pre1" />
        <vers num="1.2_pre2" />
        <vers num="1.2_pre3" />
        <vers num="1.2_pre4" />
        <vers num="1.2_pre5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0912" published="1999-09-22" name="CVE-1999-0912" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">FreeBSD VFS cache (vfs_cache) allows local users to cause a denial of service by opening a large number of files.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/653" source="BID">653</ref>
      <ref url="http://www.osvdb.org/1079" source="OSVDB">1079</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0913" published="1999-08-05" name="CVE-1999-0913" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">dfire.cgi script in Dragon-Fire IDS allows remote users to execute commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/564" source="BID">564</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93383593909438&amp;w=2" source="BUGTRAQ">19990804 NSW Dragon Fire gets drowned</ref>
    </refs>
    <vuln_soft>
      <prod vendor="network_security_wizards" name="dragon-fire_ids">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0914" published="1999-01-03" name="CVE-1999-0914" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the FTP client in the Debian GNU/Linux netstd package.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/324" source="BID">324</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0915" published="1999-10-28" name="CVE-1999-0915" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">URL Live! web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/746" source="BID">746</ref>
      <ref url="http://www.osvdb.org/1129" source="OSVDB">1129</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pacific_software" name="url_live">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0916" published="1999-06-29" name="CVE-1999-0916" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">WebTrends software stores account names and passwords in a file which does not have restricted access permissions.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="webtrends" name="webtrends_enterprise_suite">
        <vers num="v3.5" />
      </prod>
      <prod vendor="webtrends" name="webtrends_for_firewalls">
        <vers num="v1.2" />
      </prod>
      <prod vendor="webtrends" name="webtrends_log_analyzer">
        <vers num="v4.51" />
      </prod>
      <prod vendor="webtrends" name="webtrends_professional_suite">
        <vers num="v3.01" />
      </prod>
      <prod vendor="webtrends" name="webtrends_security_analyzer">
        <vers num="v2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0917" published="1999-05-27" name="CVE-1999-0917" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">The Preloader ActiveX control used by Internet Explorer allows remote attackers to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q231452" source="MSKB">Q231452</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-018.mspx" source="MS">MS99-018</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0918" published="1999-07-03" name="CVE-1999-0918" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Denial of service in various Windows systems via malformed, fragmented IGMP packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-034.mspx" source="MS" patch="1">MS99-034</ref>
      <ref url="http://www.securityfocus.com/bid/514" source="BID">514</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q238329" source="MSKB">Q238329</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_95">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0919" published="1998-05-10" name="CVE-1999-0919" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A memory leak in a Motorola CableRouter allows remote attackers to conduct a denial of service via a large number of telnet connections.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2004.php" source="XF" adv="1">motorola-cable-crash(2004)</ref>
      <ref url="http://www.netspace.org/cgi-bin/wa?A2=ind9805B&amp;L=bugtraq&amp;P=R1621" source="BUGTRAQ" adv="1">19980510 Security Vulnerability in Motorola CableRouters</ref>
    </refs>
    <vuln_soft>
      <prod vendor="motorola" name="motorola_cablerouter">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0920" published="1999-05-26" name="CVE-1999-0920" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the pop-2d POP daemon in the IMAP package allows remote attackers to gain privileges via the FOLD command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/283" source="BID">283</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_washington" name="imap">
        <vers num="4.4" />
      </prod>
      <prod vendor="university_of_washington" name="pop2d">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0921" published="1999-04-01" name="CVE-1999-0921" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BMC Patrol allows any remote attacker to flood its UDP port, causing a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1879" source="BID">1879</ref>
      <ref url="http://www.securityfocus.com/archive/1/13204" source="BUGTRAQ">19990409 Patrol security bugs</ref>
      <ref url="http://www.iss.net/security_center/static/4291.php" source="XF">bmc-patrol-udp-dos(4291)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bmc" name="patrol_agent">
        <vers num="3.2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0922" published="2001-03-12" name="CVE-1999-0922" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">An example application in ColdFusion Server 4.0 allows remote attackers to view source code via the sourcewindow.cfm file.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.allaire.com/handlers/index.cfm?ID=8739&amp;Method=Full" source="ALLAIRE" patch="1" adv="1">ASB99-02</ref>
    </refs>
    <vuln_soft>
      <prod vendor="allaire" name="coldfusion_server">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0923" published="2001-03-12" name="CVE-1999-0923" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Sample runnable code snippets in ColdFusion Server 4.0 allow remote attackers to read files, conduct a denial of service, or use the server as a proxy for other HTTP calls.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.allaire.com/handlers/index.cfm?ID=8739&amp;Method=Full" source="ALLAIRE" patch="1" adv="1">ASB99-02</ref>
    </refs>
    <vuln_soft>
      <prod vendor="allaire" name="coldfusion_server">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0924" published="2001-03-12" name="CVE-1999-0924" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Syntax Checker in ColdFusion Server 4.0 allows remote attackers to conduct a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.allaire.com/handlers/index.cfm?ID=8739&amp;Method=Full" source="ALLAIRE" patch="1" adv="1">ASB99-02</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/1742" source="XF">coldfusion-syntax-checker(1742)</ref>
      <ref url="http://www.osvdb.org/3236" source="OSVDB">3236</ref>
    </refs>
    <vuln_soft>
      <prod vendor="allaire" name="coldfusion_server">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0925" published="1999-09-03" name="CVE-1999-0925" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">UnityMail allows remote attackers to conduct a denial of service via a large number of MIME headers.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90486243124867&amp;w=2" source="BUGTRAQ">19980903 Web servers / possible DOS Attack / mime header flooding</ref>
    </refs>
    <vuln_soft>
      <prod vendor="messagemedia" name="unitymail">
        <vers prev="1" num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0926" published="1999-09-03" name="CVE-1999-0926" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Apache allows remote attackers to conduct a denial of service via a large number of MIME headers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/1998_3/0742.html" source="BUGTRAQ" adv="1">19990903 Web servers / possible DOS Attack / mime header flooding</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="1.2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0927" published="1999-05-26" name="CVE-1999-0927" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">NTMail allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/279" source="BID">279</ref>
      <ref url="http://www.eeye.com/html/Research/Advisories/AD05261999.html" source="EEYE">AD05261999</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gordano" name="ntmail">
        <vers num="4.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0928" published="1999-05-23" name="CVE-1999-0928" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in SmartDesk WebSuite allows remote attackers to cause a denial of service via a long URL.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/278" source="BID">278</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smartdesk" name="websuite">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0929" published="1999-06-16" name="CVE-1999-0929" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Novell NetWare with Novell-HTTP-Server or YAWN web servers allows remote attackers to conduct a denial of service via a large number of HTTP GET requests.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="novell" name="http_server">
        <vers num="2.51r1" />
        <vers num="3.1r1" />
      </prod>
      <prod vendor="novell" name="netware">
        <vers num="4.1" />
        <vers num="4.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0930" published="1998-09-03" name="CVE-1999-0930" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">wwwboard allows a remote attacker to delete message board articles via a malformed argument.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.worldwidemart.com/scripts/faq/wwwboard/q5.shtml" source="CONFIRM">http://www.worldwidemart.com/scripts/faq/wwwboard/q5.shtml</ref>
      <ref url="http://xforce.iss.net/static/2344.php" source="XF">http-cgi-wwwboard(2344)</ref>
      <ref url="http://www.securityfocus.com/bid/1795" source="BID">1795</ref>
    </refs>
    <vuln_soft>
      <prod vendor="matt_wright" name="wwwboard">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0931" published="1999-09-30" name="CVE-1999-0931" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Mediahouse Statistics Server allows remote attackers to execute commands.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/734" source="BID">734</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mediahouse_software" name="statistics_server">
        <vers num="4.28" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0932" published="1999-09-30" name="CVE-1999-0932" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Mediahouse Statistics Server allows remote attackers to read the administrator password, which is stored in cleartext in the ss.cfg file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/735" source="BID">735</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mediahouse_software" name="statistics_server">
        <vers num="4.28" />
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0933" published="1999-10-01" name="CVE-1999-0933" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">TeamTrack web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/689" source="BID">689</ref>
      <ref url="http://www.osvdb.org/1096" source="OSVDB">1096</ref>
    </refs>
    <vuln_soft>
      <prod vendor="teamshare" name="teamtrack">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0934" published="1999-12-15" name="CVE-1999-0934" modified="2005-05-02" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">classifieds.cgi allows remote attackers to read arbitrary files via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/3102" source="XF">http-cgi-classifieds-read(3102)</ref>
      <ref url="http://www.securityfocus.com/bid/2020" source="BID">2020</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0935" published="1999-12-15" name="CVE-1999-0935" modified="2005-05-02" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">classifieds.cgi allows remote attackers to execute arbitrary commands by specifying them in a hidden variable in a CGI form.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0936" published="1998-12-03" name="CVE-1999-0936" modified="2005-05-02" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">BNBSurvey survey.cgi program allows remote attackers to execute commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0937" published="1998-12-03" name="CVE-1999-0937" modified="2005-05-02" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">BNBForm allows remote attackers to read arbitrary files via the automessage hidden form variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="1999-0938" published="1999-06-28" name="CVE-1999-0938" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">MBone SDR Package allows remote attackers to execute commands via shell metacharacters in Sesion Initiation Protocol (SIP) messages.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="university_college_london" name="sdr">
        <vers prev="1" num="2.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0939" published="1999-08-26" name="CVE-1999-0939" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service in Debian IRC Epic/epic4 client via a long string.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/605" source="BID">605</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.1" />
        <vers num="2.2" edition="" />
        <vers num="2.2" edition=":pre_potato" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0940" published="1999-09-27" name="CVE-1999-0940" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in mutt mail client allows remote attackers to execute commands via malformed MIME messages.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="mutt" name="mutt_mail_client">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0941" published="1998-07-28" name="CVE-1999-0941" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Mutt mail client allows a remote attacker to execute commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526154&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19980728 mutt x.x</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mutt" name="mutt">
        <vers num="0.95.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0942" published="1999-10-04" name="CVE-1999-0942" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">UnixWare dos7utils allows a local user to gain root privileges by using the STATICMERGE environmental variable to find a script which it executes.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sco" name="unixware">
        <vers num="7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0943" published="1999-10-15" name="CVE-1999-0943" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in OpenLink 3.2 allows remote attackers to gain privileges via a long GET request to the web configurator.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/720" source="BID">720</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openlink" name="openlink">
        <vers num="a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0944" published="1999-10-24" name="CVE-1999-0944" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">IBM WebSphere ikeyman tool uses weak encryption to store a password for a key database that is used for SSL connections.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0945" published="2001-03-12" name="CVE-1999-0945" modified="2008-09-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Internet Mail Service (IMS) for Microsoft Exchange 5.5 and 5.0 allows remote attackers to conduct a denial of service via AUTH or AUTHINFO commands.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/alerts/advise4.php" source="ISS" patch="1" adv="1">19980724 Denial of Service attacks against Microsoft Exchange 5.0 to 5.5</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/i-080.shtml" source="CIAC" patch="1" adv="1">I-080</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/1223" source="XF">exchange-dos(1223)</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q169174" source="MSKB">Q169174</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="5.0" />
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0946" published="1999-11-02" name="CVE-1999-0946" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in Yamaha MidiPlug via a Text variable in an EMBED tag.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/760" source="BID">760</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94157187815629&amp;w=2" source="BUGTRAQ">19991102 Some holes for Win/UNIX softwares</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yamaha" name="midiplug">
        <vers num="1.1bj" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0947" published="1999-11-02" name="CVE-1999-0947" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">AN-HTTPd provides example CGI scripts test.bat, input.bat, input2.bat, and envout.bat, which allow remote attackers to execute commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/762" source="BID">762</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94157187815629&amp;w=2" source="BUGTRAQ">19991102 Some holes for Win/UNIX softwares</ref>
    </refs>
    <vuln_soft>
      <prod vendor="an" name="an-httpd">
        <vers num="1.2b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0948" published="1999-11-02" name="CVE-1999-0948" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in uum program for Canna input system allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/757" source="BID">757</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="5.3" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
        <vers num="6.5" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux">
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0949" published="1999-11-02" name="CVE-1999-0949" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in canuum program for Canna input system allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/757" source="BID">757</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="5.3" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
        <vers num="6.5" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux">
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0950" published="1999-10-28" name="CVE-1999-0950" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in WFTPD FTP server allows remote attackers to gain root access via	a series of MKD and CWD commands that create nested directories.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/747" source="BID">747</ref>
    </refs>
    <vuln_soft>
      <prod vendor="texas_imperial_software" name="wftpd">
        <vers num="2.34" />
        <vers num="2.40" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0951" published="1999-10-22" name="CVE-1999-0951" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in OmniHTTPd CGI program imagemap.exe allows remote attackers to execute commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/739" source="BID">739</ref>
      <ref url="http://www.osvdb.org/3380" source="OSVDB">3380</ref>
    </refs>
    <vuln_soft>
      <prod vendor="omnicron" name="omnihttpd">
        <vers num="1.1" />
        <vers num="2.4pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0952" published="1999-01-28" name="CVE-1999-0952" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Solaris lpstat via class argument allows local users to gain root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91759216618637&amp;w=2" source="BUGTRAQ" adv="1">19990126 Buffer overflow in Solaris 2.6/2.7 /usr/bin/lpstat</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0953" published="1999-09-16" name="CVE-1999-0953" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">WWWBoard stores encrypted passwords in a password file that is under the web root and thus accessible by remote attackers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="matt_wright" name="wwwboard">
        <vers num="2.0_alpha_2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0954" published="1999-09-16" name="CVE-1999-0954" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">WWWBoard has a default username and default password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/649" source="BID">649</ref>
    </refs>
    <vuln_soft>
      <prod vendor="matt_wright" name="wwwboard">
        <vers num="2.0_alpha_2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0955" published="1997-09-23" name="CVE-1999-0955" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Race condition in wu-ftpd and BSDI ftpd allows remote attackers gain root access via the SITE EXEC command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="washington_university" name="wu-ftpd">
        <vers num="2.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0956" published="1997-09-19" name="CVE-1999-0956" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The NeXT NetInfo _writers property allows local users to gain root privileges or conduct a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="next" name="nextstep">
        <vers num="1.0" />
        <vers num="1.0a" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0957" published="1997-06-18" name="CVE-1999-0957" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">MajorCool mj_key_cache program allows local users to modify files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="great_circle_associates" name="majorcool">
        <vers prev="1" num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0958" published="1998-01-12" name="CVE-1999-0958" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">sudo 1.5.x allows local users to execute arbitrary commands via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88465708614896&amp;w=2" source="BUGTRAQ">19980112 Re: hole in sudo for MP-RAS.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="todd_miller" name="sudo">
        <vers num="1.5" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0959" published="1997-02-01" name="CVE-1999-0959" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">IRIX startmidi program allows local users to modify arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/469" source="BID">469</ref>
      <ref url="http://www.osvdb.org/8447" source="OSVDB">8447</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19980301-01-PX" source="SGI">19980301-01-PX</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="5" />
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0960" published="1998-03-20" name="CVE-1999-0960" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">IRIX cdplayer allows local users to create directories in arbitrary locations via a command line option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19980301-01-PX" source="SGI">19980301-01-PX</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="5" />
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0961" published="1996-09-21" name="CVE-1999-0961" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">HPUX sysdiag allows local users to gain root privileges via a symlink attack during log file creation.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167419906&amp;w=2" source="BUGTRAQ">19960921 Vunerability in HP sysdiag ?</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="9.04" />
        <vers num="9.05" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0962" published="1997-05-14" name="CVE-1999-0962" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in HPUX passwd command allows local users to gain root privileges via a command line option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9701-045" source="HP">HPSBUX9701-045</ref>
      <ref url="http://www.osvdb.org/6415" source="OSVDB">6415</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10" />
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0963" published="1999-12-01" name="CVE-1999-0963" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">FreeBSD mount_union command allows local users to gain root privileges via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/6088" source="OSVDB">6088</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0964" published="2000-01-01" name="CVE-1999-0964" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in FreeBSD setlocale in the libc module allows attackers to execute arbitrary code via a long PATH_LOCALE environment variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/6086" source="OSVDB">6086</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="2.1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0965" published="1997-09-19" name="CVE-1999-0965" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">Race condition in xterm allows local users to modify arbitrary files via the logging option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="x.org" name="xterm">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0966" published="1997-01-27" name="CVE-1999-0966" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Solaris getopt in libc allows local users to gain root privileges via a long argv[0].</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0967" published="1997-11-01" name="CVE-1999-0967" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the HTML library used by Internet Explorer, Outlook Express, and Windows Explorer via the res: local resource protocol.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.0" />
      </prod>
      <prod vendor="microsoft" name="outlook_express">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_explorer">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0968" published="1998-12-26" name="CVE-1999-0968" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in BNC IRC proxy allows remote attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1546.php" source="XF">bnc-proxy-bo(1546)</ref>
      <ref url="http://www.securityfocus.com/bid/1927" source="BID">1927</ref>
      <ref url="http://www.securityfocus.com/archive/1/11711" source="BUGTRAQ">19981226 bnc exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="james_seter" name="bnc_irc">
        <vers prev="1" num="2.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0969" published="1998-09-29" name="CVE-1999-0969" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Windows NT RPC service allows remote attackers to conduct a denial of service using spoofed malformed RPC packets which generate an error message that is sent to the spoofed host, potentially setting up a loop, aka Snork.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q193233" source="MSKB">Q193233</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms98-014.mspx" source="MS">MS98-014</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0970" published="1999-06-05" name="CVE-1999-0970" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The OmniHTTPD visadmin.exe program allows a remote attacker to conduct a denial of service via a malformed URL which causes a large number of temporary files to be created.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2271.php" source="XF" patch="1" adv="1">omnihttpd-dos(2271)</ref>
      <ref url="http://www.securityfocus.com/bid/1808" source="BID">1808</ref>
      <ref url="http://www.securityfocus.com/archive/1/14311" source="BUGTRAQ">19990605 Remote Exploit (Bug) in OmniHTTPd Web Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="omnicron" name="omnihttpd">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0971" published="1997-07-22" name="CVE-1999-0971" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Exim allows local users to gain root privileges via a long :include: option in a .forward file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/7301" source="BUGTRAQ">19970722 Security hole in exim 1.62: local root exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_cambridge" name="exim">
        <vers prev="1" num="1.62" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0972" published="1999-12-09" name="CVE-1999-0972" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Xshipwars xsw program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/863" source="BID">863</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wolfpack_development" name="xshipwars">
        <vers num="1.0" />
        <vers num="1.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0973" published="1999-12-07" name="CVE-1999-0973" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Solaris snoop program allows remote attackers to gain root privileges via a long domain name when snoop is running in verbose mode.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/858" source="BID">858</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.3" />
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0974" published="1999-12-09" name="CVE-1999-0974" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Solaris snoop allows remote attackers to gain root privileges via GETQUOTA requests to the rpc.rquotad service.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/864" source="BID">864</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/190" source="SUN">00190</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":ppc" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0975" published="1999-12-10" name="CVE-1999-0975" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The Windows help system can allow a local user to execute commands as another user by editing a table of contents metafile with a .CNT extension and modifying the topic action to include the commands to be executed when the .hlp file is accessed.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/868" source="BID">868</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_95">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0976" published="1999-12-07" name="CVE-1999-0976" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Sendmail allows local users to reinitialize the aliases database via the newaliases command, then cause a denial of service by interrupting Sendmail.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/857" source="BID">857</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eric_allman" name="sendmail">
        <vers num="8.9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0977" published="1999-12-10" name="CVE-1999-0977" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Solaris sadmind allows remote attackers to gain root privileges using a NETMGT_PROC_SERVICE request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/866" source="BID">866</ref>
      <ref url="http://www.securityfocus.com/bid/2354" source="BID">2354</ref>
      <ref url="http://www.osvdb.org/2558" source="OSVDB">2558</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/191" source="SUN">00191</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":ppc" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0978" published="1999-12-09" name="CVE-1999-0978" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">htdig allows remote attackers to execute commands via filenames with shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/867" source="BID">867</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0979" published="2000-04-11" name="CVE-1999-0979" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The SCO UnixWare privileged process system allows local users to gain root privileges by using a debugger such as gdb to insert traps into _init before the privileged process is executed.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/869" source="BID">869</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94530783815434&amp;w=2" source="BUGTRAQ">19991215 Recent postings about SCO UnixWare 7</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="unixware">
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.1" />
        <vers num="7.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0980" published="2000-05-16" name="CVE-1999-0980" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Windows NT Service Control Manager (SCM) allows remote attackers to cause a denial of service via a malformed argument in a resource enumeration request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-055.mspx" source="MS">MS99-055</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q246045" source="MSKB">Q246045</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:enterprise" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0981" published="1999-12-08" name="CVE-1999-0981" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Internet Explorer 5.01 and earlier allows a remote attacker to create a reference to a client window and use a server-side redirect to access local files via that window, aka "Server-side Page Reference Redirect."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-050.mspx" source="MS">MS99-050</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q246094" source="MSKB">Q246094</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.0.1" />
        <vers num="5.0" />
        <vers prev="1" num="5.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0982" published="1999-12-05" name="CVE-1999-0982" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The Sun Web-Based Enterprise Management (WBEM) installation script stores a password in plaintext in a world readable file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sun" name="web-based_enterprise_management">
        <vers num="1.0" />
        <vers num="2.0" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="8.0" edition="beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0983" published="1999-11-09" name="CVE-1999-0983" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Whois Internic Lookup program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="internic" name="whois_lookup">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0984" published="1999-11-09" name="CVE-1999-0984" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Matt's Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="matts_whois" name="matts_whois">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0985" published="1999-11-09" name="CVE-1999-0985" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">CC Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="cc" name="cc_whois">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0986" published="1999-12-08" name="CVE-1999-0986" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The ping command in Linux 2.0.3x allows local users to cause a denial of service by sending large packets with the -R (record route) option.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/870" source="BID">870</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.1" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.0" />
        <vers num="2.0.34" />
        <vers num="2.0.35" />
        <vers num="2.0.36" />
        <vers num="2.0.37" />
        <vers num="2.0.38" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="5.2" edition="" />
        <vers num="5.2" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0987" published="1999-11-18" name="CVE-1999-0987" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Windows NT does not properly download a system policy if the domain user logs into the domain with a space at the end of the domain name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q237923" source="MSKB">Q237923</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0988" published="1999-12-04" name="CVE-1999-0988" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">UnixWare pkgtrans allows local users to read arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sco" name="unixware">
        <vers num="2.0" />
        <vers num="2.0.3" />
        <vers num="2.1" />
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="7.1.16" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0989" published="1999-12-06" name="CVE-1999-0989" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Internet Explorer 5 directshow filter (MSDXM.OCX) allows remote attackers to execute commands via the vnd.ms.radio protocol.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/861" source="BID">861</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5" edition="" />
        <vers num="5" edition=":windows_nt_4.0" />
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":windows_98" />
        <vers num="5.0" edition=":windows_95" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-0990" published="1999-12-05" name="CVE-1999-0990" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Error messages generated by gdm with the VerboseAuth setting allows an attacker to identify valid users on a system.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="gnome" name="gdm">
        <vers num="2.0_beta4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0991" published="1999-12-06" name="CVE-1999-0991" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in GoodTech Telnet Server NT allows remote users to cause a denial of service via a long login name.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/862" source="BID">862</ref>
    </refs>
    <vuln_soft>
      <prod vendor="goodtech" name="telnet_server_nt">
        <vers num="2.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0992" published="2000-01-18" name="CVE-1999-0992" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">HP VirtualVault with the PHSS_17692 patch allows unprivileged processes to bypass access restrictions via the Trusted Gateway Proxy (TGP).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9912-107" source="HP">HPSBUX9912-107</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="vvos">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0993" published="1999-12-13" name="CVE-1999-0993" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Modifications to ACLs (Access Control Lists) in Microsoft Exchange 5.5 do not take effect until the directory store cache is refreshed.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="5.0" />
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0994" published="1999-12-16" name="CVE-1999-0994" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Windows NT with SYSKEY reuses the keystream that is used for encrypting SAM password hashes, allowing an attacker to crack passwords.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/873" source="BID">873</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-056.mspx" source="MS">MS99-056</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q248183" source="MSKB">Q248183</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:enterprise" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0995" published="1999-12-16" name="CVE-1999-0995" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Windows NT Local Security Authority (LSA) allows remote attackers to cause a denial of service via malformed arguments to the LsaLookupSids function which looks up the SID, aka "Malformed Security Identifier Request."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/875" source="BID">875</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-057.mspx" source="MS">MS99-057</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q248185" source="MSKB">Q248185</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:enterprise" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0996" published="1999-12-15" name="CVE-1999-0996" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Infoseek Ultraseek search engine allows remote attackers to execute commands via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/6490" source="OSVDB">6490</ref>
      <ref url="http://www.eeye.com/html/Research/Advisories/AD19991215.html" source="EEYE">AD19991215</ref>
    </refs>
    <vuln_soft>
      <prod vendor="infoseek" name="ultraseek_server">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-0997" published="1999-12-20" name="CVE-1999-0997" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">wu-ftp with FTP conversion enabled allows an attacker to execute commands via a malformed file name that is interpreted as an argument to the program that does the conversion, e.g. tar or uncompress.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2003/dsa-377" source="DEBIAN">DSA-377</ref>
    </refs>
    <vuln_soft>
      <prod vendor="millenux_gmbh" name="anonftp">
        <vers num="2.8.1" />
      </prod>
      <prod vendor="university_of_washington" name="wu-ftpd">
        <vers num="2.4.2" />
        <vers num="2.5.0" />
        <vers num="2.6.0" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="5.2" />
        <vers num="6.0" />
        <vers num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0998" published="1999-12-16" name="CVE-1999-0998" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco Cache Engine allows an attacker to replace content in the cache.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="cisco" name="cache_engine">
        <vers num="2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-0999" published="1999-11-19" name="CVE-1999-0999" modified="2008-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Microsoft SQL 7.0 server allows a remote attacker to cause a denial of service via a malformed TDS packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/817" source="BID">817</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-059.mspx" source="MS">MS99-059</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q248749" source="MSKB">Q248749</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="sql_server">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1000" published="1999-12-16" name="CVE-1999-1000" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The web administration interface for Cisco Cache Engine allows remote attackers to view performance statistics.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="cisco" name="cache_engine">
        <vers num="2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1001" published="1999-12-16" name="CVE-1999-1001" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cisco Cache Engine allows a remote attacker to gain access via a null username and password.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="cisco" name="cache_engine">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1002" published="2000-01-12" name="CVE-1999-1002" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Netscape Navigator uses weak encryption for storing a user's Netscape mail password.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.rstcorp.com/news/bad-crypto.html" source="MISC" adv="1">http://www.rstcorp.com/news/bad-crypto.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94570673523998&amp;w=2" source="BUGTRAQ">19991220 Netscape password scrambling</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94536309217214&amp;w=2" source="BUGTRAQ">19991216 Reinventing the wheel (aka "Decoding Netscape Mail passwords")</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="communicator">
        <vers num="4.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1003" published="1999-12-13" name="CVE-1999-1003" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">War FTP Daemon 1.70 allows remote attackers to cause a denial of service by flooding it with connections.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="jgaa" name="warftpd">
        <vers num="1.70" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1004" published="1999-12-16" name="CVE-1999-1004" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in the POP server POProxy for the Norton Anti-Virus protection NAV2000 program via a large USER command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/39194" source="BUGTRAQ">19991220 Norton Email Protection Remote Overflow (Addendum)</ref>
      <ref url="http://www.securityfocus.com/archive/1/38970" source="BUGTRAQ">19991217 NAV2000 Email Protection DoS</ref>
      <ref url="http://www.osvdb.org/6267" source="OSVDB">6267</ref>
      <ref url="http://service1.symantec.com/SUPPORT/nav.nsf/df0a595864594c86852567ac0063608c/6206f660a1f2516a882568660082c930?OpenDocument&amp;Highlight=0,poproxy" source="CONFIRM">http://service1.symantec.com/SUPPORT/nav.nsf/df0a595864594c86852567ac0063608c/6206f660a1f2516a882568660082c930?OpenDocument&amp;Highlight=0,poproxy</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="norton_antivirus">
        <vers num="2000" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1005" published="1999-12-19" name="CVE-1999-1005" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Groupwise web server GWWEB.EXE allows remote attackers to read arbitrary files with .htm extensions via a .. (dot dot) attack using the HELP parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/879" source="BID">879</ref>
      <ref url="http://www.osvdb.org/3413" source="OSVDB">3413</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94571433731824&amp;w=2" source="BUGTRAQ">19991219 Groupewise Web Interface</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="enterprise_server">
        <vers num="3.0.7a" />
      </prod>
      <prod vendor="novell" name="groupwise">
        <vers num="5.2" />
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1006" published="1999-12-19" name="CVE-1999-1006" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Groupwise web server GWWEB.EXE allows remote attackers to determine the real path of the web server via the HELP parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94571433731824&amp;w=2" source="BUGTRAQ" adv="1">19991219 Groupewise Web Interface</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="groupwise">
        <vers num="5.2" />
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1007" published="1999-12-13" name="CVE-1999-1007" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Buffer overflow in VDO Live Player allows remote attackers to execute commands on the VDO client via a malformed .vdo file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/872" source="BID">872</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94512259331599&amp;w=2" source="BUGTRAQ">19991213 VDO Live Player 3.02 Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vdonet" name="vdolive_player">
        <vers num="3.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1008" published="2000-05-17" name="CVE-1999-1008" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">xsoldier program allows local users to gain root access via a long argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/871" source="BID">871</ref>
      <ref url="http://marc.theaimsgroup.com/?l=freebsd-security&amp;m=94531826621620&amp;w=2" source="MISC">http://marc.theaimsgroup.com/?l=freebsd-security&amp;m=94531826621620&amp;w=2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.3" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1009" published="1999-12-12" name="CVE-1999-1009" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">The Disney Go Express Search allows remote attackers to access and modify search information for users by connecting to an HTTP server on the user's system.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="disney" name="go_express_search">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1010" published="1999-12-14" name="CVE-1999-1010" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">An SSH 1.2.27 server allows a client to use the "none" cipher, even if it is not allowed by the server policy.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94519142415338&amp;w=2" source="BUGTRAQ">19991214 sshd1 allows unencrypted sessions regardless of server policy</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openssh">
        <vers num="1.2.27" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1011" published="1999-07-19" name="CVE-1999-1011" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-025.asp" source="MS" patch="1">MS99-025</ref>
      <ref url="http://www.osvdb.org/272" source="OSVDB">272</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms98-004.asp" source="MS">MS98-004</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/j-054.shtml" source="BID">529</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/j-054.shtml" source="CIAC">J-054</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="data_access_components">
        <vers num="1.5" />
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
      <prod vendor="microsoft" name="index_server">
        <vers num="2.0" />
      </prod>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="3.0" />
        <vers num="4.0" />
      </prod>
      <prod vendor="microsoft" name="site_server">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1012" published="1999-05-04" name="CVE-1999-1012" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SMTP component of Lotus Domino 4.6.1 on AS/400, and possibly other operating systems, allows a remote attacker to crash the mail server via a long string.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/173" source="BID" adv="1">173</ref>
      <ref url="http://www.securityfocus.com/archive/1/13527" source="BUGTRAQ" adv="1">19990504 AS/400</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lotus" name="domino">
        <vers num="4.6.1" edition="" />
        <vers num="4.6.1" edition=":as_400" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1013" published="1999-09-23" name="CVE-1999-1013" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">named-xfer in AIX 4.1.5 and 4.2.1 allows members of the system group to overwrite system files to gain root access via the -f parameter and a malformed zone file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/673" source="BID" patch="1" adv="1">673</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93837026726954&amp;w=2" source="BUGTRAQ" adv="1">19990923 named-xfer hole on AIX (fwd)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.1.5" />
        <vers num="4.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1014" published="1999-09-13" name="CVE-1999-1014" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in mail command in Solaris 2.7 and 2.7 allows local users to gain privileges via a long -m argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3297.php" source="XF" patch="1" adv="1">sun-usrbinmail-local-bo(3297)</ref>
      <ref url="http://www.securityfocus.com/bid/672" source="BID" patch="1" adv="1">672</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93846422810162&amp;w=2" source="BUGTRAQ" adv="1">19990927 Working Solaris x86 /usr/bin/mail exploit</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93727925026476&amp;w=2" source="BUGTRAQ" adv="1">19990913 Solaris 2.7 /usr/bin/mail</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.7" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1015" published="1998-04-08" name="CVE-1999-1015" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Apple AppleShare Mail Server 5.0.3 on MacOS 8.1 and earlier allows a remote attacker to cause a denial of service (crash) via a long HELO command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/61" source="BID" adv="1">61</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=89200657216213&amp;w=2" source="BUGTRAQ" adv="1">19980408 AppleShare IP Mail Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="appleshare_mail_server">
        <vers num="5.0.3" edition="" />
        <vers num="5.0.3" edition=":" />
        <vers num="5.0.3" edition="::jp" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1016" published="1999-08-27" name="CVE-1999-1016" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service (100% CPU consumption) via large HTML form fields such as text inputs in a table cell.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/606" source="BID" adv="1">606</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93578772920970&amp;w=2" source="NTBUGTRAQ">19990827 HTML code to crash IE5 and Outlook Express 5</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="frontpage">
        <vers num="" edition=":express" />
      </prod>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0" />
      </prod>
      <prod vendor="microsoft" name="outlook_express">
        <vers num="5.0" />
      </prod>
      <prod vendor="qualcomm" name="eudora">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1017" published="1999-07-28" name="CVE-1999-1017" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Seattle Labs Emurl 2.0, and possibly earlier versions, stores e-mail attachments in a specific directory with scripting enabled, which allows a malicious ASP file attachment to execute when the recipient opens the message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/544" source="BID" patch="1" adv="1">544</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93316253431588&amp;w=2" source="NTBUGTRAQ" patch="1" adv="1">19990728 Seattle Labs EMURL Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="seattle_lab_software" name="emurl">
        <vers prev="1" num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1018" published="1999-07-27" name="CVE-1999-1018" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">IPChains in Linux kernels 2.2.10 and earlier does not reassemble IP fragments before checking the header information, which allows a remote attacker to bypass the filtering rules using several fragments with 0 offsets.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/543" source="BID" patch="1" adv="1">543</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93312523904591&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19990727 Linux 2.2.10 ipchains Advisory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.2.0" />
        <vers prev="1" num="2.2.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1019" published="1999-06-23" name="CVE-1999-1019" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">SpectroSERVER in Cabletron Spectrum Enterprise Manager 5.0 installs a directory tree with insecure permissions, which allows local users to replace a privileged executable (processd) with a Trojan horse, facilitating a root or Administrator compromise.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/495" source="BID" patch="1" adv="1">495</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93024398713491&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19990623 Cabletron Spectrum security vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93024398513475&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19990624 Re: Cabletron Spectrum security vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cabletron" name="spectrum_enterprise_manager">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1020" published="1998-09-18" name="CVE-1999-1020" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The installation of Novell Netware NDS 5.99 provides an unauthenticated client with Read access for the tree, which allows remote attackers to access sensitive information such as users, groups, and readable objects via CX.EXE and NLIST.EXE.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1364.php" source="XF" patch="1" adv="1">novell-nds(1364)</ref>
      <ref url="http://www.securityfocus.com/bid/484" source="BID" patch="1" adv="1">484</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90613355902262&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19980918 NMRC Advisory - Default NDS Rights</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="netware">
        <vers num="4.1" />
        <vers num="4.11" edition="sp5b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1021" published="1992-12-30" name="CVE-1999-1021" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">NFS on SunOS 4.1 through 4.1.2 ignores the high order 16 bits in a 32 bit UID, which allows a local user to gain root access if the lower 16 bits are set to 0, as fixed by the NFS jumbo patch upgrade.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1992-15.html" source="CERT" patch="1" adv="1">CA-1992-15</ref>
      <ref url="http://www.securityfocus.com/bid/47" source="BID" patch="1" adv="1">47</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/117&amp;type=0&amp;nav=sec.sba" source="SUN" patch="1">00117</ref>
      <ref url="http://xforce.iss.net/static/82.php" source="XF">nfs-uid(82)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1022" published="1994-10-02" name="CVE-1999-1022" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">serial_ports administrative program in IRIX 4.x and 5.x trusts the user's PATH environmental variable to find and execute the ls program, which allows local users to gain root privileges via a Trojan horse ls program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2111.php" source="XF" patch="1" adv="1">sgi-serialports(2111)</ref>
      <ref url="http://www.securityfocus.com/bid/464" source="BID" patch="1" adv="1">464</ref>
      <ref url="http://www.securityfocus.com/archive/1/930" source="BUGTRAQ" adv="1">19941002 </ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="4" />
        <vers num="5.2" />
        <vers num="5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1023" published="1999-06-10" name="CVE-1999-1023" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">useradd in Solaris 7.0 does not properly interpret certain date formats as specified in the "-e" (expiration date) argument, which could allow users to login after their accounts have expired.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/426" source="BID" patch="1" adv="1">426</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92904175406756&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19990610 Sun Useradd program expiration date bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1024" published="2001-11-28" name="CVE-1999-1024" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">ip_print procedure in Tcpdump 3.4a allows remote attackers to cause a denial of service via a packet with a zero length header, which causes an infinite loop and core dump when tcpdump prints the packet.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/313" source="BID" patch="1" adv="1">313</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92989907627051&amp;w=2" source="BUGTRAQ" patch="1">19990620 Re: tcpdump 3.4 bug? (final)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92963447601748&amp;w=2" source="BUGTRAQ" patch="1">19990617 Re: tcpdump 3.4 bug?</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92955903802773&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19990616 tcpdump 3.4  bug?</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lbl" name="tcpdump">
        <vers num="3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1025" published="1998-11-12" name="CVE-1999-1025" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">CDE screen lock program (screenlock) on Solaris 2.6 does not properly lock an unprivileged user's console session when the host is an NIS+ client, which allows others with physical access to login with any string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/294" source="BID" patch="1" adv="1">294</ref>
      <ref url="http://sunsolve.Sun.COM/pub-cgi/retrieve.pl?doc=fpatches%2F106027&amp;zone_32=411568%2A%20" source="SUNBUG" patch="1" adv="1">4115685</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90831127921062&amp;w=2" source="BUGTRAQ">19981012 Annoying Solaris/CDE/NIS+ bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1026" published="1996-12-20" name="CVE-1999-1026" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">aspppd on Solaris 2.5 x86 allows local users to modify arbitrary files and gain root privileges via a symlink attack on the /tmp/.asppp.fifo file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/292" source="BID" adv="1">292</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420343&amp;w=2" source="BUGTRAQ" adv="1">19961220 Solaris 2.5 x86 aspppd (semi-exploitable-hole)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1027" published="1998-05-07" name="CVE-1999-1027" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Solaris 2.6 HW3/98 installs admintool with world-writable permissions, which allows local users to gain privileges by replacing it with a Trojan horse program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/290" source="BID" patch="1" adv="1">290</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101925880&amp;w=2" source="BUGTRAQ" adv="1">19980507 admintool mode 0777 in Solaris 2.6 HW3/98</ref>
      <ref url="http://xforce.iss.net/static/7296.php" source="XF">solaris-admintool-world-writable(7296)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1028" published="1999-05-28" name="CVE-1999-1028" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Symantec pcAnywhere 8.0 allows remote attackers to cause a denial of service (CPU utilization) via a large amount of data to port 5631.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/288" source="BID" patch="1" adv="1">288</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92807524225090&amp;w=2" source="NTBUGTRAQ" adv="1">19990528 DoS against PC Anywhere</ref>
      <ref url="http://www.iss.net/security_center/static/2256.php" source="XF">pcanywhere-dos(2256)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="pcanywhere">
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1029" published="1999-05-13" name="CVE-1999-1029" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SSH server (sshd2) before 2.0.12 does not properly record login attempts if the connection is closed before the maximum number of tries, allowing a remote attacker to guess the password without showing up in the audit logs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2193.php" source="XF" patch="1" adv="1">ssh2-bruteforce(2193)</ref>
      <ref url="http://www.securityfocus.com/bid/277" source="BID" patch="1" adv="1">277</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92663402004280&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19990513 - J.J.F. / Hackers Team warns for SSHD 2.x brute force password hacking</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ssh" name="ssh2">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1030" published="1999-05-19" name="CVE-1999-1030" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">counter.exe 2.70 allows a remote attacker to cause a denial of service (hang) via an HTTP request that ends in %0A (newline), which causes a malformed entry in the counter log that produces an access violation.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/267" source="BID" adv="1">267</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92707671717292&amp;w=2" source="NTBUGTRAQ" adv="1">19990519 Denial of Service in Counter.exe version 2.70</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92713790426690&amp;w=2" source="BUGTRAQ" adv="1">19990519 Denial of Service in Counter.exe version 2.70</ref>
    </refs>
    <vuln_soft>
      <prod vendor="behold_software" name="web_page_counter">
        <vers num="2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1031" published="1999-05-19" name="CVE-1999-1031" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">counter.exe 2.70 allows a remote attacker to cause a denial of service (hang) via a long argument.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/267" source="BID">267</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92707671717292&amp;w=2" source="NTBUGTRAQ">19990519 Denial of Service in Counter.exe version 2.70</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92713790426690&amp;w=2" source="BUGTRAQ">19990519 Denial of Service in Counter.exe version 2.70</ref>
    </refs>
    <vuln_soft>
      <prod vendor="behold_software" name="web_page_counter">
        <vers num="2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1032" published="1991-12-31" name="CVE-1999-1032" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Vulnerability in LAT/Telnet Gateway (lattelnet) on Ultrix 4.1 and 4.2 allows attackers to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1991-11.html" source="CERT" patch="1" adv="1">CA-1991-11</ref>
      <ref url="http://www.securityfocus.com/bid/26" source="BID" patch="1" adv="1">26</ref>
      <ref url="http://xforce.iss.net/static/584.php" source="XF">ultrix-telnet(584)</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/b-36.shtml" source="CIAC">B-36</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digital" name="ultrix">
        <vers num="4.1" />
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1033" published="1999-05-11" name="CVE-1999-1033" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Outlook Express before 4.72.3612.1700 allows a malicious user to send a message that contains a .., which can inadvertently cause Outlook to re-enter POP3 command mode and cause the POP3 session to hang.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/252" source="BID" patch="1" adv="1">252</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92647407427342&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19990511 Outlook Express Win98 bug</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92663402004275&amp;w=2" source="BUGTRAQ">19990512 Outlook Express Win98 bug, addition.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="outlook_express">
        <vers num="4.27.3110.1" />
        <vers num="4.72.3120.0" />
        <vers prev="1" num="4.72.3612.1700" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1034" published="1991-05-23" name="CVE-1999-1034" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in login in AT&amp;T System V Release 4 allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1991-08.html" source="CERT" patch="1" adv="1">CA-1991-08</ref>
      <ref url="http://www.securityfocus.com/bid/23" source="BID" patch="1" adv="1">23</ref>
      <ref url="http://xforce.iss.net/static/583.php" source="XF">sysv-login(583)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/b-28.shtml" source="CIAC">B-28</ref>
    </refs>
    <vuln_soft>
      <prod vendor="att" name="svr4">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1035" published="1999-12-31" name="CVE-1999-1035" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IIS 3.0 and 4.0 on x86 and Alpha allows remote attackers to cause a denial of service (hang) via a malformed GET request, aka the IIS "GET" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms98-019.asp" source="MS" patch="1" adv="1">MS98-019</ref>
      <ref url="http://support.microsoft.com/support/kb/articles/q192/2/96.asp" source="MSKB" patch="1" adv="1">Q192296</ref>
      <ref url="http://xforce.iss.net/static/1823.php" source="XF">iis-get-dos(1823)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="3.0" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1036" published="1998-06-26" name="CVE-1999-1036" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">COPS 1.04 allows local users to overwrite or create arbitrary files via a symlink attack on temporary files in (1) res_diff, (2) ca.src, and (3) mail.chk.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221103125976&amp;w=2" source="BUGTRAQ">19980626 vulnerability in satan, cops &amp; tiger</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cops" name="cops">
        <vers num="1.04" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1037" published="1998-06-26" name="CVE-1999-1037" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">rex.satan in SATAN 1.1.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/rex.$$ file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221103125976&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19980626 vulnerability in satan, cops &amp; tiger</ref>
      <ref url="http://www.osvdb.org/3147" source="OSVDB">3147</ref>
      <ref url="http://www.iss.net/security_center/static/7167.php" source="XF">satan-rexsatan-symlink(7167)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221103125986&amp;w=2" source="BUGTRAQ">19980627 Re: vulnerability in satan, cops &amp; tiger</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coast" name="satan">
        <vers num="1.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1038" published="1998-06-26" name="CVE-1999-1038" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Tiger 2.2.3 allows local users to overwrite arbitrary files via a symlink attack on various temporary files in Tiger's default working directory, as defined by the WORKDIR variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221103125976&amp;w=2" source="BUGTRAQ">19980626 vulnerability in satan, cops &amp; tiger</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tamu" name="tiger">
        <vers num="2.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1039" published="1998-05-27" name="CVE-1999-1039" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in (1) diskalign and (2) diskperf in IRIX 6.4 patches 2291 and 2848 allow a local user to create root-owned files leading to a root compromise.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19980502-01-P3030" source="SGI" patch="1" adv="1">19980502-01-P3030</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1040" published="1998-04-08" name="CVE-1999-1040" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerabilities in (1) ipxchk and (2) ipxlink in NetWare Client 1.0 on IRIX 6.3 and 6.4 allows local users to gain root access via a modified IFS environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/i-055.shtml" source="CIAC" patch="1" adv="1">I-055</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19980501-01-P2869" source="SGI" patch="1" adv="1">19980501-01-P</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=89217373930054&amp;w=2" source="BUGTRAQ">19980408 SGI O2 ipx security issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.3" />
        <vers num="6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1041" published="1998-08-27" name="CVE-1999-1041" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in mscreen on SCO OpenServer 5.0 and SCO UNIX 3.2v4 allows a local user to gain root access via (1) a long TERM environmental variable and (2) a long entry in the .mscreenrc file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/vendor_bulletins/VB-98.10.sco.mscreen" source="CERT" patch="1" adv="1">VB-98.10</ref>
      <ref url="http://www.securityfocus.com/archive/1/10420" source="BUGTRAQ" adv="1">19980827 SCO mscreen vul.</ref>
      <ref url="ftp://ftp.sco.com/SSE/security_bulletins/SB-98.05a" source="SCO">SB-98.05a</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90686250717719&amp;w=2" source="BUGTRAQ">19980926 Root exploit for SCO OpenServer.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="openserver">
        <vers num="5.0" />
      </prod>
      <prod vendor="sco" name="unix">
        <vers num="3.2v4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1042" published="1999-12-31" name="CVE-1999-1042" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">Cisco Resource Manager (CRM) 1.0 and 1.1 creates world-readable log files and temporary files, which may expose sensitive information, to local users such as user IDs, passwords and SNMP community strings.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/770/crmtmp-pub.shtml" source="CISCO" patch="1" adv="1">19980813 CRM Temporary File Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="resource_manager">
        <vers num="1.0" />
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1043" published="1999-12-31" name="CVE-1999-1043" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Exchange Server 5.5 and 5.0 does not properly handle (1) malformed NNTP data, or (2) malformed SMTP data, which allows remote attackers to cause a denial of service (application error).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms98-007.asp" source="MS" patch="1" adv="1">MS98-007</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="5.0" />
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1044" published="1998-05-07" name="CVE-1999-1044" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Vulnerability in Advanced File System Utility (advfs) in Digital UNIX 4.0 through 4.0d allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/i-050.shtml" source="COMPAQ" patch="1" adv="1">SSRT0495U</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/i-050.shtml" source="CIAC">I-050</ref>
      <ref url="http://www.iss.net/security_center/static/7431.php" source="XF">dgux-advfs-softlinks(7431)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digital" name="unix">
        <vers num="v4.0" />
        <vers prev="1" num="v4.0d" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1045" published="1998-01-15" name="CVE-1999-1045" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">pnserver in RealServer 5.0 and earlier allows remote attackers to cause a denial of service by sending a short, malformed request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://service.real.com/help/faq/serv501.html" source="MISC" patch="1">http://service.real.com/help/faq/serv501.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90338245305236&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19980817 Re: Real Audio Server Version 5 bug?</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88492978527261&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19980115 pnserver exploit..</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88490880523890&amp;w=2" source="BUGTRAQ" adv="1">19980115 [rootshell] Security Bulletin #7</ref>
      <ref url="http://www.osvdb.org/6979" source="OSVDB">6979</ref>
      <ref url="http://www.iss.net/security_center/static/7297.php" source="XF">realserver-pnserver-remote-dos(7297)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realserver">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1046" published="1999-03-01" name="CVE-1999-1046" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in IMonitor in IMail 5.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to port 8181.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1897.php" source="XF">imail-imonitor-overflow(1897)</ref>
      <ref url="http://www.securityfocus.com/bid/504" source="BID">504</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92038879607336&amp;w=2" source="BUGTRAQ">19990302 Multiple IMail Vulnerabilites</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="imail">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1047" published="1999-10-18" name="CVE-1999-1047" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">When BSDI patches for Gauntlet 5.0 BSDI are installed in a particular order, Gauntlet allows remote attackers to bypass firewall access restrictions, and does not log the activities.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94026690521279&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19991018 Gauntlet 5.0 BSDI warning</ref>
      <ref url="http://www.iss.net/security_center/static/3397.php" source="XF">gauntlet-bsdi-bypass(3397)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94036662326185&amp;w=2" source="BUGTRAQ">19991019 Re: Gauntlet 5.0 BSDI warning</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bsdi" name="gauntlet">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1048" published="1998-09-05" name="CVE-1999-1048" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in bash 2.0.0, 1.4.17, and other versions allows local attackers to gain privileges by creating an extremely large directory name, which is inserted into the password prompt via the \w option in the PS1 environmental variable when another user changes into that directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3414.php" source="XF" patch="1" adv="1">linux-bash-bo(3414)</ref>
      <ref url="http://www.debian.org/security/1998/19980909" source="DEBIAN" patch="1" adv="1">19980909 problem with very long pathnames</ref>
      <ref url="http://www.securityfocus.com/archive/1/10542" source="BUGTRAQ" adv="1">19980905 BASH buffer overflow, LiNUX x86 exploit</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602746719555&amp;w=2" source="BUGTRAQ" adv="1">19970821 Buffer overflow in /bin/bash</ref>
      <ref url="http://www.osvdb.org/8345" source="OSVDB">8345</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="1.3.1" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1049" published="1999-02-21" name="CVE-1999-1049" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">ARCserve NT agents use weak encryption (XOR) for passwords, which allows remote attackers to sniff the authentication request to port 6050 and decrypt the password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91972006211238&amp;w=2" source="BUGTRAQ">19990222 Severe Security Hole in ARCserve NT agents (fwd)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="arcserve_backup">
        <vers prev="1" num="6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1050" published="1999-11-12" name="CVE-1999-1050" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Matt Wright FormHandler.cgi script allows remote attackers to read arbitrary files via (1) a .. (dot dot) in the reply_message_attach attachment parameter, or (2) by specifying the filename as a template.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3550.php" source="XF" adv="1">formhandler-cgi-absolute-path(3550)</ref>
      <ref url="http://www.securityfocus.com/bid/799" source="BID" adv="1">799</ref>
      <ref url="http://www.securityfocus.com/bid/798" source="BID" adv="1">798</ref>
      <ref url="http://www.securityfocus.com/archive/1/34939" source="BUGTRAQ" adv="1">19991116 Re: FormHandler.cgi</ref>
      <ref url="http://www.securityfocus.com/archive/1/34600" source="BUGTRAQ">19991112 FormHandler.cgi</ref>
    </refs>
    <vuln_soft>
      <prod vendor="matt_wright" name="formhandler.cgi">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1051" published="1999-11-16" name="CVE-1999-1051" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Default configuration in Matt Wright FormHandler.cgi script allows arbitrary directories to be used for attachments, and only restricts access to the /etc/ directory, which allows remote attackers to read arbitrary files via the reply_message_attach attachment parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/34939" source="BUGTRAQ" adv="1">19991116 Re: FormHandler.cgi</ref>
    </refs>
    <vuln_soft>
      <prod vendor="matt_wright" name="formhandler.cgi">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1052" published="1999-08-24" name="CVE-1999-1052" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft FrontPage stores form results in a default location in /_private/form_results.txt, which is world-readable and accessible in the document root, which allows remote attackers to read possibly sensitive information submitted by other users.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93582550911564&amp;w=2" source="BUGTRAQ" adv="1">19990824 Front Page form_results</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="frontpage">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1053" published="1999-09-13" name="CVE-1999-1053" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">guestbook.pl cleanses user-inserted SSI commands by removing text between "&lt;!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides "-->".</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/776" source="BID" patch="1" adv="1">776</ref>
      <ref url="http://www.securityfocus.com/archive/82/27560" source="VULN-DEV" adv="1">19990916 Re: Guestbook perl script (error fix)</ref>
      <ref url="http://www.securityfocus.com/archive/82/27296" source="VULN-DEV" adv="1">19990913 Guestbook perl script (long)</ref>
      <ref url="http://www.securityfocus.com/archive/1/33674" source="BUGTRAQ" adv="1">19991105 Guestbook.pl, sloppy SSI handling in Apache? (VD#2)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="1.3.9" />
      </prod>
      <prod vendor="matt_wright" name="matt_wright_guestbook">
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1054" published="1998-09-25" name="CVE-1999-1054" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The default configuration of FLEXlm license manager 6.0d, and possibly other versions, allows remote attackers to shut down the server via the lmdown command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90675672323825&amp;w=2" source="BUGTRAQ" adv="1">19980925 Globetrotter  FlexLM 'lmdown' bogosity</ref>
    </refs>
    <vuln_soft>
      <prod vendor="globetrotter" name="flexlm">
        <vers num="6.0d" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1055" published="1999-12-31" name="CVE-1999-1055" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Microsoft Excel 97 does not warn the user before executing worksheet functions, which could allow attackers to execute arbitrary commands by using the CALL function to execute a malicious DLL, aka the Excel "CALL Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1737.php" source="XF" patch="1" adv="1">excel-call(1737)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms98-018.asp" source="MS" patch="1" adv="1">MS98-018</ref>
      <ref url="http://www.securityfocus.com/bid/179" source="BID">179</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="97" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="1999-1056" reject="1" published="1992-12-31" name="CVE-1999-1056" modified="2008-09-09">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-1395.  Reason: This candidate is a duplicate of CVE-1999-1395.  Notes: All CVE users should reference CVE-1999-1395 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1057" published="1990-10-25" name="CVE-1999-1057" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">VMS 4.0 through 5.3 allows local users to gain privileges via the ANALYZE/PROCESS_DUMP dcl command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1990-07.html" source="CERT" patch="1" adv="1">CA-1990-07</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/b-04.shtml" source="CIAC" patch="1" adv="1">B-04</ref>
      <ref url="http://www.securityfocus.com/bid/12" source="BID">12</ref>
      <ref url="http://www.iss.net/security_center/static/7137.php" source="XF">vms-analyze-processdump-privileges(7137)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digital" name="vms">
        <vers prev="1" num="5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1058" published="1999-11-22" name="CVE-1999-1058" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Vermillion FTP Daemon VFTPD 1.23 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via several long CWD commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3543.php" source="XF" patch="1" adv="1">vermillion-ftp-cwd-overflow(3543)</ref>
      <ref url="http://www.securityfocus.com/bid/818" source="BID">818</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94329968617085&amp;w=2" source="BUGTRAQ" adv="1">19991122 Remote DoS Attack in Vermillion FTP Daemon (VFTPD) v1.23 Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94337185023159&amp;w=2" source="NTBUGTRAQ">19991122 Remote DoS Attack in Vermillion FTP Daemon (VFTPD) v1.23 Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="arcane_software" name="vermillion_ftp_daemon">
        <vers num="1.23" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1059" published="1992-02-25" name="CVE-1999-1059" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Vulnerability in rexec daemon (rexecd) in AT&amp;T TCP/IP 4.0 for various SVR4 systems allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1992-04.html" source="CERT" patch="1" adv="1">CA-1992-04</ref>
      <ref url="http://www.securityfocus.com/bid/36" source="BID">36</ref>
      <ref url="http://www.iss.net/security_center/static/3159.php" source="XF">att-rexecd(3159)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="att" name="svr4">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1060" published="1999-02-17" name="CVE-1999-1060" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Tetrix TetriNet daemon 1.13.16 allows remote attackers to cause a denial of service and possibly execute arbitrary commands by connecting to port 31457 from a host with a long DNS hostname.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/340" source="BID" patch="1">340</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91937090211855&amp;w=2" source="BUGTRAQ" patch="1">19990217 Tetrix 1.13.16 is Vulnerable</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tetrix" name="tetrinet">
        <vers num="1.13.16" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1061" published="1997-10-04" name="CVE-1999-1061" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">HP Laserjet printers with JetDirect cards, when configured with TCP/IP, can be configured without a password, which allows remote attackers to connect to the printer and change its IP address or disable logging.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1876.php" source="XF" patch="1" adv="1">laserjet-unpassworded(1876)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602248518480&amp;w=2" source="BUGTRAQ" adv="1">19971004 HP Laserjet 4M Plus DirectJet Problem</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="jetdirect">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1062" published="1997-10-04" name="CVE-1999-1062" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">HP Laserjet printers with JetDirect cards, when configured with TCP/IP, allow remote attackers to bypass print filters by directly sending PostScript documents to TCP ports 9099 and 9100.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1876.php" source="XF" patch="1" adv="1">laserjet-unpassworded(1876)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602248518480&amp;w=2" source="BUGTRAQ" adv="1">19971004 HP Laserjet 4M Plus DirectJet Problem</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="jetdirect">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1063" published="1999-06-01" name="CVE-1999-1063" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">CDomain whois_raw.cgi whois CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the fqdn parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2251.php" source="XF" patch="1" adv="1">http-cgi-cdomain(2251)</ref>
      <ref url="http://www.securityfocus.com/bid/304" source="BID">304</ref>
      <ref url="http://www.securityfocus.com/archive/1/14019" source="BUGTRAQ" adv="1">19990601 whois_raw.cgi problem</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cdomain" name="cdomainfree">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1064" published="1999-08-22" name="CVE-1999-1064" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in WindowMaker 0.52 through 0.60.0 allow attackers to cause a denial of service and possibly execute arbitrary commands by executing WindowMaker with a long program name (argv[0]).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/596" source="BID">596</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93582070508957&amp;w=2" source="BUGTRAQ" adv="1">19990824 Re: WindowMaker bugs (was sub:none )</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93555317429630&amp;w=2" source="BUGTRAQ" adv="1">19990822</ref>
    </refs>
    <vuln_soft>
      <prod vendor="windowmaker" name="windowmaker">
        <vers prev="1" num="0.60.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1065" published="1999-11-04" name="CVE-1999-1065" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Palm Pilot HotSync Manager 3.0.4 in Windows 98 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to port 14238 while the manager is in network mode.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94175465525422&amp;w=2" source="BUGTRAQ" adv="1">19991104 Palm Hotsync vulnerable to DoS attack</ref>
    </refs>
    <vuln_soft>
      <prod vendor="palm_pilot" name="hotsync_manager">
        <vers num="3.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1066" published="1999-12-22" name="CVE-1999-1066" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Quake 1 server responds to an initial UDP game connection request with a large amount of traffic, which allows remote attackers to use the server as an amplifier in a "Smurf" style attack on another host, by spoofing the connection request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94589559631535&amp;w=2" source="BUGTRAQ" adv="1">19991222 Quake "smurf" - Quake War Utils</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="quake_1_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1067" published="1997-05-07" name="CVE-1999-1067" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SGI MachineInfo CGI program, installed by default on some web servers, prints potentially sensitive system status information, which could be used by remote attackers for information gathering activities.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420919&amp;w=2" source="BUGTRAQ">19970507 Re: SGI Security Advisory 19970501-01-A - Vulnerability in webdist.cgi</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1068" published="1997-07-23" name="CVE-1999-1068" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Oracle Webserver 2.1, when serving PL/SQL stored procedures, allows remote attackers to cause a denial of service via a long HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602661419366&amp;w=2" source="BUGTRAQ" adv="1">19970723 DoS against Oracle Webserver 2.1 with PL/SQL stored procedures</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="http_server">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1069" published="1997-11-08" name="CVE-1999-1069" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in carbo.dll in iCat Carbo Server 3.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the icatcommand parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1620.php" source="XF" patch="1" adv="1">icat-carbo-server-vuln(1620)</ref>
      <ref url="http://www.securityfocus.com/bid/2126" source="BID" adv="1">2126</ref>
      <ref url="http://www.securityfocus.com/archive/1/7943" source="BUGTRAQ" adv="1">19971108 Security bug in iCat Suite version 3.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="icat" name="electronic_commerce_suite">
        <vers num="3.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1070" published="1998-07-25" name="CVE-1999-1070" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in ping CGI program in Xylogics Annex terminal service allows remote attackers to cause a denial of service via a long query parameter.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/10021" source="BUGTRAQ" adv="1">19980725 Annex DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xylogics" name="annex">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1071" published="1998-11-30" name="CVE-1999-1071" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Excite for Web Servers (EWS) 1.1 installs the Architext.conf authentication file with world-writeable permissions, which allows local users to gain access to Excite accounts by modifying the file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1417.php" source="XF" patch="1" adv="1">excite-world-write(1417)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91248445931140&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19981130 Security bugs in Excite for Web Servers 1.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="excite" name="ews">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1072" published="1998-11-30" name="CVE-1999-1072" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Excite for Web Servers (EWS) 1.1 allows local users to gain privileges by obtaining the encrypted password from the world-readable Architext.conf authentication file and replaying the encrypted password in an HTTP request to AT-generated.cgi or AT-admin.cgi.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91248445931140&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19981130 Security bugs in Excite for Web Servers 1.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="excite" name="ews">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1073" published="1998-11-30" name="CVE-1999-1073" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Excite for Web Servers (EWS) 1.1 records the first two characters of a plaintext password in the beginning of the encrypted password, which makes it easier for an attacker to guess passwords via a brute force or dictionary attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91248445931140&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19981130 Security bugs in Excite for Web Servers 1.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="excite" name="ews">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1074" published="1999-12-31" name="CVE-1999-1074" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Webmin before 0.5 does not restrict the number of invalid passwords that are entered for a valid username, which could allow remote attackers to gain privileges via brute force password cracking.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/9138" source="BUGTRAQ" patch="1" adv="1">19980501 Warning! Webmin Security Advisory</ref>
      <ref url="http://www.webmin.com/webmin/changes.html" source="CONFIRM" adv="1">http://www.webmin.com/webmin/changes.html</ref>
      <ref url="http://www.securityfocus.com/bid/98" source="BID">98</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webmin" name="webmin">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.21" />
        <vers num="0.22" />
        <vers num="0.3" />
        <vers num="0.31" />
        <vers num="0.4" />
        <vers num="0.41" />
        <vers num="0.42" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1075" published="1998-03-18" name="CVE-1999-1075" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">inetd in AIX 4.1.5 dynamically assigns a port N when starting ttdbserver (ToolTalk server), but also inadvertently listens on port N-1 without passing control to ttdbserver, which allows remote attackers to cause a denial of service via a large number of connections to port N-1, which are not properly closed by inetd.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=89025820612530&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19980318 AIX 4.1.5 DoS attack (aka "Port 1025 problem")</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1076" published="1999-10-26" name="CVE-1999-1076" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Idle locking function in MacOS 9 allows local users to bypass the password protection of idled sessions by selecting the "Log Out" option and selecting a "Cancel" option in the dialog box for an application that attempts to verify that the user wants to log out, which returns the attacker into the locked session.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/745" source="BID" adv="1">745</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94096348604173&amp;w=2" source="BUGTRAQ" adv="1">19991026 Mac OS 9 Idle Lock Bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os">
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1077" published="1999-11-01" name="CVE-1999-1077" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Idle locking function in MacOS 9 allows local attackers to bypass the password protection of idled sessions via the programmer's switch or CMD-PWR keyboard sequence, which brings up a debugger that the attacker can use to disable the lock.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/756" source="BID" adv="1">756</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94149318124548&amp;w=2" source="BUGTRAQ" adv="1">19991101 Re: Mac OS 9 Idle Lock Bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os">
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1078" published="1999-07-29" name="CVE-1999-1078" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">WS_FTP Pro 6.0 uses weak encryption for passwords in its initialization files, which allows remote attackers to easily decrypt the passwords and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/547" source="BID">547</ref>
      <ref url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind9907&amp;L=ntbugtraq&amp;D=0&amp;P=10370&amp;F=P" source="NTBUGTRAQ" adv="1">19990729 WS_FTP Pro 6.0 Weak Password Encryption Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="ws_ftp_pro">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1079" published="1999-05-06" name="CVE-1999-1079" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Vulnerability in ptrace in AIX 4.3 allows local users to gain privileges by attaching to a setgid program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/439" source="BID" patch="1" adv="1">439</ref>
      <ref url="http://www-1.ibm.com/servlet/support/manager?rs=0&amp;rt=0&amp;org=apars&amp;doc=08E0B1A1B85472A1852567C90031BB36" source="AIXAPAR">IX80470</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93587956513233&amp;w=2" source="BUGTRAQ">19990825 AIX security summary</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92601792420088&amp;w=2" source="BUGTRAQ">19990506 AIX Security Fixes Update</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="3.2.5" />
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
        <vers num="4.2" />
        <vers num="4.2.1" />
        <vers num="4.3" />
        <vers num="4.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1080" published="1995-05-10" name="CVE-1999-1080" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">rmmount in SunOS 5.7 may mount file systems without the nosuid flag set, contrary to the documentation and its use in previous versions of SunOS, which could allow local users with physical access to gain root privileges by mounting a floppy or CD-ROM that contains a setuid program and running volcheck, when the file systems do not have the nosuid option specified in rmmount.conf.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92633694100270&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19990510 SunOS 5.7 rmmount, no nosuid.</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93971288323395&amp;w=2" source="BUGTRAQ" adv="1">19991011</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/8350" source="XF">solaris-rmmount-gain-root(8350)</ref>
      <ref url="http://www.securityfocus.com/bid/250" source="BID">250</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="5.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1081" published="2002-01-15" name="CVE-1999-1081" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Vulnerability in files.pl script in Novell WebServer Examples Toolkit 2 allows remote attackers to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2054.php" source="XF" patch="1" adv="1">http-nov-files(2054)</ref>
      <ref url="http://www.w3.org/Security/Faq/wwwsf8.html#Q87" source="MISC">http://www.w3.org/Security/Faq/wwwsf8.html#Q87</ref>
      <ref url="http://www.roxanne.org/faqs/www-secure/wwwsf4.html#Q35" source="MISC">http://www.roxanne.org/faqs/www-secure/wwwsf4.html#Q35</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="web_server">
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":examples_toolkit" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1082" published="1999-10-08" name="CVE-1999-1082" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Jana proxy web server 1.40 allows remote attackers to ready arbitrary files via a "......" (modified dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/699" source="BID" adv="1">699</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93941794201059&amp;w=2" source="BUGTRAQ">19991008 Jana webserver exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="t._hauck" name="jana_web_server">
        <vers num="1.0" />
        <vers num="1.40" />
        <vers num="1.45" />
        <vers num="1.46" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1083" published="1999-10-08" name="CVE-1999-1083" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Jana proxy web server 1.45 allows remote attackers to ready arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/699" source="BID">699</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95730430727064&amp;w=2" source="BUGTRAQ">20000502 Security Bug in Jana HTTP Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="t._hauck" name="jana_web_server">
        <vers num="1.0" />
        <vers num="1.45" />
        <vers num="1.46" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1084" published="1999-12-31" name="CVE-1999-1084" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The "AEDebug" registry key is installed with insecure permissions, which allows local users to modify the key to specify a Trojan Horse debugger which is automatically executed on a system crash.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1044" source="BID" patch="1" adv="1">1044</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-008.asp" source="MS" patch="1" adv="1">MS00-008</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/k-029.shtml" source="CIAC" patch="1" adv="1">K-029</ref>
      <ref url="http://support.microsoft.com/support/kb/articles/q103/8/61.asp" source="MSKB" patch="1" adv="1">Q103861</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=90222453431604&amp;w=2" source="NTBUGTRAQ">19980622 Yet another "get yourself admin rights exploit":</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition=":server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1085" published="1998-06-12" name="CVE-1999-1085" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SSH 1.2.25, 1.2.23, and other versions, when used in in CBC (Cipher Block Chaining) or CFB (Cipher Feedback 64 bits) modes, allows remote attackers to insert arbitrary data into an existing stream between an SSH client and server by using a known plaintext attack and computing a valid CRC-32 checksum for the packet, aka the "SSH insertion attack."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/13877" source="CERT-VN">VU#13877</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525878&amp;w=2" source="BUGTRAQ" patch="1">19980703 UPDATE: SSH insertion attack</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221103125884&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19980612 CORE-SDI-04: SSH insertion attack</ref>
      <ref url="http://www.iss.net/security_center/static/1126.php" source="XF">ssh-insert(1126)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ssh" name="secure_shell">
        <vers num="1.2.23" />
        <vers num="1.2.25" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1086" published="1999-07-15" name="CVE-1999-1086" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Novell 5 and earlier, when running over IPX with a packet signature level less than 3, allows remote attackers to gain administrator privileges by spoofing the MAC address in IPC fragmented packets that make NetWare Core Protocol (NCP) calls.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/528" source="BID" patch="1" adv="1">528</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93214475111651&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19990715 NMRC Advisory: Netware 5 Client Hijacking</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="netware">
        <vers num="4.1" />
        <vers num="4.11" edition="sp5b" />
        <vers prev="1" num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1087" published="1999-12-31" name="CVE-1999-1087" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Internet Explorer 4 treats a 32-bit number ("dotless IP address") in the a URL as the hostname instead of an IP address, which causes IE to apply Local Intranet Zone settings to the resulting web page, allowing remote malicious web servers to conduct unauthorized activities by using URLs that contain the dotless IP address for their server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2209.php" source="XF" patch="1" adv="1">ie-dotless(2209)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS98-016.asp" source="MS" patch="1" adv="1">MS98-016</ref>
      <ref url="http://support.microsoft.com/support/kb/articles/q168/6/17.asp" source="MSKB" patch="1" adv="1">Q168617</ref>
      <ref url="http://www.microsoft.com/Windows/Ie/security/dotless.asp" source="CONFIRM">http://www.microsoft.com/Windows/Ie/security/dotless.asp</ref>
      <ref url="http://www.osvdb.org/7828" source="OSVDB">7828</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.0" />
        <vers num="4.0.1" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1088" published="1997-01-09" name="CVE-1999-1088" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in chsh command in HP-UX 9.X through 10.20 allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2012.php" source="XF" patch="1" adv="1">hp-chsh(2012)</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/h-21.shtml" source="CIAC" patch="1" adv="1">H-21</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.00" />
        <vers num="10.01" />
        <vers prev="1" num="10.02" />
        <vers num="10.10" />
        <vers num="10.20" />
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1089" published="1996-12-13" name="CVE-1999-1089" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in chfn command in HP-UX 9.X through 10.20 allows local users to gain privileges via a long command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/h-21.shtml" source="CIAC" patch="1" adv="1">H-21</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/h-16.shtml" source="CIAC" patch="1" adv="1">H-16</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420285&amp;w=2" source="BUGTRAQ" adv="1">19961209 the HP Bug of the Week!</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10" />
        <vers prev="1" num="10.20" />
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1090" published="1991-09-10" name="CVE-1999-1090" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The default configuration of NCSA Telnet package for Macintosh and PC enables FTP, even though it does not include an "ftp=yes" line, which allows remote attackers to read and modify arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1991-15.html" source="CERT" patch="1" adv="1">CA-1991-15</ref>
      <ref url="http://xforce.iss.net/static/1844.php" source="XF" patch="1" adv="1">ftp-ncsa(1844)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ncsa" name="telnet">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1091" published="2002-01-15" name="CVE-1999-1091" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">UNIX news readers tin and rtin create the /tmp/.tin_log file with insecure permissions and follow symlinks, which allows attackers to modify the permissions of files writable by the user via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/431.php" source="XF" patch="1" adv="1">tin-tmpfile(431)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420726&amp;w=2" source="BUGTRAQ">19970329 symlink bug in tin/rtin</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167419839&amp;w=2" source="BUGTRAQ">19960903 Re: BoS:      [BUG] Vulnerability in TIN</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167419835&amp;w=2" source="BUGTRAQ">19960903 [BUG] Vulnerability in TIN</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rtin" name="rtin">
        <vers num="" />
      </prod>
      <prod vendor="tin" name="tin">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1092" published="1999-11-17" name="CVE-1999-1092" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">tin 1.40 creates the .tin directory with insecure permissions, which allows local users to read passwords from the .inputhistory file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94286179032648&amp;w=2" source="BUGTRAQ" adv="1">19991117 default permissions for tin</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iain_lea" name="tin">
        <vers num="1.40" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1093" published="1999-12-31" name="CVE-1999-1093" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in the Window.External function in the JScript Scripting Engine in Internet Explorer 4.01 SP1 and earlier allows remote attackers to execute arbitrary commands via a malicious web page.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS98-011.asp" source="MS" patch="1" adv="1">MS98-011</ref>
      <ref url="http://www.iss.net/security_center/static/1276.php" source="XF">java-script-patch(1276)</ref>
      <ref url="http://support.microsoft.com/support/kb/articles/q191/2/00.asp" source="MSKB">Q191200</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.0" />
        <vers prev="1" num="4.0.1" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1094" published="1999-12-31" name="CVE-1999-1094" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Internet Explorer 4.01 and earlier allows remote attackers to execute arbitrary commands via a long URL with the "mk:" protocol, aka the "MK Overrun security issue."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/917.php" source="XF" patch="1" adv="1">iemk-bug(917)</ref>
      <ref url="http://support.microsoft.com/support/kb/articles/q176/6/97.asp" source="MSKB" patch="1" adv="1">Q176697</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88480839506155&amp;w=2" source="BUGTRAQ" adv="1">19980114 L0pht Advisory MSIE4.0(1)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers prev="1" num="4.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1095" published="1997-10-06" name="CVE-1999-1095" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">sort creates temporary files and follows symbolic links, which allows local users to modify arbitrary files that are writable by the user running sort, as observed in updatedb and other programs that use sort.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88890116304676&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19980303 updatedb stuff</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87619953510834&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19971006 KSR[T] Advisory #3: updatedb / crontabs</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88886870129518&amp;w=2" source="BUGTRAQ" adv="1">19980302 overwrite any file with updatedb</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="4.1" />
      </prod>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1096" published="1998-05-16" name="CVE-1999-1096" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in kscreensaver in KDE klock allows local users to gain root privileges via a long HOME environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1644.php" source="XF" patch="1" adv="1">kde-klock-home-bo(1644)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101925959&amp;w=2" source="BUGTRAQ" patch="1">19980517 simple kde exploit fix</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101925954&amp;w=2" source="BUGTRAQ">19980516 kde exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="kde">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1097" published="1999-05-04" name="CVE-1999-1097" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Microsoft NetMeeting 2.1 allows one client to read the contents of another client's clipboard via a CTRL-C in the chat box when the box is empty.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2187.php" source="XF" adv="1">netmeeting-clipboard(2187)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92586457816446&amp;w=2" source="BUGTRAQ">19990504 Microsoft Netmeeting Hole</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="netmeeting">
        <vers prev="1" num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1098" published="1995-03-03" name="CVE-1999-1098" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Vulnerability in BSD Telnet client with encryption and Kerberos 4 authentication allows remote attackers to decrypt the session via sniffing.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1995-03.html" source="CERT" patch="1" adv="1">CA-1995-03</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/f-12.shtml" source="CIAC" patch="1" adv="1">F-12</ref>
      <ref url="http://www.osvdb.org/4881" source="OSVDB">4881</ref>
      <ref url="http://www.iss.net/security_center/static/516.php" source="XF">bsd-telnet(516)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bsd" name="bsd">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1099" published="1996-11-22" name="CVE-1999-1099" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Kerberos 4 allows remote attackers to obtain sensitive information via a malformed UDP packet that generates an error string that inadvertently includes the realm name and the last user.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/65.php" source="XF" patch="1" adv="1">kerberos-user-grab(65)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420184&amp;w=2" source="BUGTRAQ" adv="1">19961122 L0pht Kerberos Advisory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kth" name="kth_kerberos">
        <vers num="4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1100" published="1999-12-31" name="CVE-1999-1100" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cisco PIX Private Link 4.1.6 and earlier does not properly process certain commands in the configuration file, which reduces the effective key length of the DES key to 48 bits instead of 56 bits, which makes it easier for an attacker to find the proper key via a brute force attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1579.php" source="XF" patch="1" adv="1">cisco-pix-parse-error(1579)</ref>
      <ref url="http://www.cisco.com/warp/public/770/pixkey-pub.shtml" source="CISCO" patch="1" adv="1">19980616 PIX Private Link Key Processing and Cryptography Issues</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/i-056.shtml" source="CIAC">I-056</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="pix_private_link">
        <vers prev="1" num="4.1(6)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1101" published="1999-02-19" name="CVE-1999-1101" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Kabsoftware Lydia utility uses weak encryption to store user passwords in the lydia.ini file, which allows local users to easily decrypt the passwords and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/12618" source="BUGTRAQ">19990219 Yet Another password storing problem (was: Re: Possible Netscape Crypto Security Flaw)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kab_software" name="lydia">
        <vers prev="1" num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1102" published="1999-12-31" name="CVE-1999-1102" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">lpr on SunOS 4.1.1, BSD 4.3, A/UX 2.0.1, and other BSD-based operating systems allows local users to create or overwrite arbitrary files via a symlink attack that is triggered after invoking lpr 1000 times.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/e-25.shtml" source="CIAC" patch="1" adv="1">E-25a</ref>
      <ref url="http://www.phreak.org/archives/security/8lgm/8lgm.lpr" source="MISC" adv="1">http://www.phreak.org/archives/security/8lgm/8lgm.lpr</ref>
      <ref url="http://www.aenigma.net/resources/maillist/bugtraq/1994/0091.htm" source="BUGTRAQ">19940307 8lgm Advisory Releases</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="a_ux">
        <vers num="2.0.1" />
      </prod>
      <prod vendor="bsd" name="bsd">
        <vers num="4.3" />
      </prod>
      <prod vendor="sgi" name="irix">
        <vers prev="1" num="5.2" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers prev="1" num="4.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1103" published="1996-04-03" name="CVE-1999-1103" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">dxconsole in DEC OSF/1 3.2C and earlier allows local users to read arbitrary files by specifying the file with the -file parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/vendor_bulletins/VB-96.05.dec" source="CERT" patch="1" adv="1">VB-96.05</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/g-18.shtml" source="CIAC" patch="1" adv="1">G-18</ref>
      <ref url="http://www.tao.ca/fire/bos/0209.html" source="MISC">http://www.tao.ca/fire/bos/0209.html</ref>
      <ref url="http://www.iss.net/security_center/static/7138.php" source="XF">osf-dxconsole-gain-privileges(7138)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digital" name="osf_1">
        <vers prev="1" num="3.2c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1104" published="1999-12-31" name="CVE-1999-1104" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Windows 95 uses weak encryption for the password list (.pwl) file used when password caching is enabled, which allows local users to gain privileges by decrypting the passwords.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=88540877601866&amp;w=2" source="NTBUGTRAQ" adv="1">19980121 How to recover private keys for various Microsoft products</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88536273725787&amp;w=2" source="BUGTRAQ" adv="1">19980120 How to recover private keys for various Microsoft products</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167418931&amp;w=2" source="BUGTRAQ" adv="1">19951205 Cracked: WINDOWS.PWL</ref>
      <ref url="http://www.iss.net/security_center/static/71.php" source="XF">win95-nbsmbpwl(71)</ref>
      <ref url="http://support.microsoft.com/support/kb/articles/q140/5/57.asp" source="MSKB">Q140557</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_95">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1105" published="1999-12-31" name="CVE-1999-1105" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Windows 95, when Remote Administration and File Sharing for NetWare Networks is enabled, creates a share (C$) when an administrator logs in remotely, which allows remote attackers to read arbitrary files by mapping the network drive.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.zdnet.com/eweek/reviews/1016/tr42bug.html" source="CONFIRM" patch="1" adv="1">http://www.zdnet.com/eweek/reviews/1016/tr42bug.html</ref>
      <ref url="http://www.net-security.sk/bugs/NT/netware1.html" source="MISC" patch="1" adv="1">http://www.net-security.sk/bugs/NT/netware1.html</ref>
      <ref url="http://www.iss.net/security_center/static/7231.php" source="XF">win95-netware-hidden-share(7231)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_95">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1106" published="1998-04-29" name="CVE-1999-1106" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in kppp in KDE allows local users to gain root access via a long -c (account_name) command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1643.php" source="XF" patch="1" adv="1">kde-kppp-account-bo(1643)</ref>
      <ref url="http://www.securityfocus.com/bid/92" source="BID">92</ref>
      <ref url="http://www.securityfocus.com/archive/1/9121" source="BUGTRAQ" adv="1">19980429 Security hole in kppp</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="kde">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1107" published="1998-11-18" name="CVE-1999-1107" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in kppp in KDE allows local users to gain root access via a long PATH environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1650.php" source="XF" patch="1" adv="1">kde-kppp-path-bo(1650)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91141486301691&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19981118 Multiple KDE security vulnerabilities (root compromise)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="kde">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="1999-1108" reject="1" published="1998-11-18" name="CVE-1999-1108" modified="2008-09-09">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-1107.  Reason: This candidate is a duplicate of CVE-1999-1107.  Notes: All CVE users should reference CVE-1999-1107 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1109" published="1999-12-22" name="CVE-1999-1109" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sendmail before 8.10.0 allows remote attackers to cause a denial of service by sending a series of ETRN commands then disconnecting from the server, while Sendmail continues to process the commands after the connection has been terminated.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94780566911948&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20000113 Re: procmail / Sendmail - five bugs</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94632241202626&amp;w=2" source="BUGTRAQ" adv="1">19991222 Re: procmail / Sendmail - five bugs</ref>
      <ref url="http://www.securityfocus.com/bid/904" source="BID">904</ref>
      <ref url="http://www.iss.net/security_center/static/7760.php" source="XF">sendmail-etrn-dos(7760)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sendmail" name="sendmail">
        <vers prev="1" num="8.10.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1110" published="1999-11-14" name="CVE-1999-1110" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Windows Media Player ActiveX object as used in Internet Explorer 5.0 returns a specific error code when a file does not exist, which allows remote malicious web sites to determine the existence of files on the client.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/793" source="BID" patch="1" adv="1">793</ref>
      <ref url="http://www.securityfocus.com/archive/1/34675" source="BUGTRAQ" patch="1" adv="1">19991114 IE 5.0 and Windows Media Player ActiveX object allow checking the existence of local files and directories</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1111" published="1999-11-09" name="CVE-1999-1111" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Vulnerability in StackGuard before 1.21 allows remote attackers to bypass the Random and Terminator Canary security mechanisms by using a non-linear attack which directly modifies a pointer to a return address instead of using a buffer overflow to reach the return address entry itself.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3524.php" source="XF" patch="1" adv="1">immunix-stackguard-bo(3524)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94218618329838&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19911109 ImmuniX OS Security Alert: StackGuard 1.21 Released</ref>
      <ref url="http://www.securityfocus.com/bid/786" source="BID">786</ref>
    </refs>
    <vuln_soft>
      <prod vendor="immunix" name="stackguard">
        <vers prev="1" num="1.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1112" published="1999-11-09" name="CVE-1999-1112" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in IrfanView32 3.07 and earlier allows attackers to execute arbitrary commands via a long string after the "8BPS" image type in a Photo Shop image header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3549.php" source="XF" patch="1" adv="1">irfan-view32-bo(3549)</ref>
      <ref url="http://www.securityfocus.com/bid/781" source="BID" patch="1" adv="1">781</ref>
      <ref url="http://www.securityfocus.com/archive/1/34066" source="BUGTRAQ" adv="1">19991109 Irfan view 3.07 buffer overflow</ref>
      <ref url="http://stud4.tuwien.ac.at/~e9227474/main2.html" source="MISC" adv="1">http://stud4.tuwien.ac.at/~e9227474/main2.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="irfanview" name="irfanview">
        <vers prev="1" num="3.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1113" published="1998-04-14" name="CVE-1999-1113" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Eudora Internet Mail Server (EIMS) 2.01 and earlier on MacOS systems allows remote attackers to cause a denial of service via a long USER command to port 106.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/75" source="BID">75</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=89258194718577&amp;w=2" source="BUGTRAQ" adv="1">19980414 MacOS based buffer overflows...</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eudora" name="internet_mail_server">
        <vers num="1.2" />
        <vers num="2.0" />
        <vers prev="1" num="2.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1114" published="1998-04-08" name="CVE-1999-1114" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Korn Shell (ksh) suid_exec program on IRIX 6.x and earlier, and possibly other operating systems, allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2100.php" source="XF" patch="1" adv="1">ksh-suid_exec(2100)</ref>
      <ref url="http://www.securityfocus.com/bid/467" source="BID" patch="1" adv="1">467</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/h-15a.shtml" source="CIAC" patch="1" adv="1">H-15A</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19980405-01-I" source="SGI" patch="1" adv="1">19980405-01-I</ref>
      <ref url="ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-96.17.suid_exec.vul" source="AUSCERT">AA-96.17</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.1" />
        <vers num="5.1.1" />
        <vers num="5.2" />
        <vers num="5.3" />
        <vers num="6.0" />
        <vers num="6.0.1" edition="" />
        <vers num="6.0.1" edition=":xfs" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1115" published="1990-12-31" name="CVE-1999-1115" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in the /etc/suid_exec program in HP Apollo Domain/OS sr10.2 and sr10.3 beta, related to the Korn Shell (ksh).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1990-04.html" source="CERT" patch="1" adv="1">CA-1990-04</ref>
      <ref url="http://www.securityfocus.com/bid/7" source="BID">7</ref>
      <ref url="http://www.iss.net/security_center/static/6721.php" source="XF">apollo-suidexec-unauthorized-access(6721)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/a-30.shtml" source="CIAC">A-30</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="apollo_domain_os">
        <vers num="sr10.2" />
        <vers prev="1" num="sr10.3" edition="beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1116" published="1997-05-03" name="CVE-1999-1116" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in runpriv in Indigo Magic System Administration subsystem of SGI IRIX 6.3 and 6.4 allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2108.php" source="XF" patch="1" adv="1">sgi-runpriv(2108)</ref>
      <ref url="http://www.securityfocus.com/bid/462" source="BID" patch="1" adv="1">462</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19970503-01-PX" source="SGI" patch="1" adv="1">19970503-01-PX</ref>
      <ref url="http://www.osvdb.org/1009" source="OSVDB">1009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.3" />
        <vers num="6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1117" published="1999-12-31" name="CVE-1999-1117" modified="2008-09-09" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">lquerypv in AIX 4.1 and 4.2 allows local users to read arbitrary files by specifying the file in the -h command line parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1752.php" source="XF" patch="1" adv="1">ibm-lquerypv(1752)</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/h-13.shtml" source="CIAC" patch="1" adv="1">H-13</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420196&amp;w=2" source="BUGTRAQ" adv="1">19961125 AIX lquerypv</ref>
      <ref url="http://www.securityfocus.com/bid/455" source="BID">455</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;w=2&amp;r=1&amp;s=lquerypv&amp;q=b" source="BUGTRAQ">19961124</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420195&amp;w=2" source="BUGTRAQ">19961125 lquerypv fix</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.1" />
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1118" published="1998-03-11" name="CVE-1999-1118" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">ndd in Solaris 2.6 allows local users to cause a denial of service by modifying certain TCP/IP parameters.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/817.php" source="XF" patch="1" adv="1">sun-ndd(817)</ref>
      <ref url="http://www.securityfocus.com/bid/433" source="BID" patch="1" adv="1">433</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/165&amp;type=0&amp;nav=sec.sba" source="SUN" patch="1" adv="1">00165</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1119" published="1992-04-27" name="CVE-1999-1119" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">FTP installation script anon.ftp in AIX insecurely configures anonymous FTP, which allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1992-09.html" source="CERT" patch="1" adv="1">CA-1992-09</ref>
      <ref url="http://xforce.iss.net/static/3154.php" source="XF" patch="1" adv="1">aix-anon-ftp(3154)</ref>
      <ref url="http://www.securityfocus.com/bid/41" source="BID">41</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="" edition=":32-bit" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1120" published="1997-01-04" name="CVE-1999-1120" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">netprint in SGI IRIX 6.4 and earlier trusts the PATH environmental variable for finding and executing the disable program, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2107.php" source="XF" patch="1" adv="1">sgi-netprint(2107)</ref>
      <ref url="http://www.securityfocus.com/bid/395" source="BID" patch="1" adv="1">395</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420403&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19970104 Irix: netprint story</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19961203-02-PX" source="SGI" patch="1" adv="1">19961203-02-PX</ref>
      <ref url="http://www.osvdb.org/993" source="OSVDB">993</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19961203-01-PX" source="SGI">19961203-01-PX</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="5.3" />
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers prev="1" num="6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1121" published="1992-03-19" name="CVE-1999-1121" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The default configuration for UUCP in AIX before 3.2 allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1992-06.html" source="CERT" patch="1" adv="1">CA-1992-06</ref>
      <ref url="http://xforce.iss.net/static/554.php" source="XF" patch="1" adv="1">ibm-uucp(554)</ref>
      <ref url="http://www.securityfocus.com/bid/38" source="BID">38</ref>
      <ref url="http://www.osvdb.org/891" source="OSVDB">891</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers prev="1" num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1122" published="1989-07-26" name="CVE-1999-1122" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Vulnerability in restore in SunOS 4.0.3 and earlier allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1989-02.html" source="CERT" patch="1" adv="1">CA-1989-02</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6695" source="XF">sun-restore-gain-privileges(6695)</ref>
      <ref url="http://www.securityfocus.com/bid/3" source="BID">3</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/ciac-08.shtml" source="CIAC">CIAC-08</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers prev="1" num="4.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1123" published="1991-05-20" name="CVE-1999-1123" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The installation of Sun Source (sunsrc) tapes allows local users to gain root privileges via setuid root programs (1) makeinstall or (2) winstall.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1991-07.html" source="CERT" patch="1" adv="1">CA-1991-07</ref>
      <ref url="http://xforce.iss.net/static/582.php" source="XF" patch="1" adv="1">sun-sourcetapes(582)</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/107&amp;type=0&amp;nav=sec.sba" source="SUN" patch="1" adv="1">00107</ref>
      <ref url="http://www.securityfocus.com/bid/22" source="BID">22</ref>
      <ref url="http://www.securityfocus.com/bid/21" source="BID">21</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="4.0.3" />
        <vers num="4.1" />
        <vers num="4.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1124" published="1999-12-31" name="CVE-1999-1124" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">HTTP Client application in ColdFusion allows remote attackers to bypass access restrictions for web pages on other ports by providing the target page to the mainframeset.cfm application, which requests the page from the server, making it look like the request is coming from the local host.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://packetstorm.securify.com/mag/phrack/phrack54/P54-08" source="MISC">http://packetstorm.securify.com/mag/phrack/phrack54/P54-08</ref>
    </refs>
    <vuln_soft>
      <prod vendor="allaire" name="coldfusion">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1125" published="1997-09-19" name="CVE-1999-1125" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Oracle Webserver 2.1 and earlier runs setuid root, but the configuration file is owned by the oracle account, which allows any local or remote attacker who obtains access to the oracle account to gain privileges or modify arbitrary files by modifying the configuration file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602880019796&amp;w=2" source="BUGTRAQ">19970919 Instresting practises of Oracle [Oracle Webserver]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="http_server">
        <vers num="1.0" />
        <vers prev="1" num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1126" published="1999-12-31" name="CVE-1999-1126" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Cisco Resource Manager (CRM) 1.1 and earlier creates certain files with insecure permissions that allow local users to obtain sensitive configuration information including usernames, passwords, and SNMP community strings, from (1) swim_swd.log, (2) swim_debug.log, (3) dbi_debug.log, and (4) temporary files whose names begin with "DPR_".</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1575.php" source="XF" patch="1" adv="1">cisco-crm-file-vuln(1575)</ref>
      <ref url="http://www.cisco.com/warp/public/770/crmtmp-pub.shtml" source="CISCO" patch="1" adv="1">19980813 CRM Temporary File Vulnerability</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/i-086.shtml" source="CIAC" patch="1" adv="1">I-086</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="resource_manager">
        <vers prev="1" num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1127" published="1999-12-31" name="CVE-1999-1127" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Windows NT 4.0 does not properly shut down invalid named pipe RPC connections, which allows remote attackers to cause a denial of service (resource exhaustion) via a series of connections containing malformed data, aka the "Named Pipes Over RPC" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms98-017.asp" source="MS" patch="1" adv="1">MS98-017</ref>
      <ref url="http://support.microsoft.com/support/kb/articles/Q195/7/33.asp" source="MSKB" patch="1" adv="1">Q195733</ref>
      <ref url="http://www.iss.net/security_center/static/523.php" source="XF">nt-spoolss(523)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1128" published="1997-03-01" name="CVE-1999-1128" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Internet Explorer 3.01 on Windows 95 allows remote malicious web sites to execute arbitrary commands via a .isp file, which is automatically downloaded and executed without prompting the user.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://oliver.efri.hr/~crv/security/bugs/NT/ie3.html" source="MISC">http://oliver.efri.hr/~crv/security/bugs/NT/ie3.html</ref>
      <ref url="http://members.tripod.com/~unibyte/iebug3.htm" source="MISC">http://members.tripod.com/~unibyte/iebug3.htm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="3.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1129" published="1999-09-01" name="CVE-1999-1129" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cisco Catalyst 2900 Virtual LAN (VLAN) switches allow remote attackers to inject 802.1q frames into another VLAN by forging the VLAN identifier in the trunking tag.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3294.php" source="XF" patch="1" adv="1">cisco-catalyst-vlan-frames(3294)</ref>
      <ref url="http://www.securityfocus.com/bid/615" source="BID" patch="1" adv="1">615</ref>
      <ref url="http://www.securityfocus.com/archive/1/26008" source="BUGTRAQ" patch="1" adv="1">19990901 VLAN Security</ref>
      <ref url="http://www.cisco.com/univercd/cc/td/doc/product/lan/28201900/1928v8x/eescg8x/aleakyv.htm" source="MISC" adv="1">http://www.cisco.com/univercd/cc/td/doc/product/lan/28201900/1928v8x/eescg8x/aleakyv.htm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="catalyst_2900_vlan">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="ios">
        <vers num="11.2(8)sa5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1130" published="1999-07-30" name="CVE-1999-1130" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Default configuration of the search engine in Netscape Enterprise Server 3.5.1, and possibly other versions, allows remote attackers to read the source of JHTML files by specifying a search command using the HTML-tocrec-demo1.pat pattern file.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93346448121208&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19990730 Netscape Enterprise Server yeilds source of JHTML</ref>
      <ref url="http://www.securityfocus.com/bid/559" source="BID">559</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93337389603117&amp;w=2" source="NTBUGTRAQ">19990730 Netscape Enterprise Server yeilds source of JHTML</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="enterprise_server">
        <vers prev="1" num="3.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1131" published="1997-10-24" name="CVE-1999-1131" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in OSF Distributed Computing Environment (DCE) security demon (secd) in IRIX 6.4 and earlier allows attackers to cause a denial of service via a long principal, group, or organization.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/vendor_bulletins/VB-97.12.opengroup" source="CERT" patch="1" adv="1">VB-97.12</ref>
      <ref url="http://xforce.iss.net/static/1123.php" source="XF" patch="1" adv="1">sgi-osf-dce-dos(1123)</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/i-060.shtml" source="CIAC" patch="1" adv="1">I-060</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19980601-01-PX" source="SGI" patch="1" adv="1">19980601-01-PX</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="5.3" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1132" published="1999-12-31" name="CVE-1999-1132" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Windows NT 4.0 allows remote attackers to cause a denial of service (crash) via extra source routing data such as (1) a Routing Information Field (RIF) field with a hop count greater than 7, or (2) a list containing duplicate Token Ring IDs.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/support/kb/articles/Q179/1/57.asp" source="MSKB" patch="1" adv="1">Q179157</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90763508011966&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19981005 NMRC Advisory - Lame NT Token Ring DoS</ref>
      <ref url="http://www.iss.net/security_center/static/1399.php" source="XF">token-ring-dos(1399)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=90760603030452&amp;w=2" source="NTBUGTRAQ">19981002 NMRC Advisory - Lame NT Token Ring DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1133" published="1997-09-01" name="CVE-1999-1133" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">HP-UX 9.x and 10.x running X windows may allow local attackers to gain privileges via (1) vuefile, (2) vuepad, (3) dtfile, or (4) dtpad, which do not authenticate users.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/499.php" source="XF" patch="1" adv="1">hp-vue-dt(499)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602880019776&amp;w=2" source="HP" patch="1" adv="1">HPSBUX9709-069</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10" />
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1134" published="1994-05-18" name="CVE-1999-1134" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in Vue 3.0 in HP 9.x allows local users to gain root privileges, as fixed by PHSS_4038, PHSS_4055, and PHSS_4066.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/e-23.shtml" source="CIAC" patch="1" adv="1">E-23</ref>
      <ref url="http://www.iss.net/security_center/static/2284.php" source="XF">hp-vue(2284)</ref>
      <ref url="http://packetstorm.securify.com/advisories/hpalert/008" source="HP">HPSBUX9404-008</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1135" published="1994-04-20" name="CVE-1999-1135" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in VUE 3.0 in HP 9.x allows local users to gain root privileges, as fixed by PHSS_4994 and PHSS_5438.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2284.php" source="XF" patch="1" adv="1">hp-vue(2284)</ref>
      <ref url="http://packetstorm.securify.com/advisories/hpalert/027" source="HP">HPSBUX9504-027</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1136" published="1998-07-30" name="CVE-1999-1136" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Vulnerability in Predictive on HP-UX 11.0 and earlier, and MPE/iX 5.5 and earlier, allows attackers to compromise data transfer for Predictive messages (using e-mail or modem) between customer and Response Center Predictive systems.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1413.php" source="XF" patch="1" adv="1">mpeix-predictive(1413)</ref>
      <ref url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9807-081.html" source="HP" patch="1" adv="1">HPSBUX9807-081</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/i-081.shtml" source="CIAC" patch="1" adv="1">I-081</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526177&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19980729 HP-UX Predictive &amp; Netscape SSL Vulnerabilities</ref>
      <ref url="http://cert.ip-plus.net/bulletin-archive/msg00040.html" source="HP" patch="1" adv="1">HPSBMP9807-005</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers prev="1" num="11.00" />
      </prod>
      <prod vendor="hp" name="mpe_ix">
        <vers num="5.0" />
        <vers prev="1" num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1137" published="1993-10-01" name="CVE-1999-1137" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The permissions for the /dev/audio device on Solaris 2.2 and earlier, and SunOS 4.1.x, allow any local user to read from the device, which could be used by an attacker to monitor conversations happening near a machine that has a microphone.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/549.php" source="XF" patch="1" adv="1">sun-audio(549)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/e-01.shtml" source="CIAC" patch="1" adv="1">E-01</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/122&amp;type=0&amp;nav=sec.sba" source="SUN" patch="1" adv="1">00122</ref>
      <ref url="http://www.osvdb.org/6436" source="OSVDB">6436</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers prev="1" num="2.2" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="4.1" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1138" published="1993-09-17" name="CVE-1999-1138" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SCO UNIX System V/386 Release 3.2, and other SCO products, installs the home directories (1) /tmp for the dos user, and (2) /usr/tmp for the asg user, which allows other users to gain access to those accounts since /tmp and /usr/tmp are world-writable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1993-13.html" source="CERT">CA-1993-13</ref>
      <ref url="http://xforce.iss.net/static/546.php" source="XF" patch="1" adv="1">sco-homedir(546)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="open_desktop">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="3.0" />
      </prod>
      <prod vendor="sco" name="open_desktop_lite">
        <vers num="3.0" />
      </prod>
      <prod vendor="sco" name="openserver">
        <vers num="3.0" />
      </prod>
      <prod vendor="sco" name="unix">
        <vers num="system_v386_3.2_operating_system" />
        <vers num="system_v386_3.2_operating_system_2.0" />
        <vers num="system_v386_3.2_operating_system_4.0" />
        <vers num="system_v386_3.2_operating_system_4.x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1139" published="1997-09-01" name="CVE-1999-1139" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Character-Terminal User Environment (CUE) in HP-UX 11.0 and earlier allows local users to overwrite arbitrary files and gain root privileges via a symlink attack on the IOERROR.mytty file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9801-074.html" source="HP" patch="1" adv="1">HPSBUX9801-074</ref>
      <ref url="http://security-archive.merton.ox.ac.uk/bugtraq-199801/0122.html" source="BUGTRAQ" patch="1" adv="1">19980121 HP-UX CUE, CUD and LAND vulnerabilities</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602880019745&amp;w=2" source="BUGTRAQ" adv="1">19970901 HP UX Bug :)</ref>
      <ref url="http://www.iss.net/security_center/static/2007.php" source="XF">hp-cue(2007)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/i-027b.shtml" source="CIAC">I-027B</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers prev="1" num="11.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1140" published="1997-12-14" name="CVE-1999-1140" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in CrackLib 2.5 may allow local users to gain root privileges via a long GECOS field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/vendor_bulletins/VB-97.16.CrackLib" source="CERT" patch="1" adv="1">VB-97.16</ref>
      <ref url="http://xforce.iss.net/static/1539.php" source="XF" patch="1" adv="1">cracklib-bo(1539)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88209041500913&amp;w=2" source="BUGTRAQ" adv="1">19971214 buffer overflows in cracklib?!</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alec_muffet" name="cracklib">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1141" published="1997-05-15" name="CVE-1999-1141" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Ascom Timeplex router allows remote attackers to obtain sensitive information or conduct unauthorized activities by entering debug mode through a sequence of CTRL-D characters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1824.php" source="XF" adv="1">ascom-timeplex-debug(1824)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420981&amp;w=2" source="BUGTRAQ">19970515 MicroSolved finds hole in Ascom Timeplex Router Security</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ascom" name="timeplex_routers">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1142" published="1992-05-27" name="CVE-1999-1142" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">SunOS 4.1.2 and earlier allows local users to gain privileges via "LD_*" environmental variables to certain dynamically linked setuid or setgid programs such as (1) login, (2) su, or (3) sendmail, that change the real and effective user ids to the same user.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1992-11.html" source="CERT" patch="1" adv="1">CA-1992-11</ref>
      <ref url="http://xforce.iss.net/static/3152.php" source="XF" patch="1" adv="1">sun-env(3152)</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/116" source="SUN">00116</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers prev="1" num="4.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1143" published="1997-05-28" name="CVE-1999-1143" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in runtime linker program rld in SGI IRIX 6.x and earlier allows local users to gain privileges via setuid and setgid programs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2109.php" source="XF" patch="1" adv="1">sgi-rld(2109)</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/h-65.shtml" source="CIAC" patch="1" adv="1">H-065</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19970504-01-PX" source="SGI">19970504-01-PX</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="5" />
        <vers prev="1" num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1144" published="1997-01-30" name="CVE-1999-1144" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Certain files in MPower in HP-UX 10.x are installed with insecure permissions, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2056.php" source="XF" patch="1" adv="1">hp-mpower(2056)</ref>
      <ref url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9701-051.html" source="HP" patch="1" adv="1">HPSBUX9701-051</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.00" />
        <vers num="10.01" />
        <vers num="10.10" />
        <vers num="10.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1145" published="1997-01-07" name="CVE-1999-1145" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in Glance programs in GlancePlus for HP-UX 10.20 and earlier allows local users to access arbitrary files and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2059.php" source="XF" patch="1" adv="1">hp-glanceplus(2059)</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/h-21.shtml" source="CIAC" patch="1" adv="1">H-21</ref>
      <ref url="http://www.securityfocus.com/templates/advisory.html?id=1514" source="HP">HPSBUX9701-044</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.01" />
        <vers num="10.10" />
        <vers prev="1" num="10.20" />
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1146" published="1994-05-04" name="CVE-1999-1146" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in Glance and gpm programs in GlancePlus for HP-UX 9.x and earlier allows local users to access arbitrary files and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2060.php" source="XF" patch="1" adv="1">hp-glanceplus-gpm(2060)</ref>
      <ref url="http://www.securityfocus.com/advisories/1555" source="HP" patch="1" adv="1">HPSBUX9405-011</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="8" />
        <vers prev="1" num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1147" published="1998-12-04" name="CVE-1999-1147" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Platinum Policy Compliance Manager (PCM) 7.0 allows remote attackers to execute arbitrary commands via a long string to the Agent port (1827), which is handled by smaxagent.exe.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1430.php" source="XF" patch="1" adv="1">pcm-dos-execute(1430)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91273739726314&amp;w=2" source="BUGTRAQ" adv="1">19981204 [SAFER-981204.DOS.1.3] Buffer Overflow in Platinum PCM 7.0</ref>
      <ref url="http://www.osvdb.org/3164" source="OSVDB">3164</ref>
    </refs>
    <vuln_soft>
      <prod vendor="platinum" name="policy_compliance_manager">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1148" published="1999-12-31" name="CVE-1999-1148" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">FTP service in IIS 4.0 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via many passive (PASV) connections at the same time.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1215.php" source="XF" patch="1" adv="1">iis-passive-ftp(1215)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms98-006.asp" source="MS" patch="1" adv="1">MS98-006</ref>
      <ref url="http://support.microsoft.com/support/kb/articles/Q189/2/62.ASP" source="MSKB" patch="1" adv="1">Q189262</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers prev="1" num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1149" published="1998-07-16" name="CVE-1999-1149" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in CSM Proxy 4.1 allows remote attackers to cause a denial of service (crash) via a long string to the FTP port.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1422.php" source="XF" patch="1" adv="1">csm-proxy-dos(1422)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525993&amp;w=2" source="BUGTRAQ" adv="1">19980716 S.A.F.E.R. Security Bulletin 980708.DOS.1.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="computer_software_manufaktur" name="csm_proxy">
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1150" published="1998-06-30" name="CVE-1999-1150" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Livingston Portmaster routers running ComOS use the same initial sequence number (ISN) for TCP connections, which allows remote attackers to conduct spoofing and hijack TCP sessions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1882.php" source="XF" adv="1">portmaster-fixed-isn(1882)</ref>
      <ref url="http://www.securityfocus.com/archive/1/9723" source="BUGTRAQ" adv="1">19980630 Livingston Portmaster - ISN generation is loosy!</ref>
    </refs>
    <vuln_soft>
      <prod vendor="livingston_portmaster" name="portmaster">
        <vers num="initial" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1151" published="1998-06-03" name="CVE-1999-1151" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Compaq/Microcom 6000 Access Integrator does not cause a session timeout after prompting for a username or password, which allows remote attackers to cause a denial of service by connecting to the integrator without providing a username or password.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2089.php" source="XF" patch="1" adv="1">microcom-dos(2089)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90296493106214&amp;w=2" source="BUGTRAQ" adv="1">19980603 Compaq/Microcom 6000 DoS + more</ref>
    </refs>
    <vuln_soft>
      <prod vendor="compaq_microcom" name="microcom_6000_access_integrator">
        <vers num="initial" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1152" published="1998-06-03" name="CVE-1999-1152" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Compaq/Microcom 6000 Access Integrator does not disconnect a client after a certain number of failed login attempts, which allows remote attackers to guess usernames or passwords via a brute force attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90296493106214&amp;w=2" source="BUGTRAQ" adv="1">19980603 Compaq/Microcom 6000 DoS + more</ref>
    </refs>
    <vuln_soft>
      <prod vendor="compaq_microcom" name="microcom_6000_access_integrator">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1153" published="1998-11-09" name="CVE-1999-1153" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">HAMcards Postcard CGI script 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient email address.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1400.php" source="XF" patch="1" adv="1">cgi-perl-mail-programs(1400)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hamcards_postcard_cgi" name="hamcards_postcard_cgi">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1154" published="1998-11-09" name="CVE-1999-1154" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">LakeWeb Filemail CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient email address.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1400.php" source="XF" patch="1" adv="1">cgi-perl-mail-programs(1400)</ref>
      <ref url="http://www.securityfocus.com/archive/1/11175" source="BUGTRAQ" patch="1" adv="1">19981109 Several new CGI vulnerabilities</ref>
      <ref url="http://lakeweb.com/scripts/" source="MISC" adv="1">http://lakeweb.com/scripts/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lakeweb" name="filemail_cgi_script">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1155" published="1998-11-09" name="CVE-1999-1155" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">LakeWeb Mail List CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient email address.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1400.php" source="XF" patch="1" adv="1">cgi-perl-mail-programs(1400)</ref>
      <ref url="http://www.securityfocus.com/archive/1/11175" source="BUGTRAQ" patch="1" adv="1">19981109 Several new CGI vulnerabilities</ref>
      <ref url="http://lakeweb.com/scripts/" source="MISC" adv="1">http://lakeweb.com/scripts/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lakeweb" name="mail_list_cgi_script">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1156" published="1999-05-17" name="CVE-1999-1156" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BisonWare FTP Server 4.1 and earlier allows remote attackers to cause a denial of service via a malformed PORT command that contains a non-numeric character and a large number of carriage returns.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2254.php" source="XF" patch="1" adv="1">bisonware-port-crash(2254)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bisonware" name="bisonware_ftp_server">
        <vers prev="1" num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1157" published="1999-12-31" name="CVE-1999-1157" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Tcpip.sys in Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service via an ICMP Subnet Mask Address Request packet, when certain multiple IP addresses are bound to the same network interface.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3894.php" source="XF" patch="1" adv="1">tcpipsys-icmp-dos(3894)</ref>
      <ref url="http://support.microsoft.com/support/kb/articles/Q192/7/74.ASP" source="MSKB" patch="1" adv="1">Q192774</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers prev="1" num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1158" published="1997-05-13" name="CVE-1999-1158" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in (1) pluggable authentication module (PAM) on Solaris 2.5.1 and 2.5 and (2) unix_scheme in Solaris 2.4 and 2.3 allows local users to gain root privileges via programs that use these modules such as passwd, yppasswd, and nispasswd.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/139&amp;type=0&amp;nav=sec.sba" source="SUN" patch="1" adv="1">00139</ref>
      <ref url="ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-97.09.Solaris.passwd.buffer.overrun.vul" source="AUSCERT">AA-97.09</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1159" published="1998-12-29" name="CVE-1999-1159" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">SSH 2.0.11 and earlier allows local users to request remote forwarding from privileged ports without being root.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1471.php" source="XF" patch="1" adv="1">ssh-privileged-port-forward(1471)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91495920911490&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19981229 ssh2 security problem (and patch) (fwd)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ssh" name="ssh2">
        <vers num="2.0.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1160" published="1997-02-02" name="CVE-1999-1160" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Vulnerability in ftpd/kftpd in HP-UX 10.x and 9.x allows local and possibly remote users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420581&amp;w=2" source="HP" patch="1" adv="1">HPSBUX9702-055</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/h-33.shtml" source="CIAC" patch="1" adv="1">H-33</ref>
      <ref url="http://www.iss.net/security_center/static/7437.php" source="XF">hp-ftpd-kftpd(7437)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10" />
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1161" published="1996-11-03" name="CVE-1999-1161" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in ppl in HP-UX 10.x and earlier allows local users to gain root privileges by forcing ppl to core dump.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9704-057.html" source="HP" patch="1" adv="1">HPSBUX9704-057</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/h-32.shtml" source="CIAC" patch="1" adv="1">H-32</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420103&amp;w=2" source="BUGTRAQ" adv="1">19961104 ppl bugs</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420102&amp;w=2" source="BUGTRAQ">19961103 Re: Untitled</ref>
      <ref url="http://www.iss.net/security_center/static/7438.php" source="XF">hp-ppl(7438)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers prev="1" num="10" />
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1162" published="1993-05-24" name="CVE-1999-1162" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Vulnerability in passwd in SCO UNIX 4.0 and earlier allows attackers to cause a denial of service by preventing users from being able to log into the system.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1993-08.html" source="CERT" patch="1" adv="1">CA-1993-08</ref>
      <ref url="http://www.iss.net/security_center/static/542.php" source="XF">sco-passwd-deny(542)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="open_desktop">
        <vers num="1.1" />
        <vers num="2.0" />
      </prod>
      <prod vendor="sco" name="unix">
        <vers prev="1" num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1163" published="1999-11-24" name="CVE-1999-1163" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Vulnerability in HP Series 800 S/X/V Class servers allows remote attackers to gain access to the S/X/V Class console via the Service Support Processor (SSP) Teststation.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94347039929958&amp;w=2" source="HP" patch="1" adv="1">HPSBUX9911-105</ref>
      <ref url="http://www.iss.net/security_center/static/7439.php" source="XF">hp-ssp(7439)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="9000">
        <vers num="800" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1164" published="1999-06-25" name="CVE-1999-1164" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Outlook client allows remote attackers to cause a denial of service by sending multiple email messages with the same X-UIDL headers, which causes Outlook to hang.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93041631215856&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19990625 Outlook denial of service</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="outlook">
        <vers num="2000" />
        <vers num="97" />
        <vers num="98" />
      </prod>
      <prod vendor="microsoft" name="outlook_express">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1165" published="1999-07-21" name="CVE-1999-1165" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">GNU fingerd 1.37 does not properly drop privileges before accessing user information, which could allow local users to (1) gain root privileges via a malicious program in the .fingerrc file, or (2) read arbitrary files via symbolic links from .plan, .forward, or .project files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/535" source="BID" patch="1" adv="1">535</ref>
      <ref url="http://www.securityfocus.com/archive/1/2478" source="BUGTRAQ" adv="1">19950317 GNU finger 1.37 executes ~/.fingerrc with gid root</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93268249021561&amp;w=2" source="BUGTRAQ">19990721 old gnu finger bugs</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="fingerd">
        <vers num="1.37" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1166" published="1999-07-11" name="CVE-1999-1166" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Linux 2.0.37 does not properly encode the Custom segment limit, which allows local users to gain root privileges by accessing and modifying kernel memory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/523" source="BID" patch="1" adv="1">523</ref>
      <ref url="http://www.securityfocus.com/archive/1/18156" source="BUGTRAQ" patch="1" adv="1">19990711 Linux 2.0.37 segment limit bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.0.37" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1167" published="1999-12-31" name="CVE-1999-1167" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in Third Voice Web annotation utility allows remote users to read sensitive data and generate fake web pages for other Third Voice users by injecting malicious Javascript into an annotation.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.wired.com/news/technology/0,1282,20677,00.html" source="CONFIRM" adv="1">http://www.wired.com/news/technology/0,1282,20677,00.html</ref>
      <ref url="http://www.wired.com/news/technology/0,1282,20636,00.html" source="MISC" adv="1">http://www.wired.com/news/technology/0,1282,20636,00.html</ref>
      <ref url="http://www.iss.net/security_center/static/7252.php" source="XF">thirdvoice-cross-site-scripting(7252)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="third_voice" name="third_voice_web">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1168" published="1999-02-20" name="CVE-1999-1168" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">install.iss installation script for Internet Security Scanner (ISS) for Linux, version 5.3, allows local users to change the permissions of arbitrary files via a symlink attack on a temporary file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/12640" source="BUGTRAQ">19990220 ISS install.iss security hole</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iss" name="internet_security_scanner">
        <vers num="5.3" edition="" />
        <vers num="5.3" edition=":linux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1169" published="1999-02-04" name="CVE-1999-1169" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">nobo 1.2 allows remote attackers to cause a denial of service (crash) via a series of large UDP packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/12284" source="BUGTRAQ">19990204 NOBO denial of service</ref>
    </refs>
    <vuln_soft>
      <prod vendor="flavio_veloso" name="nobo">
        <vers prev="1" num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1170" published="1999-01-02" name="CVE-1999-1170" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">IPswitch IMail allows local users to gain additional privileges and modify or add mail accounts by setting the "flags" registry key to 1920.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/218" source="BID">218</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91816507920544&amp;w=2" source="NTBUGTRAQ">19990204 WS FTP Server Remote DoS Attack</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="imail">
        <vers num="5.0" />
      </prod>
      <prod vendor="ipswitch" name="ws_ftp_server">
        <vers num="1.0.1.e" />
        <vers num="1.0.2.e" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1171" published="1999-02-02" name="CVE-1999-1171" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">IPswitch WS_FTP allows local users to gain additional privileges and modify or add mail accounts by setting the "flags" registry key to 1920.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/218" source="BID">218</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91816507920544&amp;w=2" source="NTBUGTRAQ">19990204 WS FTP Server Remote DoS Attack</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="imail">
        <vers num="5.0" />
      </prod>
      <prod vendor="ipswitch" name="ws_ftp_server">
        <vers num="1.0.1.e" />
        <vers num="1.0.2.e" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1172" published="1999-01-14" name="CVE-1999-1172" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">By design, Maximizer Enterprise 4 calendar and address book program allows arbitrary users to modify the calendar of other users when the calendar is being shared.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/11947" source="BUGTRAQ">19990114 security hole in Maximizer</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maximizer" name="maximizer_enterprise">
        <vers num="4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1173" published="1998-12-18" name="CVE-1999-1173" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Corel Word Perfect 8 for Linux creates a temporary working directory with world-writable permissions, which allows local users to (1) modify Word Perfect behavior by modifying files in the working directory, or (2) modify files of other users via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91404045014047&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19981218 wordperfect 8 for linux security</ref>
    </refs>
    <vuln_soft>
      <prod vendor="corel" name="wordperfect">
        <vers num="8" edition="" />
        <vers num="8" edition=":linux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1174" published="2001-12-21" name="CVE-1999-1174" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">ZIP drive for Iomega ZIP-100 disks allows attackers with physical access to the drive to bypass password protection by inserting a known disk with a known password, waiting for the ZIP drive to power down, manually replacing the known disk with the target disk, and using the known password to access the target disk.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.counterpane.com/crypto-gram-9812.html#doghouse" source="MISC">http://www.counterpane.com/crypto-gram-9812.html#doghouse</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iomega" name="zip_100_mb_drive">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1175" published="1999-12-31" name="CVE-1999-1175" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Web Cache Control Protocol (WCCP) in Cisco Cache Engine for Cisco IOS 11.2 and earlier does not use authentication, which allows remote attackers to redirect HTTP traffic to arbitrary hosts via WCCP packets to UDP port 2048.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/770/wccpauth-pub.shtml" source="CISCO" patch="1" adv="1">19980513 Cisco Web Cache Control Protocol Router Vulnerability</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/i-054.shtml" source="CIAC" patch="1" adv="1">I-054</ref>
      <ref url="http://xforce.iss.net/static/1577.php" source="XF">cisco-wccp-vuln(1577)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers prev="1" num="11.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1176" published="1998-01-10" name="CVE-1999-1176" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in cidentd ident daemon allows local users to gain root privileges via a long line in the .authlie script.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90554230925545&amp;w=2" source="BUGTRAQ">19980911 Re: security problems with jidentd</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88466930416716&amp;w=2" source="BUGTRAQ">19980110 Cidentd</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aaron_ledbetter" name="cidentd">
        <vers num="" />
      </prod>
      <prod vendor="jidentd" name="jidentd">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1177" published="1999-12-31" name="CVE-1999-1177" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in nph-publish before 1.2 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the pathname for an upload operation.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www-genome.wi.mit.edu/WWW/tools/CGI_scripts/server_publish/nph-publish" source="CONFIRM" patch="1" adv="1">http://www-genome.wi.mit.edu/WWW/tools/CGI_scripts/server_publish/nph-publish</ref>
      <ref url="http://www.w3.org/Security/Faq/wwwsf4.html" source="MISC">http://www.w3.org/Security/Faq/wwwsf4.html</ref>
      <ref url="http://xforce.iss.net/static/2055.php" source="XF">http-cgi-nphpublish(2055)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lincoln_d._stein" name="nph-publish">
        <vers prev="1" num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1178" published="1998-06-10" name="CVE-1999-1178" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sambar Server 4.1 beta allows remote attackers to obtain sensitive information about the server via an HTTP request for the dumpenv.pl script.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3223.php" source="XF" patch="1" adv="1">sambar-dump-env(3223)</ref>
      <ref url="http://www.securityfocus.com/archive/1/9505" source="BUGTRAQ" patch="1" adv="1">19980610 Sambar Server Beta BUG..</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sambar" name="sambar_server">
        <vers num="4.1" edition="beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1179" published="1998-05-15" name="CVE-1999-1179" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Vulnerability in man.sh CGI script, included in May 1998 issue of SysAdmin Magazine, allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/9330" source="BUGTRAQ" patch="1" adv="1">19980515 May SysAdmin man.sh security hole</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sysadmin_magazine" name="man.sh">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1180" published="1999-02-16" name="CVE-1999-1180" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">O'Reilly WebSite 1.1e and Website Pro 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in an argument to (1) args.cmd or (2) args.bat.</descript>
    </desc>
    <sols>
      <sol source="nvd">O'Reilly has corrected this issue in WebSite Professional 2.5, which is now available from:  http://website.oreilly.com</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="oreilly" name="website">
        <vers num="1.1e" />
      </prod>
      <prod vendor="oreilly" name="website_pro">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers prev="1" num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1181" published="1998-09-29" name="CVE-1999-1181" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in On-Line Customer Registration software for IRIX 6.2 through 6.4 allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/j-003.shtml" source="CIAC" patch="1" adv="1">J-003</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19980901-01-PX" source="SGI" patch="1" adv="1">19980901-01-PX</ref>
      <ref url="http://www.iss.net/security_center/static/7441.php" source="XF">irix-register(7441)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.2" />
        <vers prev="1" num="6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1182" published="1997-07-17" name="CVE-1999-1182" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in run-time linkers (1) ld.so or (2) ld-linux.so for Linux systems allows local users to gain privileges by calling a setuid program with a long program name (argv[0]) and forcing ld.so/ld-linux.so to report an error.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602661419351&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19970722 ld.so vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602661419318&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19970717 KSR[T] Advisory #2: ld.so</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88661732807795&amp;w=2" source="BUGTRAQ" adv="1">19980204 An old ld-linux.so hole</ref>
    </refs>
    <vuln_soft>
      <prod vendor="delix" name="dld">
        <vers num="5.2" />
      </prod>
      <prod vendor="caldera" name="openlinux_lite">
        <vers num="1.1" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="4.0" />
      </prod>
      <prod vendor="lst" name="lst_power_linux">
        <vers num="2.2" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.2" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1183" published="1998-04-02" name="CVE-1999-1183" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">System Manager sysmgr GUI in SGI IRIX 6.4 and 6.3 allows remote attackers to execute commands by providing a trojan horse (1) runtask or (2) runexec descriptor file, which is used to execute a System Manager Task when the user's Mailcap entry supports the x-sgi-task or x-sgi-exec type.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19980403-02-PX" source="SGI" patch="1" adv="1">19980403-02-PX</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19980403-01-PX" source="SGI" patch="1" adv="1">19980403-01-PX</ref>
      <ref url="http://www.iss.net/security_center/static/809.php" source="XF">sgi-mailcap(809)</ref>
      <ref url="http://www.osvdb.org/8556" source="OSVDB">8556</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.3" />
        <vers num="6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1184" published="1997-05-13" name="CVE-1999-1184" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in Elm 2.4 and earlier allows local users to gain privileges via a long TERM environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420970&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19970514 Re: ELM overflow</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420967&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19970513</ref>
    </refs>
    <vuln_soft>
      <prod vendor="elm_development_group" name="elm">
        <vers num="2.3" />
        <vers prev="1" num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1185" published="1998-10-06" name="CVE-1999-1185" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in SCO mscreen allows local users to gain root privileges via a long terminal entry (TERM) in the .mscreenrc file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90686250717719&amp;w=2" source="BUGTRAQ">19980926 Root exploit for SCO OpenServer.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="cmw">
        <vers num="3.0" />
      </prod>
      <prod vendor="sco" name="internet_faststart">
        <vers num="all_versions" />
      </prod>
      <prod vendor="sco" name="open_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="sco" name="openserver">
        <vers num="3.0" />
        <vers num="5.0" />
      </prod>
      <prod vendor="sco" name="openserver_enterprise_system">
        <vers num="5.0.4p" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1186" published="1996-01-02" name="CVE-1999-1186" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">rxvt, when compiled with the PRINT_PIPE option in various Linux operating systems including Linux Slackware 3.0 and RedHat 2.1, allows local users to gain root privileges by specifying a malicious program using the -print-pipe command line parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167418966&amp;w=2" source="BUGTRAQ" adv="1">19960102 rxvt security hole</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rxvt" name="rxvt">
        <vers num="" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="2.1" />
      </prod>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1187" published="1996-08-26" name="CVE-1999-1187" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Pine before version 3.94 allows local users to gain privileges via a symlink attack on a lockfile that is created when a user receives new mail.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/416.php" source="XF" patch="1" adv="1">pine-tmpfile(416)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167419803&amp;w=2" source="BUGTRAQ" adv="1">19960826 [BUG] Vulnerability in PINE</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_washington" name="pine">
        <vers prev="1" num="3.94" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="2.1.0" />
      </prod>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1188" published="1998-12-27" name="CVE-1999-1188" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">mysqld in MySQL 3.21 creates log files with world-readable permissions, which allows local users to obtain passwords for users who are added to the user database.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1568.php" source="XF" patch="1" adv="1">mysql-readable-log-files(1568)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91479159617803&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19981227 mysql: mysqld creates world readable logs..</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="3.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1189" published="1999-11-24" name="CVE-1999-1189" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Netscape Navigator/Communicator 4.7 for Windows 95 and Windows 98 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long argument after the ? character in a URL that references an .asp, .cgi, .html, or .pl file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/822" source="BID" patch="1" adv="1">822</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/7884" source="XF" adv="1">netscape-long-argument-bo(7884)</ref>
      <ref url="http://www.securityfocus.com/archive/1/36608" source="BUGTRAQ" adv="1">19991127 Netscape Communicator 4.7 - Navigator Overflows</ref>
      <ref url="http://www.securityfocus.com/archive/1/36306" source="BUGTRAQ" adv="1">19991124 Netscape Communicator 4.7 - Navigator Overflows</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="communicator">
        <vers num="4.7" />
      </prod>
      <prod vendor="netscape" name="navigator">
        <vers num="4.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1190" published="1999-11-15" name="CVE-1999-1190" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in POP3 server of Admiral Systems EmailClub 1.05 allows remote attackers to execute arbitrary commands via a long "From" header in an e-mail message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/801" source="BID" patch="1" adv="1">801</ref>
      <ref url="http://www.securiteam.com/exploits/E-MailClub__FROM__remote_buffer_overflow.html" source="MISC" adv="1">http://www.securiteam.com/exploits/E-MailClub__FROM__remote_buffer_overflow.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="admiral_systems" name="emailclub">
        <vers num="1.0.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1191" published="1997-05-19" name="CVE-1999-1191" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in chkey in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-97.18.solaris.chkey.buffer.overflow.vul" source="AUSCERT" patch="1" adv="1">AA-97.18</ref>
      <ref url="http://www.securityfocus.com/bid/207" source="BID" patch="1" adv="1">207</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/144" source="SUN" patch="1" adv="1">00144</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167418335&amp;w=2" source="BUGTRAQ" adv="1">19970519 Re: Finally, most of an exploit for Solaris 2.5.1's ps.</ref>
      <ref url="http://www.iss.net/security_center/static/7442.php" source="XF">solaris-chkey-bo(7442)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers prev="1" num="2.5.1" edition="" />
        <vers prev="1" num="2.5.1" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1192" published="1997-06-24" name="CVE-1999-1192" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in eeprom in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/206" source="BID" patch="1" adv="1">206</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/143" source="SUN" patch="1" adv="1">00143</ref>
      <ref url="http://www.iss.net/security_center/static/7444.php" source="XF">solaris-eeprom-bo(7444)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers prev="1" num="2.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1193" published="1991-05-14" name="CVE-1999-1193" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The "me" user in NeXT NeXTstep 2.1 and earlier has wheel group privileges, which could allow the me user to use the su command to become root.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1991-06.html" source="CERT" patch="1" adv="1">CA-1991-06</ref>
      <ref url="http://xforce.iss.net/static/581.php" source="XF" patch="1" adv="1">next-me(581)</ref>
      <ref url="http://www.securityfocus.com/bid/20" source="BID">20</ref>
    </refs>
    <vuln_soft>
      <prod vendor="next" name="next">
        <vers prev="1" num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1194" published="1991-05-01" name="CVE-1999-1194" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">chroot in Digital Ultrix 4.1 and 4.0 is insecurely installed, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1991-05.html" source="CERT" patch="1" adv="1">CA-1991-05</ref>
      <ref url="http://xforce.iss.net/static/577.php" source="XF" patch="1" adv="1">dec-chroot(577)</ref>
      <ref url="http://www.securityfocus.com/bid/17" source="BID">17</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digital" name="ultrix">
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1195" published="1999-05-05" name="CVE-1999-1195" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">NAI VirusScan NT 4.0.2 does not properly modify the scan.dat virus definition file during an update via FTP, but it reports that the update was successful, which could cause a system administrator to believe that the definitions have been updated correctly.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92588169005196&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19990505 NAI AntiVirus Update Problem</ref>
      <ref url="http://www.securityfocus.com/bid/169" source="BID">169</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92587579032534&amp;w=2" source="NTBUGTRAQ">19990505 NAI AntiVirus Update Problem</ref>
    </refs>
    <vuln_soft>
      <prod vendor="network_associates" name="virusscan">
        <vers num="4.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1196" published="1999-04-07" name="CVE-1999-1196" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Hummingbird Exceed X version 5 allows remote attackers to cause a denial of service via malformed data to port 6000.</descript>
    </desc>
    <sols>
      <sol source="nvd">Upgrade to a non-vulnerable version of Exceed (Hummingbird Exceed 6.0.1 Hummingbird Exceed 6.0.2 Hummingbird Exceed 6.1)</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/158" source="BID">158</ref>
      <ref url="http://www.securityfocus.com/archive/1/13451" source="BUGTRAQ">19990427 NT/Exceed D.O.S.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hummingbird" name="exceed">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1197" published="1990-12-20" name="CVE-1999-1197" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">TIOCCONS in SunOS 4.1.1 does not properly check the permissions of a user who tries to redirect console output and input, which could allow a local user to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1990-12.html" source="CERT" patch="1" adv="1">CA-1990-12</ref>
      <ref url="http://www.securityfocus.com/bid/14" source="BID">14</ref>
      <ref url="http://www.iss.net/security_center/static/7140.php" source="XF">sunos-tioccons-console-redirection(7140)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="4.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1198" published="1990-10-03" name="CVE-1999-1198" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">BuildDisk program on NeXT systems before 2.0 does not prompt users for the root password, which allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1990-06.html" source="CERT" patch="1" adv="1">CA-1990-06</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/b-01.shtml" source="CIAC" patch="1" adv="1">B-01</ref>
      <ref url="http://www.securityfocus.com/bid/11" source="BID">11</ref>
      <ref url="http://www.iss.net/security_center/static/7141.php" source="XF">nextstep-builddisk-root-access(7141)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="next" name="next">
        <vers prev="1" num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1199" published="1998-08-07" name="CVE-1999-1199" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Apache WWW server 1.3.1 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via a large number of MIME headers with the same name, aka the "sioux" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90252779826784&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19980807 YA Apache DoS attack</ref>
      <ref url="http://www.redhat.com/support/errata/rh51-errata-general.html#apache" source="CONFIRM">http://www.redhat.com/support/errata/rh51-errata-general.html#apache</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90286768232093&amp;w=2" source="BUGTRAQ" adv="1">19980810 Apache DoS Attack</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90280517007869&amp;w=2" source="BUGTRAQ" adv="1">19980811 Apache 'sioux' DOS fix for TurboLinux</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90276683825862&amp;w=2" source="BUGTRAQ" adv="1">19980808 Debian Apache Security Update</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers prev="1" num="1.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1200" published="1998-07-20" name="CVE-1999-1200" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Vintra SMTP MailServer allows remote attackers to cause a denial of service via a malformed "EXPN *@" command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1617.php" source="XF" patch="1" adv="1">vintra-mail-dos(1617)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=90222454131610&amp;w=2" source="NTBUGTRAQ" patch="1" adv="1">19980720 DOS in Vintra systems Mailserver software.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vintra_systems" name="smtp_mailserver">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1201" published="1999-02-06" name="CVE-1999-1201" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Windows 95 and Windows 98 systems, when configured with multiple TCP/IP stacks bound to the same MAC address, allow remote attackers to cause a denial of service (traffic amplification) via a certain ICMP echo (ping) packet, which causes all stacks to send a ping response, aka TCP Chorusing.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/7542" source="XF">win-multiple-ip-dos(7542)</ref>
      <ref url="http://www.securityfocus.com/bid/225" source="BID">225</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91849617221319&amp;w=2" source="NTBUGTRAQ">19990206 New Windows 9x Bug:  TCP Chorusing</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_95">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1202" published="1998-07-03" name="CVE-1999-1202" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">StarTech (1) POP3 proxy server and (2) telnet server allows remote attackers to cause a denial of service via a long USER command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2088.php" source="XF" adv="1">startech-pop3-overflow(2088)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525873&amp;w=2" source="BUGTRAQ" adv="1">19980703 Windows95 Proxy DoS Vulnerabilites</ref>
    </refs>
    <vuln_soft>
      <prod vendor="startech" name="pop3_proxy_server">
        <vers num="" />
      </prod>
      <prod vendor="startech" name="telnet_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1203" published="1999-02-12" name="CVE-1999-1203" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multilink PPP for ISDN dialup users in Ascend before 4.6 allows remote attackers to cause a denial of service via a spoofed endpoint identifier.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.iss.net/security_center/static/7498.php" source="XF">ascend-ppp-isdn-dos(7498)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91888117502765&amp;w=2" source="BUGTRAQ">19990212 PPP/ISDN multilink security issue - summary</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91868964203769&amp;w=2" source="BUGTRAQ">19990210 Security problems in ISDN equipment authentication</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ascend" name="multilink_ppp_for_isdn">
        <vers prev="1" num="4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1204" published="1998-05-11" name="CVE-1999-1204" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Check Point Firewall-1 does not properly handle certain restricted keywords (e.g., Mail, auth, time) in user-defined objects, which could produce a rule with a default "ANY" address and result in access to more systems than intended by the administrator.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101925912&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19980511 Firewall-1 Reserved Keywords Vulnerability</ref>
      <ref url="http://www.checkpoint.com/techsupport/config/keywords.html" source="CONFIRM">http://www.checkpoint.com/techsupport/config/keywords.html</ref>
      <ref url="http://xforce.iss.net/static/7293.php" source="XF">fw1-user-defined-keywords-access(7293)</ref>
      <ref url="http://www.osvdb.org/4416" source="OSVDB">4416</ref>
    </refs>
    <vuln_soft>
      <prod vendor="checkpoint" name="firewall-1">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1205" published="1996-06-07" name="CVE-1999-1205" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">nettune in HP-UX 10.01 and 10.00 is installed setuid root, which allows local users to cause a denial of service by modifying critical networking configuration information.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://packetstormsecurity.org/advisories/ibm-ers/96-08" source="HP" patch="1" adv="1">HPSBUX9607-035</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167419195&amp;w=2" source="BUGTRAQ" adv="1">19960607 HP-UX B.10.01 vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/414" source="XF">hp-nettune(414)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.00" />
        <vers num="10.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1206" published="1999-12-31" name="CVE-1999-1206" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SystemSoft SystemWizard package in HP Pavilion PC with Windows 98, and possibly other platforms and operating systems, installs two ActiveX controls that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via a malicious web page that references (1) the Launch control, or (2) the RegObj control.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.systemsoft.com/l-2/l-3/support-systemwizard.htm" source="CONFIRM" patch="1" adv="1">http://www.systemsoft.com/l-2/l-3/support-systemwizard.htm</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93336970231857&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19990729 New ActiveX security problems in Windows 98 PCs</ref>
      <ref url="http://www.securityfocus.com/bid/555" source="BID">555</ref>
    </refs>
    <vuln_soft>
      <prod vendor="systemsoft" name="systemwizard">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1207" published="1998-02-18" name="CVE-1999-1207" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in web-admin tool in NetXRay 2.6 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/907.php" source="XF" patch="1" adv="1">netxray-bo(907)</ref>
      <ref url="http://www.efri.hr/~crv/security/bugs/NT/netxtray.html" source="MISC">http://www.efri.hr/~crv/security/bugs/NT/netxtray.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="network_general" name="netxray">
        <vers num="all_versions" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1208" published="1997-07-21" name="CVE-1999-1208" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in ping in AIX 4.2 and earlier allows local users to gain root privileges via a long command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/803.php" source="XF" patch="1" adv="1">ping-bo(803)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602661419337&amp;w=2" source="BUGTRAQ" patch="1">19970721 AIX ping, lchangelv, xlock fixes</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602661419330&amp;w=2" source="BUGTRAQ">19970721 AIX ping (Exploit)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="3.2.5" />
        <vers num="4.1" />
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1209" published="1997-11-20" name="CVE-1999-1209" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in scoterm in SCO OpenServer 5.0 and SCO Open Desktop/Open Server 3.0 allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/vendor_bulletins/VB-97.14.scoterm" source="CERT" patch="1" adv="1">VB-97.14</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/690" source="XF">sco-scoterm(690)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88131151000069&amp;w=2" source="BUGTRAQ">19971204 scoterm exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="open_desktop">
        <vers num="3.0" />
      </prod>
      <prod vendor="sco" name="openserver">
        <vers num="3.0" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1210" published="1997-11-12" name="CVE-1999-1210" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">xterm in Digital UNIX 4.0B *with* patch kit 5 allows local users to overwrite arbitrary files via a symlink attack on a core dump file, which is created when xterm is called with a DISPLAY environmental variable set to a display that xterm cannot access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/613.php" source="XF" patch="1" adv="1">dec-xterm(613)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87936891504885&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19971112 Digital Unix Security Problem</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digital" name="unix">
        <vers num="4.0b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1211" published="1991-03-27" name="CVE-1999-1211" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in in.telnetd in SunOS 4.1.1 and earlier allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1991-02.html" source="CERT" patch="1" adv="1">CA-1991-02</ref>
      <ref url="http://xforce.iss.net/static/574.php" source="XF" patch="1" adv="1">sun-intelnetd(574)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers prev="1" num="4.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1212" published="1991-03-27" name="CVE-1999-1212" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in in.rlogind in SunOS 4.0.3 and 4.0.3c allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1991-02.html" source="CERT" patch="1" adv="1">CA-1991-02</ref>
      <ref url="http://xforce.iss.net/static/574.php" source="XF" patch="1" adv="1">sun-intelnetd(574)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="4.0.3" />
        <vers num="4.0.3c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1213" published="1997-10-01" name="CVE-1999-1213" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Vulnerability in telnet service in HP-UX 10.30 allows attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/571.php" source="XF" patch="1" adv="1">hp-telnetdos(571)</ref>
      <ref url="http://www2.dataguard.no/bugtraq/1997_4/0001.html" source="HP" patch="1" adv="1">HPSBUX9710-070</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.30" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1214" published="1997-09-15" name="CVE-1999-1214" modified="2011-03-10" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The asynchronous I/O facility in 4.4 BSD kernel does not check user credentials when setting the recipient of I/O notification, which allows local users to cause a denial of service by using certain ioctl and fcntl calls to cause the signal to be sent to an arbitrary process ID.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/556.php" source="XF" patch="1" adv="1">openbsd-iosig(556)</ref>
      <ref url="http://www.openbsd.com/advisories/signals.txt" source="MISC" patch="1" adv="1">http://www.openbsd.com/advisories/signals.txt</ref>
      <ref url="http://www.osvdb.org/11062" source="OSVDB">11062</ref>
      <ref url="http://www.openbsd.com/advisories/signals.txt" source="OPENBSD">19970915 Vulnerability in I/O Signal Handling</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bsd" name="bsd">
        <vers num="4.4" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="6.2" edition="stable" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="2.0.4" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.1" />
      </prod>
      <prod vendor="sgi" name="irix">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1215" published="1993-09-16" name="CVE-1999-1215" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">LOGIN.EXE program in Novell Netware 4.0 and 4.01 temporarily writes user name and password information to disk, which could allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1993-12.html" source="CERT" patch="1" adv="1">CA-1993-12</ref>
      <ref url="http://xforce.iss.net/static/545.php" source="XF" patch="1" adv="1">novell-login(545)</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/d-21.shtml" source="CIAC">D-21</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="netware">
        <vers num="4.0" />
        <vers num="4.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1216" published="1993-04-22" name="CVE-1999-1216" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cisco routers 9.17 and earlier allow remote attackers to bypass security restrictions via certain IP source routed packets that should normally be denied using the "no ip source-route" command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1993-07.html" source="CERT" patch="1" adv="1">CA-1993-07</ref>
      <ref url="http://xforce.iss.net/static/541.php" source="XF" patch="1" adv="1">cisco-sourceroute(541)</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/d-15.shtml" source="CIAC" patch="1" adv="1">D-15</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="router">
        <vers num="8.2" />
        <vers num="8.3" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers prev="1" num="9.17" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1217" published="1997-07-25" name="CVE-1999-1217" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The PATH in Windows NT includes the current working directory (.), which could allow local users to gain privileges by placing Trojan horse programs with the same name as commonly used system programs into certain directories.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/526.php" source="XF" adv="1">nt-path(526)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=87602726319435&amp;w=2" source="NTBUGTRAQ" adv="1">19970725 Re: NT security - why bother?</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=87602726319426&amp;w=2" source="NTBUGTRAQ" adv="1">19970723 NT security - why bother?</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1218" published="1993-02-18" name="CVE-1999-1218" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Vulnerability in finger in Commodore Amiga UNIX 2.1p2a and earlier allows local users to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1993-04.html" source="CERT" patch="1" adv="1">CA-1993-04</ref>
      <ref url="http://xforce.iss.net/static/522.php" source="XF" patch="1" adv="1">amiga-finger(522)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="commodore" name="amiga_unix">
        <vers prev="1" num="2.1p2a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1219" published="1994-08-11" name="CVE-1999-1219" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in sgihelp in the SGI help system and print manager in IRIX 5.2 and earlier allows local users to gain root privileges, possibly through the clogin command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1994-13.html" source="CERT" patch="1" adv="1">CA-1994-13</ref>
      <ref url="http://xforce.iss.net/static/511.php" source="XF" patch="1" adv="1">sgi-prn-mgr(511)</ref>
      <ref url="http://www.securityfocus.com/bid/468" source="BID" patch="1" adv="1">468</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/e-33.shtml" source="CIAC" patch="1" adv="1">E-33</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="5.1" />
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1220" published="1997-08-24" name="CVE-1999-1220" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Majordomo 1.94.3 and earlier allows remote attackers to execute arbitrary commands when the advertise or noadvertise directive is used in a configuration file, via shell metacharacters in the Reply-To header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/502.php" source="XF" patch="1" adv="1">majordomo-advertise(502)</ref>
      <ref url="http://www.securityfocus.com/archive/1/7527" source="BUGTRAQ" adv="1">19970824 Vulnerability in Majordomo</ref>
    </refs>
    <vuln_soft>
      <prod vendor="great_circle_associates" name="majordomo">
        <vers prev="1" num="1.94.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1221" published="1996-11-17" name="CVE-1999-1221" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">dxchpwd in Digital Unix (OSF/1) 3.x allows local users to modify arbitrary files via a symlink attack on the dxchpwd.log file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/399.php" source="XF" patch="1" adv="1">dgux-chpwd(399)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420141&amp;w=2" source="BUGTRAQ">19961117 Digital Unix v3.x (v4.x?) security vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digital" name="unix">
        <vers num="3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1222" published="1999-12-31" name="CVE-1999-1222" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Netbt.sys in Windows NT 4.0 allows remote malicious DNS servers to cause a denial of service (crash) by returning 0.0.0.0 as the IP address for a DNS host name lookup.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3893.php" source="XF" patch="1" adv="1">dns-netbtsys-dos(3893)</ref>
      <ref url="http://support.microsoft.com/support/kb/articles/Q188/5/71.ASP" source="MSKB" patch="1" adv="1">Q188571</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":terminal_server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1223" published="1999-12-31" name="CVE-1999-1223" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IIS 3.0 allows remote attackers to cause a denial of service via a request to an ASP page in which the URL contains a large number of / (forward slash) characters.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3892.php" source="XF" patch="1" adv="1">url-asp-av(3892)</ref>
      <ref url="http://support.microsoft.com/support/kb/articles/q187/5/03.asp" source="MSKB" patch="1" adv="1">Q187503</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1224" published="1997-10-08" name="CVE-1999-1224" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">IMAP 4.1 BETA, and possibly other versions, does not properly handle the SIGABRT (abort) signal, which allows local users to crash the server (imapd) via certain sequences of commands, which causes a core dump that may contain sensitive password information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/349.php" source="XF" patch="1" adv="1">imapd-core(349)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87635124302928&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19971008 L0pht Advisory: IMAP4rev1 imapd server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_washington" name="imapd">
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1225" published="1997-08-24" name="CVE-1999-1225" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">rpc.mountd on Linux, Ultrix, and possibly other operating systems, allows remote attackers to determine the existence of a file on the server by attempting to mount that file, which generates different error messages depending on whether the file exists or not.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/347.php" source="XF" patch="1" adv="1">mountd-file-exists(347)</ref>
      <ref url="http://www.securityfocus.com/archive/1/7526" source="BUGTRAQ">19970824 Serious security flaw in rpc.mountd on several operating systems.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digital" name="ultrix">
        <vers num="" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.20.1" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="2.0.4" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1226" published="1999-10-28" name="CVE-1999-1226" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Netscape Communicator 4.7 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long certificate key.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3436.php" source="XF">netscape-huge-key-dos(3436)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="communicator">
        <vers prev="1" num="4.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1227" published="1999-07-30" name="CVE-1999-1227" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Ethereal allows local users to overwrite arbitrary files via a symlink attack on the packet capture file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3334.php" source="XF" adv="1">ethereal-dev-capturec-root(3334)</ref>
      <ref url="http://www.ethereal.com/lists/ethereal-dev/199907/msg00130.html" source="MISC" adv="1">http://www.ethereal.com/lists/ethereal-dev/199907/msg00130.html</ref>
      <ref url="http://www.ethereal.com/lists/ethereal-dev/199907/msg00126.html" source="MISC" adv="1">http://www.ethereal.com/lists/ethereal-dev/199907/msg00126.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1228" published="1998-09-27" name="CVE-1999-1228" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Various modems that do not implement a guard time, or are configured with a guard time of 0, can allow remote attackers to execute arbitrary modem commands such as ATH, ATH0, etc., via a "+++" sequence that appears in ICMP packets, the subject of an e-mail message, IRC commands, and others.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3320.php" source="XF" patch="1" adv="1">global-village-modem-dos(3320)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90695973308453&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19980927 1+2=3, +++ATH0=Old school DoS</ref>
      <ref url="http://www.macintouch.com/modemsecurity.html" source="MISC" adv="1">http://www.macintouch.com/modemsecurity.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="logicode" name="quicktel">
        <vers num="28.8" />
      </prod>
      <prod vendor="diamond" name="supra">
        <vers num="33.6" />
        <vers num="v.90" />
      </prod>
      <prod vendor="us_robotics" name="us_robotics">
        <vers num="33.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1229" published="1998-02-25" name="CVE-1999-1229" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Quake 2 server 3.13 on Linux does not properly check file permissions for the config.cfg configuration file, which allows local users to read arbitrary files via a symlink from config.cfg to the target file.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/733.php" source="XF" patch="1" adv="1">linux-quake2(733)</ref>
      <ref url="http://www.securityfocus.com/archive/1/8590" source="BUGTRAQ" adv="1">19980225 Quake 2 Linux 3.13 (and lower) allow users to read arbitrary files</ref>
    </refs>
    <vuln_soft>
      <prod vendor="id_software" name="quake_2_server">
        <vers prev="1" num="3.13" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1230" published="1997-12-24" name="CVE-1999-1230" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Quake 2 server allows remote attackers to cause a denial of service via a spoofed UDP packet with a source address of 127.0.0.1, which causes the server to attempt to connect to itself.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/698.php" source="XF" patch="1" adv="1">quake2-dos(698)</ref>
      <ref url="http://www.securityfocus.com/archive/1/8282" source="BUGTRAQ" patch="1" adv="1">19971224 Quake II Remote Denial of Service</ref>
    </refs>
    <vuln_soft>
      <prod vendor="id_software" name="quake_2">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1231" published="1999-06-09" name="CVE-1999-1231" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ssh 2.0.12, and possibly other versions, allows valid user names to attempt to enter the correct password multiple times, but only prompts an invalid user name for a password once, which allows remote attackers to determine user account names on the server.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/14758" source="BUGTRAQ" patch="1" adv="1">19990609 ssh advirsory</ref>
      <ref url="http://xforce.iss.net/static/2276.php" source="XF" adv="1">ssh-leak(2276)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ssh" name="ssh2">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.12" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1232" published="1997-05-16" name="CVE-1999-1232" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in day5datacopier in SGI IRIX 6.2 allows local users to execute arbitrary commands via a modified PATH environment variable that points to a malicious cp program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3316.php" source="XF" patch="1" adv="1">sgi-day5datacopier(3316)</ref>
      <ref url="http://www.osvdb.org/8559" source="OSVDB">8559</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420994&amp;w=2" source="BUGTRAQ" adv="1">19970516 Irix and WWW</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1233" published="1999-12-31" name="CVE-1999-1233" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">IIS 4.0 does not properly restrict access for the initial session request from a user's IP address if the address does not resolve to a DNS domain, aka the "Domain Resolution" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3306.php" source="XF" patch="1" adv="1">iis-unresolved-domain-access(3306)</ref>
      <ref url="http://www.securityfocus.com/bid/657" source="BID" patch="1" adv="1">657</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-039.asp" source="MS" patch="1" adv="1">MS99-039</ref>
      <ref url="http://support.microsoft.com/support/kb/articles/Q241/5/62.asp" source="MSKB" patch="1" adv="1">241562</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1234" published="1999-10-26" name="CVE-1999-1234" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">LSA (LSASS.EXE) in Windows NT 4.0 allows remote attackers to cause a denial of service via a NULL policy handle in a call to (1) SamrOpenDomain, (2) SamrEnumDomainUsers, and (3) SamrQueryDomainInfo.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3293.php" source="XF" adv="1">msrpc-samr-open-dos(3293)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94096671308565&amp;w=2" source="BUGTRAQ" adv="1">19991026 Re: LSA vulnerability on NT40 SP5</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1235" published="1999-08-25" name="CVE-1999-1235" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information from another user's index.dat, or (2) people who are physically observing ("shoulder surfing") another user to read the information from the status bar when the user moves the mouse over a link.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3289.php" source="XF" adv="1">nt-ie5-user-ftp-password(3289)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1236" published="1999-10-01" name="CVE-1999-1236" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Internet Anywhere Mail Server 2.3.1 stores passwords in plaintext in the msgboxes.dbf file, which could allow local users to gain privileges by extracting the passwords from msgboxes.dbf.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3285.php" source="XF">iams-passwords-plaintext(3285)</ref>
      <ref url="http://www.securityfocus.com/bid/731" source="BID" adv="1">731</ref>
      <ref url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind9910&amp;L=ntbugtraq&amp;F=&amp;S=&amp;P=662" source="NTBUGTRAQ" adv="1">19991001 Vulnerabilities in the Internet Anywhere Mail Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="true_north" name="internet_anywhere_mail_server">
        <vers num="2.3.1" />
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1237" published="1999-06-06" name="CVE-1999-1237" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in smbvalid/smbval SMB authentication library, as used in Apache::AuthenSmb and possibly other modules, allows remote attackers to execute arbitrary commands via (1) a long username, (2) a long password, and (3) other unspecified methods.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2272.php" source="XF" adv="1">smbvalid-bo(2272)</ref>
      <ref url="http://www.securityfocus.com/archive/1/14384" source="BUGTRAQ" adv="1">19990606 Buffer overflows in smbval library</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1238" published="1994-09-21" name="CVE-1999-1238" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Vulnerability in CORE-DIAG fileset in HP message catalog in HP-UX 9.05 and earlier allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2262.php" source="XF" patch="1" adv="1">hp-core-diag-fileset(2262)</ref>
      <ref url="http://www.securityfocus.com/advisories/1531" source="HP" patch="1" adv="1">HPSBUX9409-017</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="8" />
        <vers num="9" />
        <vers prev="1" num="9.05" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1239" published="1994-07-13" name="CVE-1999-1239" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">HP-UX 9.x does not properly enable the Xauthority mechanism in certain conditions, which could allow local users to access the X display even when they have not explicitly been authorized to do so.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2261.php" source="XF" patch="1" adv="1">hp-xauthority(2261)</ref>
      <ref url="http://www.securityfocus.com/advisories/1559" source="HP" patch="1" adv="1">HPSBUX9407-015</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1240" published="1996-11-26" name="CVE-1999-1240" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in cddbd CD database server allows remote attackers to execute arbitrary commands via a long log message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2203.php" source="XF" patch="1" adv="1">cddbd-bo(2203)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gracenote" name="cddbd">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1241" published="1999-05-06" name="CVE-1999-1241" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Internet Explorer, with a security setting below Medium, allows remote attackers to execute arbitrary commands via a malicious web page that uses the FileSystemObject ActiveX object.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2173.php" source="XF" patch="1" adv="1">ie-filesystemobject(2173)</ref>
      <ref url="http://oliver.efri.hr/~crv/security/bugs/NT/activex4.html" source="MISC">http://oliver.efri.hr/~crv/security/bugs/NT/activex4.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0.2900" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1242" published="1994-02-07" name="CVE-1999-1242" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Vulnerability in subnetconfig in HP-UX 9.01 and 9.0 allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2162.php" source="XF" patch="1" adv="1">hp-subnet-config(2162)</ref>
      <ref url="http://packetstormsecurity.org/advisories/hpalert/003" source="HP" patch="1" adv="1">HPSBUX9402-003</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="9.00" />
        <vers num="9.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1243" published="1995-03-03" name="CVE-1999-1243" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">SGI Desktop Permissions Tool in IRIX 6.0.1 and earlier allows local users to modify permissions for arbitrary files and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2113.php" source="XF" patch="1" adv="1">sgi-permissions(2113)</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/f-16.shtml" source="CIAC" patch="1" adv="1">F-16</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19950301-01-P373" source="SGI" patch="1" adv="1">19950301-01-P373</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="5.2" />
        <vers num="6.0" />
        <vers prev="1" num="6.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1244" published="1999-04-15" name="CVE-1999-1244" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">IPFilter 3.2.3 through 3.2.10 allows local users to modify arbitrary files via a symlink attack on the saved output file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2087.php" source="XF" adv="1">ipfilter-temp-file(2087)</ref>
      <ref url="http://www.securityfocus.com/archive/1/13303" source="BUGTRAQ" adv="1">19990415 FSA-99.04-IPFILTER-v3.2.10</ref>
    </refs>
    <vuln_soft>
      <prod vendor="darren_reed" name="ipfilter">
        <vers num="3.2.10" />
        <vers num="3.2.3" />
        <vers num="3.2.4" />
        <vers num="3.2.5" />
        <vers num="3.2.6" />
        <vers num="3.2.7" />
        <vers num="3.2.8" />
        <vers num="3.2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1245" published="1999-04-06" name="CVE-1999-1245" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">vacm ucd-snmp SNMP server, version 3.52, does not properly disable access to the public community string, which could allow remote attackers to obtain sensitive information.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability was fixed in version 3.6 of ucd-snmpd.</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2086.php" source="XF">ucd-snmpd-community(2086)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ucd-snmp" name="ucd-snmp">
        <vers num="3.52" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1246" published="1999-12-31" name="CVE-1999-1246" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Direct Mailer feature in Microsoft Site Server 3.0 saves user domain names and passwords in plaintext in the TMLBQueue network share, which has insecure default permissions, allowing remote attackers to read the passwords and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2068.php" source="XF" patch="1" adv="1">siteserver-directmail-passwords(2068)</ref>
      <ref url="http://support.microsoft.com/support/kb/articles/Q229/9/72.asp" source="MSKB" patch="1" adv="1">Q229972</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="site_server">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1247" published="1999-02-24" name="CVE-1999-1247" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in HP Camera component of HP DCE/9000 in HP-UX 9.x allows attackers to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2061.php" source="XF" patch="1" adv="1">hp-dce9000(2061)</ref>
      <ref url="http://packetstormsecurity.org/advisories/hpalert/006" source="HP" patch="1">HPSBUX9402-006</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1248" published="1994-11-30" name="CVE-1999-1248" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Vulnerability in Support Watch (aka SupportWatch) in HP-UX 8.0 through 9.0 allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2058.php" source="XF" patch="1" adv="1">hp-supportwatch(2058)</ref>
      <ref url="http://packetstormsecurity.org/advisories/hpalert/019" source="HP" patch="1" adv="1">HPSBUX9411-019</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="8.00" />
        <vers num="8.02" />
        <vers num="8.06" />
        <vers prev="1" num="9.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1249" published="1997-01-06" name="CVE-1999-1249" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">movemail in HP-UX 10.20 has insecure permissions, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2057.php" source="XF" patch="1" adv="1">hp-movemail(2057)</ref>
      <ref url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9701-047.html" source="HP" patch="1" adv="1">HPSBUX9701-047</ref>
      <ref url="http://www.osvdb.org/8099" source="OSVDB">8099</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1250" published="1997-08-19" name="CVE-1999-1250" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Vulnerability in CGI program in the Lasso application by Blue World, as used on WebSTAR and other servers, allows remote attackers to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2044.php" source="XF" patch="1" adv="1">http-cgi-lasso(2044)</ref>
      <ref url="http://www.securityfocus.com/archive/1/7506" source="BUGTRAQ" patch="1" adv="1">19970819 Lasso CGI security hole (fwd)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="blue_world_communications" name="lasso_cgi">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1251" published="1996-12-24" name="CVE-1999-1251" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Vulnerability in direct audio user space code on HP-UX 10.20 and 10.10 allows local users to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2010.php" source="XF" patch="1" adv="1">hp-audio-panic(2010)</ref>
      <ref url="http://packetstormsecurity.org/advisories/hpalert/043" source="HP" patch="1" adv="1">HPSBUX9612-043</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.10" />
        <vers num="10.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1252" published="1996-09-04" name="CVE-1999-1252" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in a certain system call in SCO UnixWare 2.0.x and 2.1.0 allows local users to access arbitrary files and gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/vendor_bulletins/VB-96.15.sco" source="CERT" patch="1" adv="1">VB-96.15</ref>
      <ref url="http://xforce.iss.net/static/1966.php" source="XF" patch="1" adv="1">sco-system-call(1966)</ref>
      <ref url="ftp://ftp.sco.COM/SSE/security_bulletins/SB.96:02a" source="SCO">96:002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="unixware">
        <vers num="2.0.x" />
        <vers num="2.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1253" published="1996-06-07" name="CVE-1999-1253" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in a kernel error handling routine in SCO OpenServer 5.0.2 and earlier, and SCO Internet FastStart 1.0, allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/vendor_bulletins/VB-96.10.sco" source="CERT" patch="1" adv="1">VB-96.10</ref>
      <ref url="http://xforce.iss.net/static/1965.php" source="XF" patch="1" adv="1">sco-kernel(1965)</ref>
      <ref url="ftp://ftp.sco.com/SSE/security_bulletins/SB.96:01a" source="SCO">96:001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="internet_faststart">
        <vers num="1.0" />
      </prod>
      <prod vendor="sco" name="openserver">
        <vers num="5.0" />
        <vers prev="1" num="5.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1254" published="1999-03-08" name="CVE-1999-1254" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Windows 95, 98, and NT 4.0 allow remote attackers to cause a denial of service by spoofing ICMP redirect messages from a router, which causes Windows to change its routing tables.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <access />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1947.php" source="XF">win-redirects-freeze(1947)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92099515709467&amp;w=2" source="NTBUGTRAQ">19990308 Winfreeze EXPLOIT  Win9x/NT</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_95">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1255" published="1999-02-19" name="CVE-1999-1255" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Hyperseek allows remote attackers to modify the hyperseek configuration by directly calling the admin.cgi program with an edit_file action parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1914.php" source="XF">hyperseek-modify(1914)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ccs_network" name="hyperseek_search_engine">
        <vers prev="1" num="2000" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1256" published="1999-03-04" name="CVE-1999-1256" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Oracle Database Assistant 1.0 in Oracle 8.0.3 Enterprise Edition stores the database master password in plaintext in the spoolmain.log file when a new database is created, which allows local users to obtain the password from that file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1902.php" source="XF" adv="1">oracle-passwords(1902)</ref>
      <ref url="http://www.securityfocus.com/archive/1/12744" source="BUGTRAQ">19990304 Oracle Plaintext Password</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92056752115116&amp;w=2" source="NTBUGTRAQ">19990304 Oracle Plaintext Password</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_assistant">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1257" published="1997-11-26" name="CVE-1999-1257" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Xyplex terminal server 6.0.1S1, and possibly other versions, allows remote attackers to bypass the password prompt by entering (1) a CTRL-Z character, or (2) a ? (question mark).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1826.php" source="XF" patch="1" adv="1">xyplex-question-login(1826)</ref>
      <ref url="http://xforce.iss.net/static/1825.php" source="XF" patch="1" adv="1">xyplex-controlz-login(1825)</ref>
      <ref url="http://www.securityfocus.com/archive/1/8134" source="BUGTRAQ" adv="1">19971126 Xyplex terminal server bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xyplex" name="maxserver_xyplex_terminal_server">
        <vers num="6.0.1_s1" />
        <vers prev="1" num="6.0.2_s4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1258" published="1991-01-15" name="CVE-1999-1258" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">rpc.pwdauthd in SunOS 4.1.1 and earlier does not properly prevent remote access to the daemon, which allows remote attackers to obtain sensitive system information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1782.php" source="XF" patch="1" adv="1">sun-pwdauthd(1782)</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/102" source="SUN" patch="1" adv="1">00102</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="4.1" />
        <vers prev="1" num="4.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1259" published="1999-12-31" name="CVE-1999-1259" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Microsoft Office 98, Macintosh Edition, does not properly initialize the disk space used by Office 98 files and effectively inserts data from previously deleted files into the Office file, which could allow attackers to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1780.php" source="XF" patch="1" adv="1">office-extraneous-data(1780)</ref>
      <ref url="http://support.microsoft.com/support/kb/articles/q189/5/29.asp" source="MSKB" patch="1" adv="1">Q189529</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="98" edition="" />
        <vers num="98" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1260" published="1999-02-15" name="CVE-1999-1260" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">mSQL (Mini SQL) 2.0.6 allows remote attackers to obtain sensitive server information such as logged users, database names, and server version via the ServerStats query.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1777.php" source="XF">msql-serverstats(1777)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91910115718150&amp;w=2" source="BUGTRAQ">19990215 KSR[T] Advisory #10: mSQL ServerStats</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hughes" name="msql">
        <vers prev="1" num="2.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1261" published="1997-10-24" name="CVE-1999-1261" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Rainbow Six Multiplayer allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long nickname (nick) command.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1772.php" source="XF">rainbowsix-nick-bo(1772)</ref>
      <ref url="http://www.securityfocus.com/archive/1/12433" source="BUGTRAQ">19990211 Rainbow Six Buffer Overflow.....</ref>
    </refs>
    <vuln_soft>
      <prod vendor="metamail_corporation" name="metamail">
        <vers prev="1" num="7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1262" published="1997-08-01" name="CVE-1999-1262" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Java in Netscape 4.5 does not properly restrict applets from connecting to other hosts besides the one from which the applet was loaded, which violates the Java security model and could allow remote attackers to conduct unauthorized activities.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1727.php" source="XF">java-socket-open(1727)</ref>
      <ref url="http://www.securityfocus.com/archive/1/12231" source="BUGTRAQ">19990202 Unsecured server in applets under Netscape</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="communicator">
        <vers num="4.01" />
        <vers num="4.06" />
        <vers num="4.07" />
        <vers num="4.08" />
        <vers num="4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1263" published="2003-08-15" name="CVE-1999-1263" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Metamail before 2.7-7.2 allows remote attackers to overwrite arbitrary files via an e-mail message containing a uuencoded attachment that specifies the full pathname for the file to be modified, which is processed by uuencode in Metamail scripts such as sun-audio-file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1677.php" source="XF">metamail-file-creation(1677)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87773365324657&amp;w=2" source="BUGTRAQ">19971024 Vulnerability in metamail</ref>
    </refs>
    <vuln_soft>
      <prod vendor="metamail_corporation" name="metamail">
        <vers prev="1" num="2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1264" published="1999-01-21" name="CVE-1999-1264" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">WebRamp M3 router does not disable remote telnet or HTTP access to itself, even when access has been expliticly disabled.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91815321510224&amp;w=2" source="BUGTRAQ" patch="1">19990203 WebRamp M3 Perceived Bug</ref>
      <ref url="http://xforce.iss.net/static/1670.php" source="XF">webramp-remote-access(1670)</ref>
      <ref url="http://www.securityfocus.com/archive/1/12048" source="BUGTRAQ">19990121 WebRamp M3 remote network access bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ramp_networks" name="webramp">
        <vers num="300" />
        <vers num="m3" />
        <vers num="m3i" />
        <vers num="m3t" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1265" published="1998-09-22" name="CVE-1999-1265" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SMTP server in SLmail 3.1 and earlier allows remote attackers to cause a denial of service via malformed commands whose arguments begin with a "(" (parenthesis) character, such as (1) SEND, (2) VRFY, (3) EXPN, (4) MAIL FROM, (5) RCPT TO.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1664.php" source="XF" patch="1" adv="1">slmail-parens-overload(1664)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=90650438826447&amp;w=2" source="NTBUGTRAQ" adv="1">19980922 WARNING! SMTP Denial of Service in SLmail ver 3.1</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90649892424117&amp;w=2" source="BUGTRAQ" adv="1">19980922 WARNING! SMTP Denial of Service in SLmail ver 3.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="seatle_lab_software" name="slmail">
        <vers prev="1" num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1266" published="1997-06-13" name="CVE-1999-1266" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">rsh daemon (rshd) generates different error messages when a valid username is provided versus an invalid name, which allows remote attackers to determine valid users on the system.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1660.php" source="XF" patch="1" adv="1">rsh-username-leaks(1660)</ref>
      <ref url="http://www.securityfocus.com/archive/1/6978" source="BUGTRAQ" adv="1">19970613 rshd gives away usernames</ref>
    </refs>
    <vuln_soft>
      <prod vendor="metamail_corporation" name="metamail">
        <vers prev="1" num="7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1267" published="1997-05-05" name="CVE-1999-1267" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">KDE file manager (kfm) uses a TCP server for certain file operations, which allows remote attackers to modify arbitrary files by sending a copy command to the server.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1646.php" source="XF" patch="1" adv="1">kde-flawed-ipc(1646)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420906&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19970505 Hole in the KDE desktop</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="kde">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1268" published="1999-01-06" name="CVE-1999-1268" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in KDE konsole allows local users to hijack or observe sessions of other users by accessing certain devices.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://lists.kde.org/?l=kde-devel&amp;m=91560433413263&amp;w=2" source="MISC" patch="1">http://lists.kde.org/?l=kde-devel&amp;m=91560433413263&amp;w=2</ref>
      <ref url="http://xforce.iss.net/static/1645.php" source="XF" adv="1">kde-konsole-hijack(1645)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="kde">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1269" published="1998-02-06" name="CVE-1999-1269" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Screen savers in KDE beta 3 allows local users to overwrite arbitrary files via a symlink attack on the .kss.pid file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1641.php" source="XF" patch="1" adv="1">kde-kss-file-clobber(1641)</ref>
      <ref url="http://www.securityfocus.com/archive/1/8506" source="BUGTRAQ" patch="1" adv="1">19980206 serious security hole in KDE Beta 3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="kde_beta_3">
        <vers num="initial" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1270" published="1998-07-11" name="CVE-1999-1270" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">KMail in KDE 1.0 provides a PGP passphrase as a command line argument to other programs, which could allow local users to obtain the passphrase and compromise the PGP keys of other users by viewing the arguments via programs that list process information, such as ps.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1639.php" source="XF" patch="1" adv="1">kde-kmail-passphrase-leak(1639)</ref>
      <ref url="http://lists.kde.org/?l=kde-devel&amp;m=90221974029738&amp;w=2" source="MISC" adv="1">http://lists.kde.org/?l=kde-devel&amp;m=90221974029738&amp;w=2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="kde">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1271" published="1998-06-11" name="CVE-1999-1271" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Macromedia Dreamweaver uses weak encryption to store FTP passwords, which could allow local users to easily decrypt the passwords of other users.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1636.php" source="XF" patch="1" adv="1">dreamweaver-weak-passwords(1636)</ref>
      <ref url="http://www.securityfocus.com/archive/1/9511" source="BUGTRAQ" adv="1">19980611 Unsecure passwords in Macromedia Dreamweaver</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macromedia" name="dreamweaver">
        <vers num="initial" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1272" published="1998-03-01" name="CVE-1999-1272" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflows in CDROM Confidence Test program (cdrom) allow local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1635.php" source="XF" patch="1" adv="1">irix-cdrom-confidence(1635)</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19980301-01-PX" source="SGI" patch="1" adv="1">19980301-01-PX</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="5" />
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1273" published="1998-02-20" name="CVE-1999-1273" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Squid Internet Object Cache 1.1.20 allows users to bypass access control lists (ACLs) by encoding the URL with hexadecimal escape sequences.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1627.php" source="XF" patch="1" adv="1">squid-regexp-acl(1627)</ref>
      <ref url="http://www.securityfocus.com/archive/1/8551" source="BUGTRAQ" patch="1" adv="1">19980220 Simple way to bypass squid ACLs</ref>
    </refs>
    <vuln_soft>
      <prod vendor="national_science_foundation" name="squid_web_proxy">
        <vers num="1.1.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1274" published="1997-12-29" name="CVE-1999-1274" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">iPass RoamServer 3.1 creates temporary files with world-writable permissions.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1625.php" source="XF" patch="1" adv="1">ipass-temporary-files(1625)</ref>
      <ref url="http://www.securityfocus.com/archive/1/8307" source="BUGTRAQ" adv="1">19971229 iPass RoamServer 3.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipass" name="roamserver">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1275" published="1997-09-08" name="CVE-1999-1275" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Lotus cc:Mail release 8 stores the postoffice password in plaintext in a hidden file which has insecure permissions, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1619.php" source="XF" patch="1" adv="1">lotus-ccmail-passwords(1619)</ref>
      <ref url="http://www.securityfocus.com/archive/1/9478" source="BUGTRAQ" adv="1">19970908 Password unsecurity in cc:Mail release 8</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_cc_mail">
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1276" published="1998-12-07" name="CVE-1999-1276" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">fte-console in the fte package before 0.46b-4.1 does not drop root privileges, which allows local users to gain root access via the virtual console device.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1609.php" source="XF" patch="1" adv="1">fte-console-privileges(1609)</ref>
      <ref url="http://www.debian.org/security/1998/19981207" source="DEBIAN" patch="1" adv="1">19981207 fte-console: does not drop its root priviliges</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.1" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.20.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1277" published="1998-12-24" name="CVE-1999-1277" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">BackWeb client stores the username and password in cleartext for proxy authentication in the Communication registry key, which could allow other local users to gain privileges by reading the password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1565.php" source="XF" adv="1">backweb-cleartext-passwords(1565)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91487886514546&amp;w=2" source="NTBUGTRAQ" adv="1">19981224 BackWeb - Password issue (used by NAI for Corporate customer notification).</ref>
    </refs>
    <vuln_soft>
      <prod vendor="backweb_technologies" name="backweb_client">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1278" published="1998-12-25" name="CVE-1999-1278" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">nlog CGI scripts do not properly filter shell metacharacters from the IP address argument, which could allow remote attackers to execute certain commands via (1) nlog-smb.pl or (2) rpc-nlog.pl.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1550.php" source="XF" patch="1" adv="1">http-cgi-nlog-netbios(1550)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91471400632145&amp;w=2" source="BUGTRAQ">19981226 Nlog 1.1b released - security holes fixed</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91470326629357&amp;w=2" source="BUGTRAQ">19981225 Re: Nlog v1.0 Released - Nmap 2.x log management / analyzing tool</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nlog" name="nlog">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1279" published="1999-12-31" name="CVE-1999-1279" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">An interaction between the AS/400 shared folders feature and Microsoft SNA Server 3.0 and earlier allows users to view each other's folders when the users share the same Local APPC LU.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/support/kb/articles/q138/0/01.asp" source="MSKB" patch="1" adv="1">Q138001</ref>
      <ref url="http://xforce.iss.net/static/1548.php" source="XF" adv="1">snaserver-shared-folders(1548)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="sna_server">
        <vers num="2.11" />
        <vers prev="1" num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1280" published="1998-12-03" name="CVE-1999-1280" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Hummingbird Exceed 6.0.1.0 inadvertently includes a DLL that was meant for development and testing, which logs user names and passwords in cleartext in the test.log file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1547.php" source="XF" patch="1" adv="1">exceed-cleartext-passwords(1547)</ref>
      <ref url="http://www.securityfocus.com/archive/1/11512" source="BUGTRAQ" patch="1" adv="1">19981203 Remote Tools w/Exceed v.6.0.1.0 fer 95</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hummingbird" name="exceed">
        <vers num="6.0.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1281" published="1998-12-26" name="CVE-1999-1281" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Development version of Breeze Network Server allows remote attackers to cause the system to reboot by accessing the configbreeze CGI program.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1544.php" source="XF" patch="1" adv="1">breeze-remote-reboot(1544)</ref>
      <ref url="http://www.securityfocus.com/archive/1/11720" source="BUGTRAQ" adv="1">19981226 Breeze Network Server remote reboot and other bogosity.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="winddance_networks_corporation" name="breeze_network_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1282" published="1998-12-10" name="CVE-1999-1282" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">RealSystem G2 server stores the administrator password in cleartext in a world-readable configuration file, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1542.php" source="XF" patch="1" adv="1">realsystem-readable-conf-file(1542)</ref>
      <ref url="http://www.securityfocus.com/archive/1/11543" source="BUGTRAQ" patch="1" adv="1">19981210 RealSystem passwords</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realsystem_g2_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1283" published="1998-08-14" name="CVE-1999-1283" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Opera 3.2.1 allows remote attackers to cause a denial of service (application crash) via a URL that contains an extra / in the http:// tag.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1541.php" source="XF" patch="1" adv="1">opera-slash-crash(1541)</ref>
      <ref url="http://www.securityfocus.com/archive/1/10320" source="BUGTRAQ" adv="1">19980814 URL exploit to crash Opera Browser</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="3.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1284" published="1998-11-05" name="CVE-1999-1284" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">NukeNabber allows remote attackers to cause a denial of service by connecting to the NukeNabber port (1080) without sending any data, which causes the CPU usage to rise to 100% from the report.exe program that is executed upon the connection.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1540.php" source="XF" patch="1" adv="1">nukenabber-timeout-dos(1540)</ref>
      <ref url="http://www.securityfocus.com/archive/1/11131" source="BUGTRAQ" adv="1">19981105 various *lame* DoS attacks</ref>
      <ref url="http://www.dynamsol.com/puppet/text/new.txt" source="MISC">http://www.dynamsol.com/puppet/text/new.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91063407332594&amp;w=2" source="BUGTRAQ">19981107 Re: various *lame* DoS attacks</ref>
    </refs>
    <vuln_soft>
      <prod vendor="puppets_place" name="nukenabber">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1285" published="1998-12-27" name="CVE-1999-1285" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Linux 2.1.132 and earlier allows local users to cause a denial of service (resource exhaustion) by reading a large buffer from a random device (e.g. /dev/urandom), which cannot be interrupted until the read has completed.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91495921611500&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19981227 [patch] fix for urandom read(2) not interruptible</ref>
      <ref url="http://xforce.iss.net/static/1472.php" source="XF" adv="1">linux-random-read-dos(1472)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers prev="1" num="2.1.132" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1286" published="1997-05-09" name="CVE-1999-1286" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">addnetpr in SGI IRIX 6.2 and earlier allows local users to modify arbitrary files and possibly gain root access via a symlink attack on a temporary file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1433.php" source="XF" patch="1" adv="1">irix-addnetpr(1433)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420927&amp;w=2" source="BUGTRAQ" adv="1">19970509 Re: Irix: misc</ref>
      <ref url="http://www.securityfocus.com/bid/330" source="BID">330</ref>
      <ref url="http://www.osvdb.org/8560" source="OSVDB">8560</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19961203-02-PX" source="MISC">ftp://patches.sgi.com/support/free/security/advisories/19961203-02-PX</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="5.3" />
        <vers prev="1" num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1287" published="1999-12-31" name="CVE-1999-1287" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Vulnerability in Analog 3.0 and earlier allows remote attackers to read arbitrary files via the forms interface.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1410.php" source="XF" patch="1" adv="1">analog-remote-file(1410)</ref>
      <ref url="http://www.statslab.cam.ac.uk/~sret1/analog/security.html" source="CONFIRM" adv="1">http://www.statslab.cam.ac.uk/~sret1/analog/security.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stephen_turner" name="analog">
        <vers prev="1" num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1288" published="1998-11-19" name="CVE-1999-1288" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Samba 1.9.18 inadvertently includes a prototype application, wsmbconf, which is installed with incorrect permissions including the setgid bit, which allows local users to read and write files and possibly gain privileges via bugs in the program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1406.php" source="XF" patch="1" adv="1">samba-wsmbconf(1406)</ref>
      <ref url="http://www.caldera.com/support/security/advisories/SA-1998.35.txt" source="CALDERA" patch="1" adv="1">SA-1998.35</ref>
      <ref url="http://www.securityfocus.com/archive/1/11397" source="BUGTRAQ">19981119 Vulnerability in Samba on RedHat, Caldera and PHT TurboLinux</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="1.9.18" />
      </prod>
      <prod vendor="caldera" name="openlinux">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1289" published="1998-11-11" name="CVE-1999-1289" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">ICQ 98 beta on Windows NT leaks the internal IP address of a client in the TCP data segment of an ICQ packet instead of the public address (e.g. through NAT), which provides remote attackers with potentially sensitive information about the client or the internal network configuration.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1398.php" source="XF" adv="1">icq-ip-info(1398)</ref>
      <ref url="http://www.securityfocus.com/archive/1/11233" source="BUGTRAQ" adv="1">19981111 WARNING: Another ICQ IP address vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mirabilis" name="icq">
        <vers num="98_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1290" published="1999-12-31" name="CVE-1999-1290" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in nftp FTP client version 1.40 allows remote malicious FTP servers to cause a denial of service, and possibly execute arbitrary commands, via a long response string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1397.php" source="XF" patch="1" adv="1">nftp-bo(1397)</ref>
      <ref url="http://www.ayukov.com/nftp/history.html" source="CONFIRM" patch="1" adv="1">http://www.ayukov.com/nftp/history.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91127951426494&amp;w=2" source="BUGTRAQ" adv="1">19981117 nftp vulnerability (fwd)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="chris_matthee" name="nftp">
        <vers num="1.40" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1291" published="1998-10-05" name="CVE-1999-1291" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">TCP/IP implementation in Microsoft Windows 95, Windows NT 4.0, and possibly others, allows remote attackers to reset connections by forcing a reset (RST) via a PSH ACK or other means, obtaining the target's last sequence number from the resulting packet, then spoofing a reset to the target.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1383.php" source="XF" adv="1">nt-brkill(1383)</ref>
      <ref url="http://www.securityfocus.com/archive/1/10789" source="BUGTRAQ" adv="1">19981005 New Windows Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_95">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1292" published="1998-09-01" name="CVE-1999-1292" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in web administration feature of Kolban Webcam32 4.8.3 and earlier allows remote attackers to execute arbitrary commands via a long URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1366.php" source="XF" patch="1" adv="1">webcam32-buffer-overflow(1366)</ref>
      <ref url="http://xforce.iss.net/alerts/advise7.php" source="ISS" adv="1">19980901 Remote Buffer Overflow in the Kolban Webcam32 Program</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kolban" name="webcam32">
        <vers prev="1" num="4.8.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1293" published="1999-12-31" name="CVE-1999-1293" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">mod_proxy in Apache 1.2.5 and earlier allows remote attackers to cause a denial of service via malformed FTP commands, which causes Apache to dump core.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.apache.org/info/security_bulletin_1.2.5.html" source="CONFIRM" patch="1" adv="1">http://www.apache.org/info/security_bulletin_1.2.5.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88413292830649&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19980106 Apache security advisory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers prev="1" num="1.2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1294" published="1999-12-31" name="CVE-1999-1294" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Office Shortcut Bar (OSB) in Windows 3.51 enables backup and restore permissions, which are inherited by programs such as File Manager that are started from the Shortcut Bar, which could allow local users to read folders for which they do not have permission.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/support/kb/articles/q146/6/04.asp" source="MSKB" patch="1" adv="1">Q146604</ref>
      <ref url="http://xforce.iss.net/static/562.php" source="XF">nt-filemgr(562)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="3.51" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1295" published="1996-09-17" name="CVE-1999-1295" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Transarc DCE Distributed File System (DFS) 1.1 for Solaris 2.4 and 2.5 does not properly initialize the grouplist for users who belong to a large number of groups, which could allow those users to gain access to resources that are protected by DFS.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/vendor_bulletins/VB-96.16.transarc" source="CERT" patch="1" adv="1">VB-96.16</ref>
      <ref url="http://xforce.iss.net/static/7154.php" source="XF">dfs-login-groups(7154)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="transarc" name="dce_distributed_file_system">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1296" published="1997-04-29" name="CVE-1999-1296" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Kerberos IV compatibility libraries as used in Kerberos V allows local users to gain root privileges via a long line in a kerberos configuration file, which can be specified via the KRB_CONF environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420878&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19970429 vulnerabilities in kerberos</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="5-1.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1297" published="1998-07-15" name="CVE-1999-1297" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">cmdtool in OpenWindows 3.0 and XView 3.0 in SunOS 4.1.4 and earlier allows attackers with physical access to the system to display unechoed characters (such as those from password prompts) via the L2/AGAIN key.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/7482.php" source="XF" patch="1" adv="1">sun-cmdtool-echo(7482)</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fpatches%2F100452&amp;zone_32=10045%2A%20" source="SUNBUG" patch="1">1077164</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.1" />
        <vers num="1.1.1a" />
        <vers num="1.1.2" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1298" published="1997-04-07" name="CVE-1999-1298" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Sysinstall in FreeBSD 2.2.1 and earlier, when configuring anonymous FTP, creates the ftp user without a password and with /bin/date as the shell, which could allow attackers to gain access to certain system resources.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-97:03.sysinstall.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-97:03</ref>
      <ref url="http://www.osvdb.org/6087" source="OSVDB">6087</ref>
      <ref url="http://www.iss.net/security_center/static/7537.php" source="XF">freebsd-sysinstall-ftp-password(7537)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="2.1.0" />
        <vers num="2.1.5" />
        <vers num="2.1.6" />
        <vers num="2.1.7" />
        <vers num="2.2" />
        <vers prev="1" num="2.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1299" published="1997-02-03" name="CVE-1999-1299" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">rcp on various Linux systems including Red Hat 4.0 allows a "nobody" user or other user with UID of 65535 to overwrite arbitrary files, since 65535 is interpreted as -1 by chown and other system calls, which causes the calls to fail to modify the ownership of the file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420509&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19970203 Linux rcp bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="4.0" />
      </prod>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1300" published="1999-12-31" name="CVE-1999-1300" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Vulnerability in accton in Cray UNICOS 6.1 and 6.0 allows local users to read arbitrary files and modify system accounting configuration.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/b-31.shtml" source="CIAC" patch="1" adv="1">B-31</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cray" name="unicos">
        <vers num="6.0" />
        <vers num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1301" published="1996-07-16" name="CVE-1999-1301" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">A design flaw in the Z-Modem protocol allows the remote sender of a file to execute arbitrary programs on the client, as implemented in rz in the rzsz module of FreeBSD before 2.1.5, and possibly other programs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/g-31.shtml" source="CIAC" patch="1" adv="1">G-31</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-96:17.rzsz.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-96:17</ref>
      <ref url="http://www.iss.net/security_center/static/7540.php" source="XF">rzsz-command-execution(7540)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers prev="1" num="2.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1302" published="1994-11-30" name="CVE-1999-1302" modified="2011-03-10" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unspecified vulnerability in pt_chmod in SCO UNIX 4.2 and earlier allows local users to gain root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/f-05.shtml" source="SCO" patch="1" adv="1">94:001</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/7586" source="XF">sco-pt_chmod(7586)</ref>
      <ref url="http://www.osvdb.org/8797" source="OSVDB">8797</ref>
      <ref url="http://ftp.cerias.purdue.edu/pub/advisories/cert/cert_bulletins/VB-94:01.sco" source="CERT">VB-94:01</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/f-05.shtml" source="CIAC">F-05</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="open_desktop">
        <vers num="2.0" />
        <vers num="3.0" />
      </prod>
      <prod vendor="sco" name="open_desktop_lite">
        <vers num="3.0" />
      </prod>
      <prod vendor="sco" name="openserver_enterprise_system">
        <vers num="3.0" />
      </prod>
      <prod vendor="sco" name="openserver_network_system">
        <vers num="3.0" />
      </prod>
      <prod vendor="sco" name="unix">
        <vers num="3.2" />
        <vers num="4.0" />
        <vers num="4.1" />
        <vers prev="1" num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1303" published="1994-11-30" name="CVE-1999-1303" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in prwarn in SCO UNIX 4.2 and earlier allows local users to gain root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/f-05.shtml" source="CIAC" patch="1" adv="1">F-05</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/f-05.shtml" source="CIAC">F-05</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="open_desktop">
        <vers num="2.0" />
        <vers num="3.0" />
      </prod>
      <prod vendor="sco" name="open_desktop_lite">
        <vers num="3.0" />
      </prod>
      <prod vendor="sco" name="openserver_enterprise_system">
        <vers num="3.0" />
      </prod>
      <prod vendor="sco" name="openserver_network_system">
        <vers num="3.0" />
      </prod>
      <prod vendor="sco" name="unix">
        <vers num="3.2" />
        <vers num="4.0" />
        <vers num="4.1" />
        <vers prev="1" num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1304" published="1994-11-30" name="CVE-1999-1304" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in login in SCO UNIX 4.2 and earlier allows local users to gain root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/f-05.shtml" source="CIAC" patch="1" adv="1">F-05</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/f-05.shtml" source="CIAC">F-05</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="open_desktop">
        <vers num="2.0" />
        <vers num="3.0" />
      </prod>
      <prod vendor="sco" name="open_desktop_lite">
        <vers num="3.0" />
      </prod>
      <prod vendor="sco" name="openserver_enterprise_system">
        <vers num="3.0" />
      </prod>
      <prod vendor="sco" name="openserver_network_system">
        <vers num="3.0" />
      </prod>
      <prod vendor="sco" name="unix">
        <vers num="3.2" />
        <vers num="4.0" />
        <vers num="4.1" />
        <vers prev="1" num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1305" published="1994-11-30" name="CVE-1999-1305" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in "at" program in SCO UNIX 4.2 and earlier allows local users to gain root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/f-05.shtml" source="SCO" patch="1" adv="1">94:001</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/f-05.shtml" source="CIAC">F-05</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="open_desktop">
        <vers num="2.0" />
        <vers num="3.0" />
      </prod>
      <prod vendor="sco" name="open_desktop_lite">
        <vers num="3.0" />
      </prod>
      <prod vendor="sco" name="openserver_enterprise_system">
        <vers num="3.0" />
      </prod>
      <prod vendor="sco" name="openserver_network_system">
        <vers num="3.0" />
      </prod>
      <prod vendor="sco" name="unix">
        <vers num="3.2" />
        <vers num="4.0" />
        <vers num="4.1" />
        <vers prev="1" num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1306" published="1992-12-10" name="CVE-1999-1306" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cisco IOS 9.1 and earlier does not properly handle extended IP access lists when the IP route cache is enabled and the "established" keyword is set, which could allow attackers to bypass filters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1992-20.html" source="CERT" patch="1" adv="1">CA-1992-20</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers prev="1" num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1307" published="1999-12-31" name="CVE-1999-1307" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in urestore in Novell UnixWare 1.1 allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/f-06.shtml" source="CIAC" patch="1" adv="1">F-06</ref>
      <ref url="http://www.dataguard.no/bugtraq/1994_4/0676.html" source="BUGTRAQ" adv="1">19941209 Novell security advisory on sadc, urestore and the suid_exec feature</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="unixware">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1308" published="1997-07-31" name="CVE-1999-1308" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Certain programs in HP-UX 10.20 do not properly handle large user IDs (UID) or group IDs (GID) over 60000, which could allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/h-91.shtml" source="CIAC" patch="1" adv="1">H-91</ref>
      <ref url="http://www.iss.net/security_center/static/7594.php" source="XF">hp-large-uid-gid(7594)</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/h-91.shtml" source="CIAC">H-91</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/h-09.shtml" source="CIAC">H-09</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1309" published="1996-08-30" name="CVE-1999-1309" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Sendmail before 8.6.7 allows local users to gain root access via a large value in the debug (-d) command line option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-94.12.sendmail.vulnerabilities" source="CERT" patch="1" adv="1">CA-1994-12</ref>
      <ref url="http://www.dataguard.no/bugtraq/1994_1/0048.html" source="BUGTRAQ" adv="1">19940315 Security problem in sendmail versions 8.x.x</ref>
      <ref url="http://www.dataguard.no/bugtraq/1994_1/0042.html" source="BUGTRAQ" adv="1">19940315 anyone know details?</ref>
      <ref url="http://www.dataguard.no/bugtraq/1994_1/0040.html" source="BUGTRAQ" adv="1">19940314 sendmail -d problem (OLD yet still here)</ref>
      <ref url="http://xforce.iss.net/static/7155.php" source="XF">sendmail-debug-gain-root(7155)</ref>
      <ref url="http://www.dataguard.no/bugtraq/1994_1/0078.html" source="BUGTRAQ">19940327 sendmail exploit script - resend</ref>
      <ref url="http://www.dataguard.no/bugtraq/1994_1/0043.html" source="BUGTRAQ">19940315 so...</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sendmail" name="sendmail">
        <vers prev="1" num="8.6.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="1999-1310" reject="1" published="1994-11-04" name="CVE-1999-1310" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-1022.  Reason: This candidate is a duplicate of CVE-1999-1022.  Notes: All CVE users should reference CVE-1999-1022 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1311" published="1997-01-07" name="CVE-1999-1311" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Vulnerability in dtlogin and dtsession in HP-UX 10.20 and 10.10 allows local users to bypass authentication and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/h-21.shtml" source="HP" patch="1" adv="1">HPSBUX9701-046</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/h-21.shtml" source="CIAC">H-21</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.10" />
        <vers num="10.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1312" published="1993-02-24" name="CVE-1999-1312" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in DEC OpenVMS VAX 5.5-2 through 5.0, and OpenVMS AXP 1.0, allows local users to gain system privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1993-05.html" source="CERT" patch="1" adv="1">CA-1993-05</ref>
      <ref url="http://xforce.iss.net/static/7142.php" source="XF">openvms-local-privilege-elevation(7142)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dec" name="dec_openvms_axp">
        <vers num="1.0" />
      </prod>
      <prod vendor="dec" name="dec_openvms_vax">
        <vers prev="1" num="5.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1313" published="1996-05-23" name="CVE-1999-1313" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Manual page reader (man) in FreeBSD 2.2 and earlier allows local users to gain privileges via a sequence of commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/g-24.shtml" source="CIAC" patch="1" adv="1">G-24</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-96:11.man.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-96:11</ref>
      <ref url="http://xforce.iss.net/static/7348.php" source="XF">bsd-man-command-sequence(7348)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="2.0" />
        <vers num="2.0.5" />
        <vers num="2.1.0" />
        <vers prev="1" num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1314" published="1996-05-17" name="CVE-1999-1314" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Vulnerability in union file system in FreeBSD 2.2 and earlier, and possibly other operating systems, allows local users to cause a denial of service (system reload) via a series of certain mount_union commands.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-96:10.mount_union.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-96:10</ref>
      <ref url="http://www.iss.net/security_center/static/7429.php" source="XF">unionfs-mount-ordering(7429)</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/g-24.shtml" source="CIAC">G-24</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="2.0" />
        <vers num="2.0.5" />
        <vers num="2.1" edition="stable" />
        <vers num="2.1.0" />
        <vers prev="1" num="2.2" edition="current" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1315" published="1999-12-31" name="CVE-1999-1315" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Vulnerabilities in DECnet/OSI for OpenVMS before 5.8 on DEC Alpha AXP and VAX/VMS systems allow local users to gain privileges or cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/f-04.shtml" source="CIAC" patch="1" adv="1">F-04</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dec" name="dec_openvms">
        <vers prev="1" num="5.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1316" published="1999-12-31" name="CVE-1999-1316" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Passfilt.dll in Windows NT SP2 allows users to create a password that contains the user's name, which could make it easier for an attacker to guess.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/support/kb/articles/Q247/9/75.asp" source="MSKB" patch="1" adv="1">Q247975</ref>
      <ref url="http://xforce.iss.net/static/7391.php" source="XF">passfilt-fullname(7391)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp2:server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1317" published="1999-12-31" name="CVE-1999-1317" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Windows NT 4.0 SP4 and earlier allows local users to gain privileges by modifying the symbolic link table in the \?? object folder using a different case letter (upper or lower) to point to a different device.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/support/kb/articles/q222/1/59.asp" source="MSKB" patch="1" adv="1">Q222159</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92162979530341&amp;w=2" source="NTBUGTRAQ" adv="1">19990314 AW: [ ALERT ] Case Sensitivity and Symbolic Links</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92127046701349&amp;w=2" source="NTBUGTRAQ" adv="1">19990312 [ ALERT ] Case Sensitivity and Symbolic Links</ref>
      <ref url="http://xforce.iss.net/static/7398.php" source="XF">nt-symlink-case(7398)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers prev="1" num="4.0" edition="sp4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1318" published="1993-09-17" name="CVE-1999-1318" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">/usr/5bin/su in SunOS 4.1.3 and earlier uses a search path that includes the current working directory (.), which allows local users to gain privileges via Trojan horse programs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fpatches%2F100630&amp;zone_32=112193%2A%20" source="SUNBUG" patch="1" adv="1">1121935</ref>
      <ref url="http://www.iss.net/security_center/static/7480.php" source="XF">sun-su-path(7480)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.1" />
        <vers num="1.1c" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers prev="1" num="4.1.3" />
        <vers num="4.1.3c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1319" published="1996-01-03" name="CVE-1999-1319" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Vulnerability in object server program in SGI IRIX 5.2 through 6.1 allows remote attackers to gain root privileges in certain configurations.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19960101-01-PX" source="SGI" patch="1" adv="1">19960101-01-PX</ref>
      <ref url="http://www.iss.net/security_center/static/7430.php" source="XF">irix-object-server(7430)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="5" />
        <vers num="5.2" />
        <vers num="6.0" />
        <vers prev="1" num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1320" published="1999-12-31" name="CVE-1999-1320" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Vulnerability in Novell NetWare 3.x and earlier allows local users to gain privileges via packet spoofing.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/d-01.shtml" source="CIAC" patch="1" adv="1">D-01</ref>
      <ref url="http://www.iss.net/security_center/static/7213.php" source="XF">netware-packet-spoofing-privileges(7213)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="netware">
        <vers prev="1" num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1321" published="1998-11-05" name="CVE-1999-1321" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in ssh 1.2.26 client with Kerberos V enabled could allow remote attackers to cause a denial of service or execute arbitrary commands via a long DNS hostname that is not properly handled during TGT ticket passing.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.netspace.org/cgi-bin/wa?A2=ind9811A&amp;L=bugtraq&amp;P=R4814" source="BUGTRAQ">19981105 security patch for ssh-1.2.26 kerberos code</ref>
      <ref url="http://www.osvdb.org/4883" source="OSVDB">4883</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="v" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1322" published="1998-11-12" name="CVE-1999-1322" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The installation of 1ArcServe Backup and Inoculan AV client modules for Exchange create a log file, exchverify.log, which contains usernames and passwords in plaintext.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91133714919229&amp;w=2" source="NTBUGTRAQ">19981117 Re: exchverify.log - update #1</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91096758513985&amp;w=2" source="NTBUGTRAQ">19981112 exchverify.log</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="arcserve_backup">
        <vers num="" />
      </prod>
      <prod vendor="ca" name="inoculan">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1323" published="1999-04-09" name="CVE-1999-1323" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Norton AntiVirus for Internet Email Gateways (NAVIEG) 1.0.1.7 and earlier, and Norton AntiVirus for MS Exchange (NAVMSE) 1.5 and earlier, store the administrator password in cleartext in (1) the navieg.ini file for NAVIEG, and (2) the ModifyPassword registry key in NAVMSE.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92370067416739&amp;w=2" source="NTBUGTRAQ">19990409 NAV for MS Exchange &amp; Internet Email Gateways</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="norton_antivirus">
        <vers prev="1" num="1.0.1.7" edition="" />
        <vers prev="1" num="1.0.1.7" edition=":internet_email_gateways" />
        <vers prev="1" num="1.5" edition="" />
        <vers prev="1" num="1.5" edition=":exchange" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1324" published="1999-12-31" name="CVE-1999-1324" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">VAXstations running Open VMS 5.3 through 5.5-2 with VMS DECwindows or MOTIF do not properly disable access to user accounts that exceed the break-in limit threshold for failed login attempts, which makes it easier for attackers to conduct brute force password guessing.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/d-06.shtml" source="CIAC" patch="1" adv="1">D-06</ref>
      <ref url="http://xforce.iss.net/static/7225.php" source="XF">openvms-sysgen-enabled(7225)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dec" name="dec_openvms_vax">
        <vers num="5.3" />
        <vers num="5.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1325" published="1999-12-31" name="CVE-1999-1325" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">SAS System 5.18 on VAX/VMS is installed with insecure permissions for its directories and startup file, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/c-19.shtml" source="CIAC" adv="1">C-19</ref>
      <ref url="http://xforce.iss.net/static/7261.php" source="XF">vaxvms-sas-gain-privileges(7261)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vax_vms" name="sas_system">
        <vers num="5.18" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1326" published="1997-07-04" name="CVE-1999-1326" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">wu-ftpd 2.4 FTP server does not properly drop privileges when an ABOR (abort file transfer) command is executed during a file transfer, which causes a signal to be handled incorrectly and allows local and possibly remote attackers to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420408&amp;w=2" source="BUGTRAQ" patch="1">19970105 BoS:  serious security bug in wu-ftpd v2.4 -- PATCH</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420401&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19970104 serious security bug in wu-ftpd v2.4</ref>
      <ref url="http://xforce.iss.net/static/7169.php" source="XF">wuftpd-abor-gain-privileges(7169)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="washington_university" name="wu-ftpd">
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1327" published="1999-12-31" name="CVE-1999-1327" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in linuxconf 1.11r11-rh2 on Red Hat Linux 5.1 allows local users to gain root privileges via a long LANG environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/rh51-errata-general.html#linuxconf" source="CONFIRM">http://www.redhat.com/support/errata/rh51-errata-general.html#linuxconf</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221103125826&amp;w=2" source="BUGTRAQ" adv="1">19980601 Re: SECURITY: Red Hat Linux 5.1 linuxconf bug (fwd)</ref>
      <ref url="http://www.osvdb.org/6065" source="OSVDB">6065</ref>
      <ref url="http://www.iss.net/security_center/static/7239.php" source="XF">linuxconf-lang-bo(7239)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1328" published="1999-12-31" name="CVE-1999-1328" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">linuxconf before 1.11.r11-rh3 on Red Hat Linux 5.1 allows local users to overwrite arbitrary files and gain root access via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90383955231511&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19980823 Security concerns in linuxconf shipped w/RedHat 5.1</ref>
      <ref url="http://www.redhat.com/support/errata/rh51-errata-general.html#linuxconf" source="CONFIRM">http://www.redhat.com/support/errata/rh51-errata-general.html#linuxconf</ref>
      <ref url="http://www.osvdb.org/6068" source="OSVDB">6068</ref>
      <ref url="http://www.iss.net/security_center/static/7232.php" source="XF">linuxconf-symlink-gain-privileges(7232)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1329" published="1999-12-31" name="CVE-1999-1329" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in SysVInit in Red Hat Linux 5.1 and earlier allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/rh50-errata-general.html#SysVinit" source="CONFIRM">http://www.redhat.com/support/errata/rh50-errata-general.html#SysVinit</ref>
      <ref url="http://www.iss.net/security_center/static/7250.php" source="XF">sysvinit-root-bo(7250)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers prev="1" num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1330" published="1999-12-31" name="CVE-1999-1330" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The snprintf function in the db library 1.85.4 ignores the size parameter, which could allow attackers to exploit buffer overflows that would be prevented by a properly implemented snprintf.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602661419259&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19970709 [linux-security] so-called snprintf() in db-1.85.4 (fwd)</ref>
      <ref url="http://www.redhat.com/support/errata/rh42-errata-general.html#db" source="CONFIRM">http://www.redhat.com/support/errata/rh42-errata-general.html#db</ref>
      <ref url="http://lists.openresources.com/Debian/debian-bugs-closed/msg00581.html" source="CONFIRM">http://lists.openresources.com/Debian/debian-bugs-closed/msg00581.html</ref>
      <ref url="http://www.iss.net/security_center/static/7244.php" source="XF">linux-libdb-snprintf-bo(7244)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="4.0" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1331" published="1999-12-31" name="CVE-1999-1331" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">netcfg 2.16-1 in Red Hat Linux 4.2 allows the Ethernet interface to be controlled by users on reboot when an option is set, which allows local users to cause a denial of service by shutting down the interface.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/rh42-errata-general.html#netcfg" source="CONFIRM">http://www.redhat.com/support/errata/rh42-errata-general.html#netcfg</ref>
      <ref url="http://www.iss.net/security_center/static/7245.php" source="XF">netcfg-ethernet-dos(7245)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1332" published="1999-12-31" name="CVE-1999-1332" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">gzexe in the gzip package on Red Hat Linux 5.0 and earlier allows local users to overwrite files of other users via a symlink attack on a temporary file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/rh50-errata-general.html#gzip" source="CONFIRM">http://www.redhat.com/support/errata/rh50-errata-general.html#gzip</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88603844115233&amp;w=2" source="BUGTRAQ" adv="1">19980128 GZEXE - the big problem</ref>
      <ref url="http://www.securityfocus.com/bid/7845" source="BID">7845</ref>
      <ref url="http://www.osvdb.org/3812" source="OSVDB">3812</ref>
      <ref url="http://www.iss.net/security_center/static/7241.php" source="XF">gzip-gzexe-tmp-symlink(7241)</ref>
      <ref url="http://www.debian.org/security/2003/dsa-308" source="DEBIAN">DSA-308</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers prev="1" num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1333" published="1999-12-31" name="CVE-1999-1333" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">automatic download option in ncftp 2.4.2 FTP client in Red Hat Linux 5.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the names of files that are to be downloaded.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=89042322924057&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19980319 ncftp 2.4.2 MkDirs bug</ref>
      <ref url="http://www.redhat.com/support/errata/rh50-errata-general.html#ncftp" source="CONFIRM">http://www.redhat.com/support/errata/rh50-errata-general.html#ncftp</ref>
      <ref url="http://www.osvdb.org/6111" source="OSVDB">6111</ref>
      <ref url="http://www.iss.net/security_center/static/7240.php" source="XF">ncftp-autodownload-command-execution(7240)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers prev="1" num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1334" published="1999-12-31" name="CVE-1999-1334" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in filter command in Elm 2.4 allows attackers to execute arbitrary commands via (1) long From: headers, (2) long Reply-To: headers, or (3) via a long -f (filterfile) command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88609666024181&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19980129 KSR[T] Advisory #7: filter</ref>
      <ref url="http://www.redhat.com/support/errata/rh50-errata-general.html#elm" source="CONFIRM">http://www.redhat.com/support/errata/rh50-errata-general.html#elm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="elm_development_group" name="elm">
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1335" published="1999-12-31" name="CVE-1999-1335" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">snmpd server in cmu-snmp SNMP package before 3.3-1 in Red Hat Linux 4.0 is configured to allow remote attackers to read and write sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/rh40-errata-general.html#cmu-snmp" source="CONFIRM">http://www.redhat.com/support/errata/rh40-errata-general.html#cmu-snmp</ref>
      <ref url="http://xforce.iss.net/static/7251.php" source="XF">cmusnmp-read-write(7251)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers prev="1" num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1336" published="1999-08-12" name="CVE-1999-1336" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">3Com HiPer Access Router Card (HiperARC) 4.0 through 4.2.29 allows remote attackers to cause a denial of service (reboot) via a flood of IAC packets to the telnet port.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93492615408725&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19990816 Re: 3com hiperarch flaw [hiperbomb.c]</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93458364903256&amp;w=2" source="BUGTRAQ" patch="1">19990812 3com hiperarch flaw [hiperbomb.c]</ref>
      <ref url="http://www.osvdb.org/6057" source="OSVDB">6057</ref>
    </refs>
    <vuln_soft>
      <prod vendor="3com" name="hiperarc">
        <vers prev="1" num="4.2.29" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1337" published="1999-08-01" name="CVE-1999-1337" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">FTP client in Midnight Commander (mc) before 4.5.11 stores usernames and passwords for visited sites in plaintext in the world-readable history file, which allows other local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93370073207984&amp;w=2" source="BUGTRAQ" adv="1">19990801 midnight commander vulnerability(?) (fwd)</ref>
      <ref url="http://www.osvdb.org/5921" source="OSVDB">5921</ref>
      <ref url="http://www.iss.net/security_center/static/9873.php" source="XF">midnight-commander-data-disclosure(9873)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="midnight_commander" name="midnight_commander">
        <vers prev="1" num="4.5.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1338" published="1999-07-21" name="CVE-1999-1338" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Delegate proxy 5.9.3 and earlier creates files and directories in the DGROOT with world-writable permissions.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93259112204664&amp;w=2" source="BUGTRAQ">19990721 Delegate creates directories writable for anyone</ref>
    </refs>
    <vuln_soft>
      <prod vendor="delegate" name="delegate">
        <vers prev="1" num="5.9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1339" published="1999-12-31" name="CVE-1999-1339" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Vulnerability when Network Address Translation (NAT) is enabled in Linux 2.2.10 and earlier with ipchains, or FreeBSD 3.2 with ipfw, allows remote attackers to cause a denial of service (kernel panic) via a ping -R (record route) command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.2/patch-2.2.11.gz" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.2/patch-2.2.11.gz</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93277766505061&amp;w=2" source="BUGTRAQ" adv="1">19990722 Re: ping -R causes kernel panic on a forwarding machine ( 2.2.5 a nd 2 .2.10)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93277426802802&amp;w=2" source="BUGTRAQ" adv="1">19990722 Linux +ipchains+ ping -R</ref>
      <ref url="http://www.osvdb.org/6105" source="OSVDB">6105</ref>
      <ref url="http://www.iss.net/security_center/static/7257.php" source="XF">ipchains-ping-route-dos(7257)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.2" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers prev="1" num="2.2.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1340" published="1999-11-04" name="CVE-1999-1340" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in faxalter in hylafax 4.0.2 allows local users to gain privileges via a long -m command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/765" source="BID" adv="1">765</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94173799532589&amp;w=2" source="BUGTRAQ" adv="1">19991104 hylafax-4.0.2 local exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hylafax" name="hylafax">
        <vers num="4.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1341" published="1999-10-22" name="CVE-1999-1341" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Linux kernel before 2.3.18 or 2.2.13pre15, with SLIP and PPP options, allows local unprivileged users to forge IP packets via the TIOCSETD option on tty devices.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94061108411308&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19991022 Local user can send forged packets</ref>
      <ref url="http://xforce.iss.net/static/7858.php" source="XF">linux-tiocsetd-forge-packets(7858)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers prev="1" num="2.2.13" edition="pre15" />
        <vers prev="1" num="2.3.18" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1342" published="1999-10-17" name="CVE-1999-1342" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ICQ ActiveList Server allows remote attackers to cause a denial of service (crash) via malformed packets to the server's UDP port.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94042342010662&amp;w=2" source="NTBUGTRAQ" adv="1">19991017 ICQ ActiveList Server Exploit...</ref>
    </refs>
    <vuln_soft>
      <prod vendor="icq" name="activelist_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1343" published="1999-10-13" name="CVE-1999-1343" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">HTTP server for Xerox DocuColor 4 LP allows remote attackers to cause a denial of service (hang) via a long URL that contains a large number of . characters.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93986405412867&amp;w=2" source="BUGTRAQ" adv="1">19991013 Xerox DocuColor 4 LP D.O.S</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xerox" name="docucolor_4lp">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1344" published="1999-10-05" name="CVE-1999-1344" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Auto_FTP.pl script in Auto_FTP 0.2 stores usernames and passwords in plaintext in the auto_ftp.conf configuration file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93923873006014&amp;w=2" source="BUGTRAQ">19991005 Auto_FTP v0.02 Advisory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="auto_ftp" name="auto_ftp">
        <vers num="0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1345" published="1999-10-05" name="CVE-1999-1345" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Auto_FTP.pl script in Auto_FTP 0.2 uses the /tmp/ftp_tmp as a shared directory with insecure permissions, which allows local users to (1) send arbitrary files to the remote server by placing them in the directory, and (2) view files that are being transferred.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93923873006014&amp;w=2" source="BUGTRAQ">19991005 Auto_FTP v0.02 Advisory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="auto_ftp" name="auto_ftp">
        <vers num="0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1346" published="1999-10-07" name="CVE-1999-1346" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PAM configuration file for rlogin in Red Hat Linux 6.1 and earlier includes a less restrictive rule before a more restrictive one, which allows users to access the host via rlogin even if rlogin has been explicitly disabled using the /etc/nologin file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93942774609925&amp;w=2" source="BUGTRAQ" adv="1">19991007 Problems with redhat 6 Xsession and pam.d/rlogin.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers prev="1" num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1347" published="1999-10-07" name="CVE-1999-1347" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Xsession in Red Hat Linux 6.1 and earlier can allow local users with restricted accounts to bypass execution of the .xsession file by starting kde, gnome or anotherlevel from kdm.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93942774609925&amp;w=2" source="BUGTRAQ" adv="1">19991007 Problems with redhat 6 Xsession and pam.d/rlogin.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers prev="1" num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1348" published="1999-06-30" name="CVE-1999-1348" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Linuxconf on Red Hat Linux 6.0 and earlier does not properly disable PAM-based access to the shutdown command, which could allow local users to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93220073515880&amp;w=2" source="BUGTRAQ" adv="1">19990630 linuxconf doesn't seem to deal correctly with /etc/pam.d/reboot</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers prev="1" num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1349" published="1999-10-06" name="CVE-1999-1349" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">NFS daemon (nfsd.exe) for Omni-NFS/X 6.1 allows remote attackers to cause a denial of service (resource exhaustion) via certain packets, possibly with the Urgent (URG) flag set, to port 111.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93923679004325&amp;w=2" source="BUGTRAQ" adv="1">19991006 Omni-NFS/X Enterprise  (nfsd.exe) DOS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xlink_technology" name="omni-nfs_x_enterprise">
        <vers num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1350" published="1999-09-29" name="CVE-1999-1350" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">ARCAD Systemhaus 0.078-5 installs critical programs and files with world-writeable permissions, which could allow local users to gain privileges by replacing a program with a Trojan horse.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93871933521519&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19990929 Multiple Vendor ARCAD permission problems</ref>
    </refs>
    <vuln_soft>
      <prod vendor="arcad_systemhaus" name="arcad">
        <vers num="0.078_5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1351" published="1999-09-24" name="CVE-1999-1351" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in KVIrc IRC client 0.9.0 with the "Listen to !nick &lt;soundname> requests" option enabled allows remote attackers to read arbitrary files via a .. (dot dot) in a DCC GET request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.iss.net/security_center/static/7761.php" source="XF">kvirc-dot-directory-traversal(7761)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93845560631314&amp;w=2" source="BUGTRAQ">19990924 Kvirc bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kvirc" name="irc_client">
        <vers num="0.9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1352" published="1999-09-28" name="CVE-1999-1352" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">mknod in Linux 2.2 follows symbolic links, which could allow local users to overwrite files or gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93855134409747&amp;w=2" source="BUGTRAQ" adv="1">19990928 Re: [Fwd: Truth about ssh 1.2.27 vulnerabiltiy]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1353" published="1999-09-07" name="CVE-1999-1353" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Nosque MsgCore 2.14 stores passwords in cleartext: (1) the administrator password in the AdmPasswd registry key, and (2) user passwords in the Userbase.dbf data file, which could allow local users to gain privielges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93698162708211&amp;w=2" source="BUGTRAQ" adv="1">19990907 MsgCore mailserver stores passwords in clear text</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nosque" name="msgcore">
        <vers num="2.14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1354" published="1999-08-30" name="CVE-1999-1354" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">E-mail client in Softarc FirstClass Internet Server 5.506 and earlier stores usernames and passwords in cleartext in the files (1) home.fc for version 5.506, (2) network.fc for version 3.5, or (3) FCCLIENT.LOG when logging is enabled.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93698283309513&amp;w=2" source="NTBUGTRAQ" adv="1">19990909 SoftArc's FirstClass E-mail Client</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93637687305327&amp;w=2" source="NTBUGTRAQ" adv="1">19990830 SoftArc's FirstClass E-mail Client</ref>
    </refs>
    <vuln_soft>
      <prod vendor="softarc" name="firstclass_internet_server">
        <vers prev="1" num="5.506" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1355" published="1999-12-31" name="CVE-1999-1355" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">BMC Patrol component, when installed with Compaq Insight Management Agent 4.23 and earlier, or Management Agents for Servers 4.40 and earlier, creates a PFCUser account with a default password and potentially dangerous privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3231.php" source="XF" patch="1" adv="1">management-pfcuser(3231)</ref>
      <ref url="http://www.compaq.com/products/servers/management/advisory.html" source="CONFIRM" adv="1">http://www.compaq.com/products/servers/management/advisory.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93654336516711&amp;w=2" source="NTBUGTRAQ" adv="1">19990905 Case ID  SSRT0620  - PFCUser account communication</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93542118727732&amp;w=2" source="NTBUGTRAQ" adv="1">19990817 Compaq PFCUser account</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94183795025294&amp;w=2" source="NTBUGTRAQ">19991105 UPDATE: SSRT0620 Compaq Foundation Agents v4.40B  PFCUser issues</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93759822430801&amp;w=2" source="NTBUGTRAQ">19990915 (I) UPDATE - PFCUser Account,</ref>
    </refs>
    <vuln_soft>
      <prod vendor="compaq" name="insight_management_agent">
        <vers prev="1" num="4.20" />
      </prod>
      <prod vendor="compaq" name="management_agents_for_servers">
        <vers prev="1" num="4.40" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1356" published="1999-09-02" name="CVE-1999-1356" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Compaq Integration Maintenance Utility as used in Compaq Insight Manager agent before SmartStart 4.50 modifies the legal notice caption (LegalNoticeCaption) and text (LegalNoticeText) in Windows NT, which could produce a legal notice that is in violation of the security policy.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93759822830815&amp;w=2" source="NTBUGTRAQ" adv="1">19990917 Re: Compaq CIM UG Overwrites Legal Notice</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93646669500991&amp;w=2" source="BUGTRAQ" adv="1">19990902 Compaq CIM UG Overwrites Legal Notice</ref>
      <ref url="http://www.iss.net/security_center/static/7763.php" source="XF">compaq-smartstart-legal-notice(7763)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93637792706047&amp;w=2" source="NTBUGTRAQ">19990902 Compaq CIM UG Overwrites Legal Notice</ref>
    </refs>
    <vuln_soft>
      <prod vendor="compaq" name="smartstart">
        <vers prev="1" num="4.50" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1357" published="1999-10-05" name="CVE-1999-1357" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Netscape Communicator 4.04 through 4.7 (and possibly other versions) in various UNIX operating systems converts the 0x8b character to a "&lt;" sign, and the 0x9b character to a ">" sign, which could allow remote attackers to attack other clients via cross-site scripting (CSS) in CGI programs that do not filter these characters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93915331626185&amp;w=2" source="BUGTRAQ" adv="1">19991005 Time to update those CGIs again</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="communicator">
        <vers num="4.04" />
        <vers num="4.51" />
        <vers prev="1" num="4.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1358" published="1999-12-31" name="CVE-1999-1358" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">When an administrator in Windows NT or Windows 2000 changes a user policy, the policy is not properly updated if the local ntconfig.pol is not writable by the user, which could allow local users to bypass restrictions that would otherwise be enforced by the policy, possibly by changing the policy file to be read-only.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/support/kb/articles/q157/6/73.asp" source="MSKB" patch="1" adv="1">Q157673</ref>
      <ref url="http://www.iss.net/security_center/static/7400.php" source="XF">nt-user-policy-update(7400)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1359" published="1999-12-31" name="CVE-1999-1359" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">When the Ntconfig.pol file is used on a server whose name is longer than 13 characters, Windows NT does not properly enforce policies for global groups, which could allow users to bypass restrictions that were intended by those policies.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/support/kb/articles/q163/8/75.asp" source="MSKB" patch="1" adv="1">Q163875</ref>
      <ref url="http://www.iss.net/security_center/static/7401.php" source="XF">nt-group-policy-longname(7401)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1360" published="1999-12-31" name="CVE-1999-1360" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Windows NT 4.0 allows local users to cause a denial of service via a user mode application that closes a handle that was opened in kernel mode, which causes a crash when the kernel attempts to close the handle.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/support/kb/articles/q160/6/50.asp" source="MSKB" patch="1" adv="1">Q160650</ref>
      <ref url="http://www.iss.net/security_center/static/7402.php" source="XF">nt-kernel-handle-dos(7402)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1361" published="1998-05-09" name="CVE-1999-1361" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Windows NT 3.51 and 4.0 running WINS (Windows Internet Name Service) allows remote attackers to cause a denial of service (resource exhaustion) via a flood of malformed packets, which causes the server to slow down and fill the event logs with error messages.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101925891&amp;w=2" source="BUGTRAQ" adv="1">19980509 coke.c</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="3.5.1" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1362" published="1999-12-31" name="CVE-1999-1362" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Win32k.sys in Windows NT 4.0 before SP2 allows local users to cause a denial of service (crash) by calling certain WIN32K functions with incorrect parameters.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/support/kb/articles/q160/6/01.asp" source="MSKB" patch="1" adv="1">Q160601</ref>
      <ref url="http://www.iss.net/security_center/static/7403.php" source="XF">nt-win32k-dos(7403)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers prev="1" num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1363" published="1999-12-31" name="CVE-1999-1363" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Windows NT 3.51 and 4.0 allow local users to cause a denial of service (crash) by running a program that creates a large number of locks on a file, which exhausts the NonPagedPool.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/support/kb/articles/q163/1/43.asp" source="MSKB" patch="1" adv="1">Q163143</ref>
      <ref url="http://www.iss.net/security_center/static/7405.php" source="XF">nt-nonpagedpool-dos(7405)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="3.5.1" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1364" published="1999-12-31" name="CVE-1999-1364" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Windows NT 4.0 allows local users to cause a denial of service (crash) via an illegal kernel mode address to the functions (1) GetThreadContext or (2) SetThreadContext.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/support/kb/articles/q142/6/53.asp" source="MSKB" patch="1" adv="1">Q142653</ref>
      <ref url="http://www.iss.net/security_center/static/7421.php" source="XF">nt-threadcontext-dos(7421)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1365" published="1999-06-28" name="CVE-1999-1365" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Windows NT searches a user's home directory (%systemroot% by default) before other directories to find critical programs such as NDDEAGNT.EXE, EXPLORER.EXE, USERINIT.EXE or TASKMGR.EXE, which could allow local users to bypass access restrictions or gain privileges by placing a Trojan horse program into the root directory, which is writable by default.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/0515" source="BID" patch="1" adv="1">0515</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93069418400856&amp;w=2" source="NTBUGTRAQ" patch="1" adv="1">19990628 NT runs Explorer.exe, Taskmgr.exe etc. from wrong location</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/2336" source="XF" adv="1">nt-login-default-folder(2336)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93127894731200&amp;w=2" source="NTBUGTRAQ" adv="1">19990630 Update: NT runs explorer.exe, etc...</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1366" published="1999-05-15" name="CVE-1999-1366" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Pegasus e-mail client 3.0 and earlier uses weak encryption to store POP3 passwords in the pmail.ini file, which allows local users to easily decrypt the passwords and read e-mail.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92714118829880&amp;w=2" source="BUGTRAQ">19990515 Pegasus Mail weak encryption</ref>
    </refs>
    <vuln_soft>
      <prod vendor="david_harris" name="pegasus_mail">
        <vers prev="1" num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1367" published="1999-05-06" name="CVE-1999-1367" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Internet Explorer 5.0 does not properly reset the username/password cache for Web sites that do not use standard cache controls, which could allow users on the same system to access restricted web sites that were visited by other users.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.pcworld.com/news/article/0,aid,10842,00.asp" source="MISC" patch="1" adv="1">http://www.pcworld.com/news/article/0,aid,10842,00.asp</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1368" published="1999-05-12" name="CVE-1999-1368" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">AV Option for MS Exchange Server option for InoculateIT 4.53, and possibly other versions, only scans the Inbox folder tree of a Microsoft Exchange server, which could allow viruses to escape detection if a user's rules cause the message to be moved to a different mailbox.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=97439568517355&amp;w=2" source="NTBUGTRAQ" patch="1" adv="1">20001116 InoculateIT AV Option for MS Exchange Server</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92652152723629&amp;w=2" source="NTBUGTRAQ" adv="1">19990512 InoculateIT 4.53 Real-Time Exchange Scanner Flawed</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="inoculateit">
        <vers num="4.53" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1369" published="1999-04-14" name="CVE-1999-1369" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Real Media RealServer (rmserver) 6.0.3.353 stores a password in plaintext in the world-readable rmserver.cfg file, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92411181619110&amp;w=2" source="BUGTRAQ">19990414 Real Media Server stores passwords in plain text</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realserver">
        <vers num="6.0.3.353" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1370" published="1999-03-23" name="CVE-1999-1370" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The setup wizard (ie5setup.exe) for Internet Explorer 5.0 disables (1) the screen saver, which could leave the system open to users with physical access if a failure occurs during an unattended installation, and (2) the Task Scheduler Service, which might prevent the scheduled execution of security-critical programs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92220197414799&amp;w=2" source="NTBUGTRAQ">19990323 MSIE 5 installer disables screen saver</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1371" published="1999-03-08" name="CVE-1999-1371" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in /usr/bin/write in Solaris 2.6 and 7 allows local users to gain privileges via a long string in the terminal name argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/7546" source="XF">solaris-write-bo(7546)</ref>
      <ref url="http://www.securiteam.com/exploits/5ZP0O1P35O.html" source="MISC">http://www.securiteam.com/exploits/5ZP0O1P35O.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92100752221493&amp;w=2" source="BUGTRAQ">19990308 Solaris "/usr/bin/write" bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.5.1" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1372" published="1999-02-19" name="CVE-1999-1372" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Triactive Remote Manager with Basic authentication enabled stores the username and password in cleartext in registry keys, which could allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91966339502073&amp;w=2" source="BUGTRAQ">19990219 Plaintext Password in Tractive's Remote Manager Software</ref>
    </refs>
    <vuln_soft>
      <prod vendor="triactive" name="remote_management">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1373" published="2005-01-05" name="CVE-1999-1373" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">FORE PowerHub before 5.0.1 allows remote attackers to cause a denial of service (hang) via a TCP SYN scan with TCP/IP OS fingerprinting, e.g. via nmap.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91651770130771&amp;w=2" source="BUGTRAQ">19990105 Re: Network Scan Vulnerability [SUMMARY]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fore" name="powerhub_software">
        <vers prev="1" num="5.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1374" published="2005-05-02" name="CVE-1999-1374" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">perlshop.cgi shopping cart program stores sensitive customer information in directories and files that are under the web root, which allows remote attackers to obtain that information via an HTTP request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92523159819402&amp;w=2" source="BUGTRAQ">19990427 Re: Shopping Carts exposing CC data</ref>
    </refs>
    <vuln_soft>
      <prod vendor="arpanet" name="perlshop">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1375" published="1999-02-11" name="CVE-1999-1375" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/230" source="BID" adv="1">230</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91877455626320&amp;w=2" source="NTBUGTRAQ">19990211 Using FSO in ASP to view just about anything</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="3.0" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1376" published="1999-01-14" name="CVE-1999-1376" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91632724913080&amp;w=2" source="NTBUGTRAQ" adv="1">19990114 MS IIS 4.0 Security Advisory</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91638375309890&amp;w=2" source="BUGTRAQ">19990114 MS IIS 4.0 Security Advisory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1377" published="1999-09-09" name="CVE-1999-1377" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Matt Wright's download.cgi 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://pulhas.org/phrack/55/P55-07.html" source="MISC" adv="1">http://pulhas.org/phrack/55/P55-07.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="matt_wright" name="download.cgi">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1378" published="1999-07-19" name="CVE-1999-1378" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">dbmlparser.exe CGI guestbook program does not perform a chroot operation properly, which allows remote attackers to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93250710625956&amp;w=2" source="BUGTRAQ">19990917 improper chroot in dbmlparser.exe</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dbmlparser.exe" name="dbmlparser.exe">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1379" published="1999-12-31" name="CVE-1999-1379" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">DNS allows remote attackers to use DNS name servers as traffic amplifiers via a UDP DNS query with a spoofed source address, which produces more traffic to the victim than was sent by the attacker.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="ftp://ftp.auscert.org.au/pub/auscert/advisory/AL-1999.004.dns_dos" source="AUSCERT" patch="1" adv="1">AL-1999.004</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93433758607623&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19990810 Possible Denial Of Service using DNS</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/j-063.shtml" source="CIAC" patch="1" adv="1">J-063</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93348057829957&amp;w=2" source="BUGTRAQ" adv="1">19990730 Possible Denial Of Service using DNS</ref>
      <ref url="http://www.iss.net/security_center/static/7238.php" source="XF">dns-udp-query-dos(7238)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dnstools_software" name="dnstools">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1380" published="1997-05-04" name="CVE-1999-1380" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Symantec Norton Utilities 2.0 for Windows 95 marks the TUNEOCX.OCX ActiveX control as safe for scripting, which allows remote attackers to execute arbitrary commands via the run option through malicious web pages that are accessed by browsers such as Internet Explorer 3.0.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
      <env />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://mlarchive.ima.com/win95/1997/May/0342.html" source="MISC" patch="1" adv="1">http://mlarchive.ima.com/win95/1997/May/0342.html</ref>
      <ref url="http://www.net-security.sk/bugs/NT/nu20.html" source="MISC">http://www.net-security.sk/bugs/NT/nu20.html</ref>
      <ref url="http://news.zdnet.co.uk/story/0,,s2065518,00.html" source="MISC" adv="1">http://news.zdnet.co.uk/story/0,,s2065518,00.html</ref>
      <ref url="http://www.iss.net/security_center/static/7188.php" source="XF">nu-tuneocx-activex-control(7188)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="norton_utilities">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1381" published="1998-10-08" name="CVE-1999-1381" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in dbadmin CGI program 1.0.1 on Linux allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90786656409618&amp;w=2" source="BUGTRAQ">19981008 buffer overflow in dbadmin</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dbadmin" name="dbadmin">
        <vers num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1382" published="1999-12-31" name="CVE-1999-1382" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">NetWare NFS mode 1 and 2 implements the "Read Only" flag in Unix by changing the ownership of a file to root, which allows local users to gain root privileges by creating a setuid program and setting it to "Read Only," which NetWare-NFS changes to a setuid root program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://support.novell.com/cgi-bin/search/tidfinder.cgi?2940551" source="CONFIRM" patch="1" adv="1">http://support.novell.com/cgi-bin/search/tidfinder.cgi?2940551</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90295697702474&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19980812 Re: Netware NFS (fwd)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88427711321769&amp;w=2" source="BUGTRAQ" adv="1">19980108 NetWare NFS</ref>
      <ref url="http://www.iss.net/security_center/static/7246.php" source="XF">netware-nfs-file-ownership(7246)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="netware">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1383" published="1996-09-13" name="CVE-1999-1383" modified="2011-08-08" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">(1) bash before 1.14.7, and (2) tcsh 6.05 allow local users to gain privileges via directory names that contain shell metacharacters (` back-tick), which can cause the commands enclosed in the directory name to be executed when the shell expands filenames using the \w option in the PS1 variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.dataguard.no/bugtraq/1996_3/0503.html" source="BUGTRAQ" patch="1" adv="1">19960919 Vulnerability in expansion of PS1 in bash &amp; tcsh</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167419868&amp;w=2" source="BUGTRAQ">19960913 tee see shell problems</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="bash">
        <vers num="1.14.0" />
        <vers num="1.14.1" />
        <vers num="1.14.2" />
        <vers num="1.14.3" />
        <vers num="1.14.4" />
        <vers num="1.14.5" />
        <vers prev="1" num="1.14.6" />
      </prod>
      <prod vendor="tcsh" name="tcsh">
        <vers num="6.05" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1384" published="1996-10-30" name="CVE-1999-1384" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Indigo Magic System Tour in the SGI system tour package (systour) for IRIX 5.x through 6.3 allows local users to gain root privileges via a Trojan horse .exitops program, which is called by the inst command that is executed by the RemoveSystemTour program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-96.08.SGI.systour.vul" source="AUSCERT" patch="1" adv="1">AA-96.08</ref>
      <ref url="http://www.securityfocus.com/bid/470" source="BID" patch="1" adv="1">470</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420095&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19961030 (Another) vulnerability in new SGIs</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19961101-01-I" source="SGI" patch="1" adv="1">19961101-01-I</ref>
      <ref url="http://www.iss.net/security_center/static/7456.php" source="XF">irix-systour(7456)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="5" />
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.1" />
        <vers num="5.1.1" />
        <vers num="5.2" />
        <vers num="5.3" edition="" />
        <vers num="5.3" edition=":xfs" />
        <vers num="6.0" />
        <vers num="6.0.1" edition="" />
        <vers num="6.0.1" edition=":xfs" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers prev="1" num="6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1385" published="1996-12-19" name="CVE-1999-1385" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in ppp program in FreeBSD 2.1 and earlier allows local users to gain privileges via a long HOME environment variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-96:20.stack-overflow.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-96:20</ref>
      <ref url="http://www.osvdb.org/6085" source="OSVDB">6085</ref>
      <ref url="http://www.iss.net/security_center/static/7465.php" source="XF">ppp-bo(7465)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420332&amp;w=2" source="BUGTRAQ">19961219 Exploit for ppp bug (FreeBSD 2.1.0).</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers prev="1" num="2.1.0" />
        <vers num="2.1.5" />
        <vers num="2.1.6" />
        <vers num="2.1.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1386" published="1999-12-31" name="CVE-1999-1386" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Perl 5.004_04 and earlier follows symbolic links when running with the -e option, which allows local users to overwrite arbitrary files via a symlink attack on the /tmp/perl-eaXXXXX file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88932165406213&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19980308 another /tmp race: `perl -e' opens temp file not safely</ref>
      <ref url="http://www.redhat.com/support/errata/rh50-errata-general.html#perl" source="CONFIRM">http://www.redhat.com/support/errata/rh50-errata-general.html#perl</ref>
      <ref url="http://www.iss.net/security_center/static/7243.php" source="XF">perl-e-tmp-symlink(7243)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="larry_wall" name="perl">
        <vers prev="1" num="5.4.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1387" published="1997-04-02" name="CVE-1999-1387" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Windows NT 4.0 SP2 allows remote attackers to cause a denial of service (crash), possibly via malformed inputs or packets, such as those generated by a Linux smbmount command that was compiled on the Linux 2.0.29 kernel but executed on Linux 2.0.25.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420741&amp;w=2" source="BUGTRAQ" adv="1">19970407 DUMP of NT system crash</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420732&amp;w=2" source="BUGTRAQ" adv="1">19970403 Fatal bug in NT 4.0 server (more comments)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420731&amp;w=2" source="BUGTRAQ" adv="1">19970402 Fatal bug in NT 4.0 server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1388" published="1994-05-13" name="CVE-1999-1388" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">passwd in SunOS 4.1.x allows local users to overwrite arbitrary files via a symlink attack and the -F command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www2.dataguard.no/bugtraq/1994_2/0207.html" source="BUGTRAQ" patch="1">19940514 [8lgm]-Advisory-7.UNIX.passwd.11-May-1994.NEWFIX</ref>
      <ref url="http://www2.dataguard.no/bugtraq/1994_2/0197.html" source="BUGTRAQ" patch="1" adv="1">19940513 [8lgm]-Advisory-7.UNIX.passwd.11-May-1994</ref>
      <ref url="http://www.dataguard.no/bugtraq/1994_4/0755.html" source="BUGTRAQ" patch="1" adv="1">19941218 Sun Patch Id #102060-01</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1389" published="1998-05-11" name="CVE-1999-1389" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">US Robotics/3Com Total Control Chassis with Frame Relay between 3.6.22 and 3.7.24 does not properly enforce access filters when the "set host prompt" setting is made for a port, which allows attackers to bypass restrictions by providing the hostname twice at the "host: " prompt.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/99" source="BID" adv="1">99</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101925916&amp;w=2" source="BUGTRAQ" adv="1">19980511 3Com/USR Total Control Chassis dialup port access filters</ref>
    </refs>
    <vuln_soft>
      <prod vendor="3com" name="total_control_netserver_card">
        <vers prev="1" num="3.7.24" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1390" published="1998-04-28" name="CVE-1999-1390" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">suidexec in suidmanager 0.18 on Debian 2.0 allows local users to gain root privileges by specifying a malicious program on the command line.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://darwin.bio.uci.edu/~mcoogan/bugtraq/msg00890.html" source="BUGTRAQ" patch="1" adv="1">19980428 [Debian 2.0] /usr/bin/suidexec gives root access</ref>
      <ref url="http://www.securityfocus.com/bid/94" source="BID">94</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1391" published="1990-10-03" name="CVE-1999-1391" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in NeXT 1.0a and 1.0 with publicly accessible printers allows local users to gain privileges via a combination of the npd program and weak directory permissions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1990-06.html" source="CERT" patch="1" adv="1">CA-1990-06</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/b-01.shtml" source="CIAC" patch="1" adv="1">B-01</ref>
      <ref url="http://www.securityfocus.com/bid/10" source="BID">10</ref>
      <ref url="http://www.iss.net/security_center/static/7143.php" source="XF">nextstep-npd-root-access(7143)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="next" name="next">
        <vers num="1.0" />
        <vers num="1.0a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1392" published="1990-10-03" name="CVE-1999-1392" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in restore0.9 installation script in NeXT 1.0a and 1.0 allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1990-06.html" source="CERT" patch="1" adv="1">CA-1990-06</ref>
      <ref url="http://www.securityfocus.com/bid/9" source="BID" patch="1" adv="1">9</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/b-01.shtml" source="CIAC" patch="1" adv="1">B-01</ref>
      <ref url="http://www.iss.net/security_center/static/7144.php" source="XF">nextstep-restore09-root-access(7144)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="next" name="nex">
        <vers num="1.0a" />
      </prod>
      <prod vendor="next" name="next">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1393" published="1999-05-21" name="CVE-1999-1393" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Control Panel "Password Security" option for Apple Powerbooks allows attackers with physical access to the machine to bypass the security by booting it with an emergency startup disk and using a disk editor to modify the on/off toggle or password in the aaaaaaaAPWD file, which is normally inaccessible.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/532" source="BID" adv="1">532</ref>
      <ref url="http://freaky.staticusers.net/macsec/data/powerbooksecurity-data.html" source="MISC" adv="1">http://freaky.staticusers.net/macsec/data/powerbooksecurity-data.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os">
        <vers num="8.5" />
        <vers num="8.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1394" published="1999-07-02" name="CVE-1999-1394" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">BSD 4.4 based operating systems, when running at security level 1, allow the root user to clear the immutable and append-only flags for files by unmounting the file system and using a file system editor such as fsdb to directly modify the file through a device.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93094058620450&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19990702 BSD-fileflags</ref>
      <ref url="http://www.securityfocus.com/bid/510" source="BID">510</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bsd" name="bsd">
        <vers num="4.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1395" published="1992-11-17" name="CVE-1999-1395" modified="2009-10-31" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in Monitor utility (SYS$SHARE:SPISHR.EXE) in VMS 5.0 through 5.4-2 allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-92.16.VMS.Monitor.vulnerability" source="CERT" patch="1" adv="1">CA-92.16</ref>
      <ref url="http://www.cert.org/advisories/CA-1992-18.html" source="CERT" patch="1" adv="1">CA-1992-18</ref>
      <ref url="http://www.securityfocus.com/bid/51" source="BID">51</ref>
      <ref url="http://www.iss.net/security_center/static/7136.php" source="XF">vms-monitor-gain-privileges(7136)</ref>
      <ref url="http://osvdb.org/59332" source="OSVDB">59332</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dec" name="dec_openvms">
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.1" />
        <vers num="5.1.1" />
        <vers num="5.1.2" />
        <vers num="5.1b" />
        <vers num="5.2" />
        <vers num="5.2.1" />
        <vers num="5.3" />
        <vers num="5.3.1" />
        <vers num="5.3.2" />
        <vers num="5.4" />
        <vers num="5.4.1" />
        <vers num="5.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1396" published="1992-07-21" name="CVE-1999-1396" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in integer multiplication emulation code on SPARC architectures for SunOS 4.1 through 4.1.2 allows local users to gain root access or cause a denial of service (crash).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1992-15.html" source="CERT" patch="1" adv="1">CA-1992-15</ref>
      <ref url="http://www.securityfocus.com/bid/49" source="BID">49</ref>
      <ref url="http://www.iss.net/security_center/static/7150.php" source="XF">sun-integer-multiplication-access(7150)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1397" published="1999-03-23" name="CVE-1999-1397" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Index Server 2.0 on IIS 4.0 stores physical path information in the ContentIndex\Catalogs subkey of the AllowedPaths registry key, whose permissions allows local and remote users to obtain the physical paths of directories that are being indexed.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92242671024118&amp;w=2" source="BUGTRAQ">19990323 Index Server 2.0 and the Registry</ref>
      <ref url="http://www.securityfocus.com/bid/476" source="BID">476</ref>
      <ref url="http://www.iss.net/security_center/static/7559.php" source="XF">iis-indexserver-reveal-path(7559)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92223293409756&amp;w=2" source="NTBUGTRAQ">19990323 Index Server 2.0 and the Registry</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="index_server">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1398" published="1997-05-07" name="CVE-1999-1398" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">Vulnerability in xfsdump in SGI IRIX may allow local users to obtain root privileges via the bck.log log file, possibly via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/472" source="BID" patch="1" adv="1">472</ref>
      <ref url="http://www.insecure.org/sploits/irix.xfsdump.html" source="MISC">http://www.insecure.org/sploits/irix.xfsdump.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420921&amp;w=2" source="BUGTRAQ" adv="1">19970507 Irix: misc</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.1" />
        <vers num="5.1.1" />
        <vers num="5.2" />
        <vers num="5.3" edition="" />
        <vers num="5.3" edition=":xfs" />
        <vers num="6.0" />
        <vers num="6.0.1" edition="" />
        <vers num="6.0.1" edition=":xfs" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1399" published="1997-08-20" name="CVE-1999-1399" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">spaceball program in SpaceWare 7.3 v1.0 in IRIX 6.2 allows local users to gain root privileges by setting the HOSTNAME environmental variable to contain the commands to be executed.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/471" source="BID" patch="1" adv="1">471</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602746719552&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19970820 SpaceWare 7.3 v1.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1400" published="1999-06-03" name="CVE-1999-1400" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The Economist screen saver 1999 with the "Password Protected" option enabled allows users with physical access to the machine to bypass the screen saver and read files by running Internet Explorer while the screen is still locked.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/466" source="BID">466</ref>
      <ref url="http://archives.indenial.com/hypermail/ntbugtraq/1999/June1999/0009.html" source="NTBUGTRAQ" adv="1">19990603 Re: Huge Exploit in NT 4.0 SP5 Screensaver with Password Protecti on Enabled.</ref>
      <ref url="http://archives.indenial.com/hypermail/ntbugtraq/1999/June1999/0007.html" source="NTBUGTRAQ" adv="1">19990603 Huge Exploit in NT 4.0 SP5 Screensaver with Password Protection Enabled</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92851653600852&amp;w=2" source="NTBUGTRAQ">19990604 Official response from The Economist re: 1999 Screen Saver</ref>
    </refs>
    <vuln_soft>
      <prod vendor="the_economist" name="the_economist_1999_screen_saver">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1401" published="1996-12-05" name="CVE-1999-1401" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Vulnerability in Desktop searchbook program in IRIX 5.0.x through 6.2 sets insecure permissions for certain user files (iconbook and searchbook).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/463" source="BID" patch="1" adv="1">463</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19961201-01-PX" source="SGI" patch="1" adv="1">19961201-01-PX</ref>
      <ref url="http://www.iss.net/security_center/static/7575.php" source="XF">irix-searchbook-permissions(7575)</ref>
      <ref url="http://www.osvdb.org/8563" source="OSVDB">8563</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.1" />
        <vers num="5.1.1" />
        <vers num="5.2" />
        <vers num="5.3" edition="" />
        <vers num="5.3" edition=":xfs" />
        <vers num="6.0" />
        <vers num="6.0.1" edition="" />
        <vers num="6.0.1" edition=":xfs" />
        <vers num="6.1" />
        <vers num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1402" published="1997-05-17" name="CVE-1999-1402" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The access permissions for a UNIX domain socket are ignored in Solaris 2.x and SunOS 4.x, and other BSD-based operating systems before 4.4, which could allow local users to connect to the socket and possibly disrupt or control the operations of the program using that socket.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/456" source="BID" patch="1" adv="1">456</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602248718482&amp;w=2" source="BUGTRAQ" adv="1">19971003 Solaris 2.6 and sockets</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167418317&amp;w=2" source="BUGTRAQ" adv="1">19970517 UNIX domain socket (Solarisx86 2.5)</ref>
      <ref url="http://www.iss.net/security_center/static/7172.php" source="XF">sun-domain-socket-permissions(7172)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.8" />
        <vers num="3.0" />
        <vers num="3.1" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.0" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":ppc" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1403" published="1998-10-02" name="CVE-1999-1403" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">IBM/Tivoli OPC Tracker Agent version 2 release 1 creates files, directories, and IPC message queues with insecure permissions (world-readable and world-writable), which could allow local users to disrupt operations and possibly gain privileges by modifying or deleting files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/382" source="BID">382</ref>
      <ref url="http://www.securityfocus.com/archive/1/10771" source="BUGTRAQ" adv="1">19981002 Several potential security problems in IBM/Tivoli OPC Tracker Age nt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="tivoli_opc_tracker_agent">
        <vers num="1.0x" />
        <vers num="2.0x" />
        <vers num="3.0x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1404" published="1998-10-02" name="CVE-1999-1404" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IBM/Tivoli OPC Tracker Agent version 2 release 1 allows remote attackers to cause a denial of service (resource exhaustion) via malformed data to the localtracker client port (5011), which prevents the connection from being closed properly.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/382" source="BID">382</ref>
      <ref url="http://www.securityfocus.com/archive/1/10771" source="BUGTRAQ" adv="1">19981002 Several potential security problems in IBM/Tivoli OPC Tracker Age nt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="tivoli_opc_tracker_agent">
        <vers num="1.0x" />
        <vers num="2.0x" />
        <vers num="3.0x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1405" published="1999-02-17" name="CVE-1999-1405" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which could allow local users to access the shadowed password file by creating /tmp/ibmsupt/general/passwd before root runs snap -a.</descript>
    </desc>
    <sols>
      <sol source="nvd">Fixed in AIX 4.3 and 4.3.2
AIX 4.3.x APAR: IX88263
AIX 4.2.x APAR: IX88261</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/375" source="BID">375</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91954824614013&amp;w=2" source="BUGTRAQ">19990220 Re: snap utility for AIX.</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91936783009385&amp;w=2" source="BUGTRAQ">19990217 snap utility for AIX.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="3.2.5" />
        <vers num="4.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
        <vers num="4.2" />
        <vers num="4.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1406" published="1998-07-29" name="CVE-1999-1406" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">dumpreg in Red Hat Linux 5.1 opens /dev/mem with O_RDWR access, which allows local users to cause a denial of service (crash) by redirecting fd 1 (stdout) to the kernel.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526185&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19980729 Crash a redhat 5.1 linux box</ref>
      <ref url="http://www.securityfocus.com/bid/372" source="BID">372</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526192&amp;w=2" source="BUGTRAQ" adv="1">19980730 FD's 0..2 and suid/sgid procs (Was: Crash a redhat 5.1 linux box)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1407" published="1998-03-09" name="CVE-1999-1407" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">ifdhcpc-done script for configuring DHCP on Red Hat Linux 5 allows local users to append text to arbitrary files via a symlink attack on the dhcplog file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/rh50-errata-general.html#initscripts" source="CONFIRM">http://www.redhat.com/support/errata/rh50-errata-general.html#initscripts</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88950856416985&amp;w=2" source="BUGTRAQ" adv="1">19980309 *sigh* another RH5 /tmp problem</ref>
      <ref url="http://www.securityfocus.com/bid/368" source="BID">368</ref>
      <ref url="http://www.iss.net/security_center/static/7294.php" source="XF">initscripts-ifdhcpdone-dhcplog-symlink(7294)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1408" published="1997-03-05" name="CVE-1999-1408" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the socket, then using the same socket to connect to a different port on localhost.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/352" source="BID" patch="1" adv="1">352</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420641&amp;w=2" source="BUGTRAQ">19970305 Bug in connect() for aix 4.1.4 ?</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.01" />
        <vers num="10.20" />
        <vers num="9.05" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1409" published="1998-07-03" name="CVE-1999-1409" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The at program in IRIX 6.2 and NetBSD 1.3.2 and earlier allows local users to read portions of arbitrary files by submitting the file to at with the -f argument, which generates error messages that at sends to the user via e-mail.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.shmoo.com/mail/bugtraq/jul98/msg00064.html" source="BUGTRAQ" patch="1" adv="1">19980703 more about 'at'</ref>
      <ref url="http://www.securityfocus.com/bid/331" source="BID" patch="1" adv="1">331</ref>
      <ref url="http://www.iss.net/security_center/static/7577.php" source="XF">at-f-read-files(7577)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90233906612929&amp;w=2" source="BUGTRAQ">19980805 irix-6.2 "at -f" vulnerability</ref>
      <ref url="ftp://ftp.NetBSD.ORG/pub/NetBSD/security/advisories/NetBSD-SA1998-004.txt.asc" source="NETBSD">NetBSD-SA1998-004</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers prev="1" num="1.3.2" />
      </prod>
      <prod vendor="sgi" name="irix">
        <vers num="6.2" />
        <vers num="6.4" />
        <vers num="6.5" />
        <vers num="6.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1410" published="1997-05-09" name="CVE-1999-1410" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">addnetpr in IRIX 5.3 and 6.2 allows local users to overwrite arbitrary files and possibly gain root privileges via a symlink attack on the printers temporary file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/330" source="BID" patch="1" adv="1">330</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19961203-02-PX" source="MISC" patch="1" adv="1">ftp://patches.sgi.com/support/free/security/advisories/19961203-02-PX</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420927&amp;w=2" source="BUGTRAQ">19970509 Re: Irix: misc</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.1" />
        <vers num="5.1.1" />
        <vers num="5.2" />
        <vers num="5.3" />
        <vers num="6.0.1" edition="" />
        <vers num="6.0.1" edition=":xfs" />
        <vers num="6.1" />
        <vers num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1411" published="1998-11-26" name="CVE-1999-1411" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The installation of the fsp package 2.71-10 in Debian GNU/Linux 2.0 adds the anonymous FTP user without notifying the administrator, which could automatically enable anonymous FTP on some servers such as wu-ftp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/316" source="BID" patch="1" adv="1">316</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91228908407679&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19981128 Debian: Security flaw in FSP</ref>
      <ref url="http://www.iss.net/security_center/static/7574.php" source="XF">fsp-anon-ftp-access(7574)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91936850009861&amp;w=2" source="BUGTRAQ">19990217 Debian GNU/Linux 2.0r5 released (fwd)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91244712808780&amp;w=2" source="BUGTRAQ">19981130 Debian: Security flaw in FSP</ref>
      <ref url="http://lists.debian.org/debian-security-announce/debian-security-announce-1998/msg00033.html" source="DEBIAN">19981126 new version of fsp fixes security flaw</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1412" published="1999-06-03" name="CVE-1999-1412" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs, which generates a large number of processes.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/14215" source="BUGTRAQ" patch="1" adv="1">19990603 MacOS X system panic with CGI</ref>
      <ref url="http://www.securityfocus.com/bid/306" source="BID">306</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1413" published="1996-08-03" name="CVE-1999-1413" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which allows local users to overwrite or create files at higher privileges by causing a core dump, e.g. through dmesg.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/296" source="BID" patch="1" adv="1">296</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167419549&amp;w=2" source="BUGTRAQ" adv="1">19960803 Exploiting Zolaris 2.4 ??  :)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1414" published="1999-05-25" name="CVE-1999-1414" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">IBM Netfinity Remote Control allows local users to gain administrator privileges by starting programs from the process manager, which runs with system level privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92902484317769&amp;w=2" source="NTBUGTRAQ" patch="1">19990609 IBM's response to "Security Leak with IBM Netfinity Remote Control Software</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92765856706547&amp;w=2" source="NTBUGTRAQ" adv="1">19990525 Security Leak with IBM Netfinity Remote Control Software</ref>
      <ref url="http://www.securityfocus.com/bid/284" source="BID">284</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="netfinity_remote_control">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1415" published="1991-08-23" name="CVE-1999-1415" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Vulnerability in /usr/bin/mail in DEC ULTRIX before 4.2 allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-91.13.Ultrix.mail.vulnerability" source="CERT" patch="1" adv="1">CA-91.13</ref>
      <ref url="http://www.securityfocus.com/bid/27" source="BID">27</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digital" name="ultrix">
        <vers prev="1" num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1416" published="1998-08-23" name="CVE-1999-1416" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">AnswerBook2 (AB2) web server dwhttpd 3.1a4 allows remote attackers to cause a denial of service (resource exhaustion) via an HTTP POST request with a large content-length.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/253" source="BID">253</ref>
      <ref url="http://www.securityfocus.com/archive/1/10383" source="BUGTRAQ" adv="1">19980823 Solaris ab2 web server is junk</ref>
    </refs>
    <vuln_soft>
      <prod vendor="inso" name="dwhttpd">
        <vers num="3.1a4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1417" published="1998-08-23" name="CVE-1999-1417" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in AnswerBook2 (AB2) web server dwhttpd 3.1a4 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via encoded % characters in an HTTP request, which is improperly logged.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/253" source="BID">253</ref>
      <ref url="http://www.securityfocus.com/archive/1/10383" source="BUGTRAQ" adv="1">19980823 Solaris ab2 web server is junk</ref>
    </refs>
    <vuln_soft>
      <prod vendor="inso" name="answerbook2">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1418" published="1999-05-01" name="CVE-1999-1418" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ICQ99 ICQ web server build 1701 with "Active Homepage" enabled generates allows remote attackers to determine the existence of files on the server by comparing server responses when a file exists ("404 Forbidden") versus when a file does not exist ("404 not found").</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/13508" source="BUGTRAQ" patch="1" adv="1">19990501 Update: security hole in the ICQ-Webserver</ref>
      <ref url="http://www.securityfocus.com/bid/246" source="BID">246</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mirabilis" name="icq_web_front">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1419" published="1997-07-30" name="CVE-1999-1419" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in nss_nisplus.so.1 library in NIS+ in Solaris 2.3 and 2.4 allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/219" source="BID" patch="1" adv="1">219</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/148" source="SUN" patch="1" adv="1">00148</ref>
      <ref url="http://www.iss.net/security_center/static/7535.php" source="XF">sun-nisplus-bo(7535)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.3" />
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1420" published="1998-07-20" name="CVE-1999-1420" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">NBase switches NH2012, NH2012R, NH2015, and NH2048 have a back door password that cannot be disabled, which allows remote attackers to modify the switch's configuration.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/212" source="BID">212</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526065&amp;w=2" source="BUGTRAQ" adv="1">19980722 N-Base Vulnerability Advisory Followup</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526016&amp;w=2" source="BUGTRAQ" adv="1">19980720 N-Base Vulnerability Advisory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="n-base" name="nh2012">
        <vers num="2.53" />
      </prod>
      <prod vendor="n-base" name="nh2012r">
        <vers num="2.53" />
      </prod>
      <prod vendor="n-base" name="nh2015">
        <vers num="2.51" />
      </prod>
      <prod vendor="n-base" name="nh2048">
        <vers num="1.33" />
      </prod>
      <prod vendor="n-base" name="nh3012">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1421" published="1998-07-20" name="CVE-1999-1421" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">NBase switches NH208 and NH215 run a TFTP server which allows remote attackers to send software updates to modify the switch or cause a denial of service (crash) by guessing the target filenames, which have default names.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/212" source="BID">212</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526065&amp;w=2" source="BUGTRAQ" adv="1">19980722 N-Base Vulnerability Advisory Followup</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526016&amp;w=2" source="BUGTRAQ" adv="1">19980720 N-Base Vulnerability Advisory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="n-base" name="nh208">
        <vers num="" />
      </prod>
      <prod vendor="n-base" name="nh215">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1422" published="1999-01-02" name="CVE-1999-1422" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The default configuration of Slackware 3.4, and possibly other versions, includes . (dot, the current directory) in the PATH environmental variable, which could allow local users to create Trojan horse programs that are inadvertently executed by other users.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91540043023167&amp;w=2" source="BUGTRAQ">19990102 PATH variable in zip-slackware 2.0.35</ref>
    </refs>
    <vuln_soft>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="2.0.35" />
        <vers num="3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1423" published="1997-06-26" name="CVE-1999-1423" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">ping in Solaris 2.3 through 2.6 allows local users to cause a denial of service (crash) via a ping request to a multicast address through the loopback interface, e.g. via ping -i.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/209" source="BID" patch="1" adv="1">209</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/146" source="SUN" patch="1" adv="1">00146</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319180&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19971005 Solaris Ping Bug and other [bc] oddities</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319171&amp;w=2" source="BUGTRAQ" patch="1">19970627 SUMMARY: Solaris Ping bug (DoS)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319160&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19970626 Solaris Ping bug (DoS)</ref>
      <ref url="http://www.iss.net/security_center/static/7492.php" source="XF">ping-multicast-loopback-dos(7492)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319181&amp;w=2" source="BUGTRAQ">19970627 Solaris Ping bug(inetsvc)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.3" />
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":ppc" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1424" published="1997-11-10" name="CVE-1999-1424" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">Solaris Solstice AdminSuite (AdminSuite) 2.1 uses unsafe permissions when adding new users to the NIS+ password table, which allows local users to gain root access by modifying their password table entries.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/208" source="BID" patch="1" adv="1">208</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/145" source="SUN" patch="1" adv="1">00145</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solstice_adminsuite">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":x86" />
        <vers num="2.2" edition="" />
        <vers num="2.2" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1425" published="1997-11-10" name="CVE-1999-1425" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">Solaris Solstice AdminSuite (AdminSuite) 2.1 incorrectly sets write permissions on source files for NIS maps, which could allow local users to gain privileges by modifying /etc/passwd.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/208" source="BID" patch="1" adv="1">208</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/145" source="SUN" patch="1" adv="1">00145</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solstice_adminsuite">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":x86" />
        <vers num="2.2" edition="" />
        <vers num="2.2" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1426" published="1997-11-10" name="CVE-1999-1426" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">Solaris Solstice AdminSuite (AdminSuite) 2.1 follows symbolic links when updating an NIS database, which allows local users to overwrite arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/208" source="BID" patch="1" adv="1">208</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/145" source="SUN" patch="1" adv="1">00145</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solstice_adminsuite">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":x86" />
        <vers num="2.2" edition="" />
        <vers num="2.2" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1427" published="1997-11-10" name="CVE-1999-1427" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">Solaris Solstice AdminSuite (AdminSuite) 2.1 and 2.2 create lock files insecurely, which allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/208" source="BID" patch="1" adv="1">208</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/145" source="SUN" patch="1" adv="1">00145</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solstice_adminsuite">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":x86" />
        <vers num="2.2" edition="" />
        <vers num="2.2" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1428" published="1997-11-10" name="CVE-1999-1428" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">Solaris Solstice AdminSuite (AdminSuite) 2.1 and 2.2 allows local users to gain privileges via the save option in the Database Manager, which is running with setgid bin privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/208" source="BID" patch="1" adv="1">208</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/145" source="SUN" patch="1" adv="1">00145</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solstice_adminsuite">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":x86" />
        <vers num="2.2" edition="" />
        <vers num="2.2" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1429" published="1998-01-05" name="CVE-1999-1429" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">DIT TransferPro installs devices with world-readable and world-writable permissions, which could allow local users to damage disks through the ff device driver.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/204" source="BID">204</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88419633507543&amp;w=2" source="BUGTRAQ" adv="1">19980105 Security flaw in either DIT TransferPro or Solaris</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dit" name="transferpro">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1430" published="1999-01-01" name="CVE-1999-1430" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">PIM software for Royal daVinci does not properly password-protext access to data stored in the .mdb (Microsoft Access) file, which allows local users to read the data without a password by directly accessing the files with a different application, such as Access.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/185" source="BID">185</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91540043723185&amp;w=2" source="BUGTRAQ">19990102 security problem with Royal daVinci</ref>
    </refs>
    <vuln_soft>
      <prod vendor="royal" name="davinci">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1431" published="2005-01-07" name="CVE-1999-1431" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">ZAK in Appstation mode allows users to bypass the "Run only allowed apps" policy by starting Explorer from Office 97 applications (such as Word), installing software into the TEMP directory, and changing the name to that for an allowed application, such as Winword.exe.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/181" source="BID" adv="1">181</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91606260910008&amp;w=2" source="NTBUGTRAQ" adv="1">19990109 WinNT, ZAK and Office 97</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91576100022688&amp;w=2" source="NTBUGTRAQ" adv="1">19990107 WinNT, ZAK and Office 97</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="zero_administration_kit">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1432" published="1998-07-16" name="CVE-1999-1432" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Power management (Powermanagement) on Solaris 2.4 through 2.6 does not start the xlock process until after the sys-suspend has completed, which allows an attacker with physical access to input characters to the last active application from the keyboard for a short period after the system is restoring, which could lead to increased privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525997&amp;w=2" source="BUGTRAQ" adv="1">19980716 Security risk with powermanagemnet on Solaris 2.6</ref>
      <ref url="http://www.securityfocus.com/bid/160" source="BID">160</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":ppc" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1433" published="1998-07-15" name="CVE-1999-1433" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">HP JetAdmin D.01.09 on Solaris allows local users to change the permissions of arbitrary files via a symlink attack on the /tmp/jetadmin.log file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526067&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19980722 Re: JetAdmin software</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525988&amp;w=2" source="BUGTRAQ" adv="1">19980715 JetAdmin software</ref>
      <ref url="http://www.securityfocus.com/bid/157" source="BID">157</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="jetadmin">
        <vers num="rev._d.01.09" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1434" published="1998-07-13" name="CVE-1999-1434" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">login in Slackware Linux 3.2 through 3.5 does not properly check for an error when the /etc/group file is missing, which prevents it from dropping privileges, causing it to assign root privileges to any local user who logs on to the server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525951&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19980713 Slackware Shadow Insecurity</ref>
      <ref url="http://www.securityfocus.com/bid/155" source="BID">155</ref>
    </refs>
    <vuln_soft>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1435" published="1998-07-10" name="CVE-1999-1435" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in libsocks5 library of Socks 5 (socks5) 1.0r5 allows local users to gain privileges via long environmental variables.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525933&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19980710 socks5 1.0r5 buffer overflow..</ref>
      <ref url="http://www.securityfocus.com/bid/154" source="BID">154</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nec" name="socks_5">
        <vers num="1.0r5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1436" published="1998-07-08" name="CVE-1999-1436" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Ray Chan WWW Authorization Gateway 0.1 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the "user" parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525905&amp;w=2" source="BUGTRAQ" patch="1">19980708 WWW Authorization Gateway</ref>
      <ref url="http://www.securityfocus.com/bid/152" source="BID">152</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ray_chan" name="www_authorization_gateway">
        <vers num="0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1437" published="1998-07-07" name="CVE-1999-1437" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">ePerl 2.2.12 allows remote attackers to read arbitrary files and possibly execute certain commands by specifying a full pathname of the target file as an argument to bar.phtml.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525927&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19980710 ePerl Security Update Available</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525890&amp;w=2" source="BUGTRAQ" adv="1">19980707 ePerl: bad handling of ISINDEX queries</ref>
      <ref url="http://www.securityfocus.com/bid/151" source="BID">151</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ralf_s._engelschall" name="eperl">
        <vers num="2.2.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1438" published="1991-02-22" name="CVE-1999-1438" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in /bin/mail in SunOS 4.1.1 and earlier allows local users to gain root privileges via certain command line arguments.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-91.01a.SunOS.mail.vulnerability" source="CERT" patch="1" adv="1">CA-1991-01</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/105" source="SUN" patch="1" adv="1">00105</ref>
      <ref url="http://www.securityfocus.com/bid/15" source="BID">15</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="4.0.3" />
        <vers num="4.1" />
        <vers prev="1" num="4.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1439" published="1998-01-02" name="CVE-1999-1439" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">gcc 2.7.2 allows local users to overwrite arbitrary files via a symlink attack on temporary .i, .s, or .o files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/146" source="BID">146</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88524071002939&amp;w=2" source="BUGTRAQ" adv="1">19980108 GCC Exploit</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88492937727193&amp;w=2" source="BUGTRAQ" adv="1">19980115 GCC 2.7.? /tmp files</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88419592307388&amp;w=2" source="BUGTRAQ" adv="1">19980102 Symlink bug with GCC 2.7.2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gcc" name="gcc">
        <vers num="2.7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1440" published="1999-01-01" name="CVE-1999-1440" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Win32 ICQ 98a 1.30, and possibly other versions, does not display the entire portion of long filenames, which could allow attackers to send an executable file with a long name that contains so many spaces that the .exe extension is not displayed, which could make the user believe that the file is safe to open from the client.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/132" source="BID">132</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91522424302962&amp;w=2" source="BUGTRAQ">19990101 Win32 ICQ 98a flaw</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mirabilis" name="icq_98a">
        <vers prev="1" num="1.30" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1441" published="1998-06-30" name="CVE-1999-1441" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Linux 2.0.34 does not properly prevent users from sending SIGIO signals to arbitrary processes, which allows local users to cause a denial of service by sending SIGIO to processes that do not catch it.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221103126047&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19980630 Serious Linux 2.0.34 security problem</ref>
      <ref url="http://www.securityfocus.com/bid/111" source="BID">111</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.0.34" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1442" published="1998-06-22" name="CVE-1999-1442" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Bug in AMD K6 processor on Linux 2.0.x and 2.1.x kernels allows local users to cause a denial of service (crash) via a particular sequence of instructions, possibly related to accessing addresses outside of segments.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/105" source="BID">105</ref>
      <ref url="http://www.cs.helsinki.fi/linux/linux-kernel/Year-1998/1998-25/0816.html" source="MISC" adv="1">http://www.cs.helsinki.fi/linux/linux-kernel/Year-1998/1998-25/0816.html</ref>
      <ref url="http://uwsg.iu.edu/hypermail/linux/kernel/9805.3/0855.html" source="MISC" adv="1">http://uwsg.iu.edu/hypermail/linux/kernel/9805.3/0855.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers prev="1" num="2.0.39" />
        <vers prev="1" num="2.1.132" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1443" published="1998-06-02" name="CVE-1999-1443" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Micah Software Full Armor Network Configurator and Zero Administration allow local users with physical access to bypass the desktop protection by (1) using &lt;CTRL>&lt;ALT>&lt;DEL> and kill the process using the task manager, (2) booting the system from a separate disk, or (3) interrupting certain processes that execute while the system is booting.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/103" source="BID">103</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221103125889&amp;w=2" source="BUGTRAQ" adv="1">19980602 Full Armor.... Fool Proof etc... bugs</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221103125869&amp;w=2" source="BUGTRAQ" adv="1">19980609 Full Armor</ref>
    </refs>
    <vuln_soft>
      <prod vendor="micah_software" name="full_armor">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1444" published="1999-12-31" name="CVE-1999-1444" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">genkey utility in Alibaba 2.0 generates RSA key pairs with an exponent of 1, which results in transactions that are sent in cleartext.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://catless.ncl.ac.uk/Risks/20.41.html#subj4" source="MISC">http://catless.ncl.ac.uk/Risks/20.41.html#subj4</ref>
    </refs>
    <vuln_soft>
      <prod vendor="computer_software_manufaktur" name="alibaba">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1445" published="1998-02-02" name="CVE-1999-1445" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Vulnerability in imapd and ipop3d in Slackware 3.4 and 3.3 with shadowing enabled, and possibly other operating systems, allows remote attackers to cause a core dump via a short sequence of USER and PASS commands that do not provide valid usernames or passwords.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88637951600184&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19980202 imapd/ipop3d coredump in slackware 3.4</ref>
    </refs>
    <vuln_soft>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="3.3" />
        <vers num="3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1446" published="1997-08-05" name="CVE-1999-1446" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Internet Explorer 3 records a history of all URL's that are visited by a user in DAT files located in the Temporary Internet Files and History folders, which are not cleared when the user selects the "Clear History" option, and are not visible when the user browses the folders because of tailored displays.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=87602837719655&amp;w=2" source="NTBUGTRAQ" adv="1">19970806 Re: Strange behavior regarding directory</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=87602837719654&amp;w=2" source="NTBUGTRAQ" adv="1">19970805 Re: Strange behavior regarding directory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1447" published="1998-07-28" name="CVE-1999-1447" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Internet Explorer 4.0 allows remote attackers to cause a denial of service (crash) via HTML code that contains a long CLASSID parameter in an OBJECT tag.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526169&amp;w=2" source="BUGTRAQ" adv="1">19980728 Object tag crashes Internet Explorer 4.0</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526188&amp;w=2" source="BUGTRAQ">19980730 Re: Object tag crashes Internet Explorer 4.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1448" published="1998-07-29" name="CVE-1999-1448" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Eudora and Eudora Light before 3.05 allows remote attackers to cause a crash and corrupt the user's mailbox via an e-mail message with certain dates, such as (1) dates before 1970, which cause a Divide By Zero error, or (2) dates that are 100 years after the current date, which causes a segmentation fault.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526168&amp;w=2" source="BUGTRAQ" adv="1">19980729 Eudora exploit (was Microsoft Security Bulletin (MS98-008))</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qualcomm" name="eudora">
        <vers prev="1" num="3.05" />
      </prod>
      <prod vendor="qualcomm" name="eudora_light">
        <vers prev="1" num="3.05" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1449" published="1997-05-19" name="CVE-1999-1449" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">SunOS 4.1.4 on a Sparc 20 machine allows local users to cause a denial of service (kernel panic) by reading from the /dev/tcx0 TCX device.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.insecure.org/sploits/sunos.dev.tcx0.write.wierd.shit.to.device.bug.html" source="MISC" adv="1">http://www.insecure.org/sploits/sunos.dev.tcx0.write.wierd.shit.to.device.bug.html</ref>
      <ref url="http://oamk.fi/~jukkao/bugtraq/before-971202/0498.html" source="BUGTRAQ" adv="1">19970519 /dev/tcx0 crashes SunOS 4.1.4 on Sparc 20's</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="4.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1450" published="1999-01-27" name="CVE-1999-1450" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Vulnerability in (1) rlogin daemon rshd and (2) scheme on SCO UNIX OpenServer 5.0.5 and earlier, and SCO UnixWare 7.0.1 and earlier, allows remote attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="ftp://ftp.sco.COM/SSE/sse020.ltr" source="SCO">SSE020</ref>
      <ref url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.06b" source="SCO">SB-99.06b</ref>
      <ref url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.03b" source="SCO">SB-99.03b</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="openserver">
        <vers num="5.0" />
        <vers num="5.0.2" />
        <vers num="5.0.4" />
        <vers prev="1" num="5.0.5" />
      </prod>
      <prod vendor="sco" name="unixware">
        <vers prev="1" num="2.1.3" />
        <vers prev="1" num="7.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1451" published="1999-12-31" name="CVE-1999-1451" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Winmsdp.exe sample file in IIS 4.0 and Site Server 3.0 allows remote attackers to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3271.php" source="XF" patch="1" adv="1">iis-samples-winmsdp(3271)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-013.asp" source="MS" patch="1" adv="1">MS99-013</ref>
      <ref url="http://support.microsoft.com/support/kb/articles/q231/3/68.asp" source="MSKB" patch="1" adv="1">Q231368</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
      </prod>
      <prod vendor="microsoft" name="site_server">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1452" published="1999-12-31" name="CVE-1999-1452" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">GINA in Windows NT 4.0 allows attackers with physical access to display a portion of the clipboard of the user who has locked the workstation by pasting (CTRL-V) the contents into the username prompt.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/198" source="BID" patch="1" adv="1">198</ref>
      <ref url="http://support.microsoft.com/support/kb/articles/q214/8/02.asp" source="MSKB" patch="1" adv="1">Q214802</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91822011021558&amp;w=2" source="NTBUGTRAQ" patch="1" adv="1">19990205 Alert: MS releases GINA-fix for SP3, SP4, and TS</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91788829326419&amp;w=2" source="BUGTRAQ" adv="1">19990129 ole objects in a "secured" environment?</ref>
      <ref url="http://xforce.iss.net/static/1975.php" source="XF">nt-gina-clipboard(1975)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91764169410814&amp;w=2" source="NTBUGTRAQ">19990129 ole objects in a "secured" environment?</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1453" published="1999-02-02" name="CVE-1999-1453" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the Internet WebBrowser ActiveX object.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/215" source="BID">215</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91979439932341&amp;w=2" source="NTBUGTRAQ">19990222 New IE4 vulnerability : the clipboard again.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1454" published="1999-10-04" name="CVE-1999-1454" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Macromedia "The Matrix" screen saver on Windows 95 with the "Password protected" option enabled allows attackers with physical access to the machine to bypass the password prompt by pressing the ESC (Escape) key.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93915027622690&amp;w=2" source="BUGTRAQ" adv="1">19991004 Weakness In "The Matrix" Screensaver For Windows</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macromedia" name="matrix_screen_saver">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1455" published="1999-12-31" name="CVE-1999-1455" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">RSH service utility RSHSVC in Windows NT 3.5 through 4.0 does not properly restrict access as specified in the .Rhosts file when a user comes from an authorized host, which could allow unauthorized users to access the service by logging in from an authorized host.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/support/kb/articles/q158/3/20.asp" source="MSKB" adv="1">Q158320</ref>
      <ref url="http://xforce.iss.net/static/7422.php" source="XF">nt-rshsvc-ale-bypass(7422)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers prev="1" num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1456" published="1999-12-31" name="CVE-1999-1456" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">thttpd HTTP server 2.03 and earlier allows remote attackers to read arbitrary files via a GET request with more than one leading / (slash) character in the filename.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1809.php" source="XF" patch="1" adv="1">thttpd-file-read(1809)</ref>
      <ref url="http://www.securityfocus.com/archive/1/10368" source="BUGTRAQ" adv="1">19980819 thttpd 2.04 released (fwd)</ref>
      <ref url="http://www.acme.com/software/thttpd/thttpd.html#releasenotes" source="CONFIRM">http://www.acme.com/software/thttpd/thttpd.html#releasenotes</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thttpd" name="thttpd_http_server">
        <vers prev="1" num="2.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1457" published="1999-11-16" name="CVE-1999-1457" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in thttpd HTTP server before 2.04-31 allows remote attackers to execute arbitrary commands via a long date string, which is not properly handled by the tdate_parse function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.novell.com/linux/security/advisories/suse_security_announce_30.html" source="SUSE">19991116 thttpd</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thttpd" name="thttpd_http_server">
        <vers num="1.90a" />
        <vers prev="1" num="2.04" />
        <vers prev="1" num="2.04.31" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1458" published="1999-01-25" name="CVE-1999-1458" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in at program in Digital UNIX 4.0 allows local users to gain root privileges via a long command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3138.php" source="XF" patch="1" adv="1">du-at(3138)</ref>
      <ref url="http://www.securityfocus.com/archive/1/12121" source="BUGTRAQ" patch="1" adv="1">19990125 Digital Unix 4.0 exploitable buffer overflows</ref>
      <ref url="http://ftp1.support.compaq.com/public/dunix/v4.0d/ssrt0583u.README" source="SCO" patch="1" adv="1">SSRT0583U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digital" name="unix">
        <vers num="4.0" />
        <vers num="4.0a" />
        <vers num="4.0b" />
        <vers num="4.0c" />
        <vers num="4.0d" />
        <vers num="4.0e" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1459" published="1998-11-02" name="CVE-1999-1459" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">BMC PATROL Agent before 3.2.07 allows local users to gain root privileges via a symlink attack on a temporary file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1388.php" source="XF" patch="1" adv="1">bmc-patrol-file-create(1388)</ref>
      <ref url="http://xforce.iss.net/alerts/advise10.php" source="ISS" patch="1" adv="1">19981102 BMC PATROL File Creation Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/534" source="BID" adv="1">534</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bmc" name="patrol_agent">
        <vers num="3.2" />
        <vers num="3.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1460" published="1999-07-13" name="CVE-1999-1460" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">BMC PATROL SNMP Agent before 3.2.07 allows local users to create arbitrary world-writeable files as root by specifying the target file as the second argument to the snmpmagt program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/525" source="BID" patch="1" adv="1">525</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93198293132463&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19990713 Root Perms Gained with Patrol SNMP Agent 3.2 (all others?)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93372579004129&amp;w=2" source="BUGTRAQ" adv="1">19990801 Re: Root Perms Gained with Patrol SNMP Agent 3.2 (all others?)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bmc" name="patrol_agent">
        <vers num="3.2" />
        <vers num="3.2.3" />
        <vers num="3.2.5" />
        <vers prev="1" num="3.2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1461" published="1997-05-07" name="CVE-1999-1461" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">inpview in InPerson on IRIX 5.3 through IRIX 6.5.10 trusts the PATH environmental variable to find and execute the ttsession program, which allows local users to obtain root access by modifying the PATH to point to a Trojan horse ttsession program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/381" source="BID" patch="1" adv="1">381</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20001101-01-I" source="SGI" patch="1" adv="1">20001101-01-I</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420921&amp;w=2" source="BUGTRAQ">19970507 Irix: misc</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="5.3" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
        <vers num="6.5.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1462" published="1999-12-31" name="CVE-1999-1462" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Vulnerability in bb-hist.sh CGI History module in Big Brother 1.09b and 1.09c allows remote attacker to read portions of arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3755.php" source="XF" patch="1" adv="1">http-cgi-bigbrother-bbhist(3755)</ref>
      <ref url="http://www.securityfocus.com/bid/142" source="BID" patch="1" adv="1">142</ref>
      <ref url="http://www.securityfocus.com/archive/1/13440" source="BUGTRAQ" adv="1">19990426 FW: Security Notice: Big Brother 1.09b/c</ref>
      <ref url="http://bb4.com/README.CHANGES" source="CONFIRM">http://bb4.com/README.CHANGES</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sean_macguire" name="big_brother">
        <vers num="1.09b" />
        <vers num="1.09c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1463" published="1997-07-10" name="CVE-1999-1463" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Windows NT 4.0 before SP3 allows remote attackers to bypass firewall restrictions or cause a denial of service (crash) by sending improperly fragmented IP packets without the first fragment, which the TCP/IP stack incorrectly reassembles into a valid session.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/528.php" source="XF" patch="1" adv="1">nt-frag(528)</ref>
      <ref url="http://www.securityfocus.com/archive/1/7219" source="BUGTRAQ" patch="1" adv="1">19970710 A New Fragmentation Attack</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers prev="1" num="4.0" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1464" published="1999-12-31" name="CVE-1999-1464" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Vulnerability in Cisco IOS 11.1CC and 11.1CT with distributed fast switching (DFS) enabled allows remote attackers to bypass certain access control lists when the router switches traffic from a DFS-enabled interface to an interface that does not have DFS enabled, as described by Cisco bug CSCdk35564.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1401.php" source="XF" patch="1" adv="1">cisco-acl-leakage(1401)</ref>
      <ref url="http://www.cisco.com/warp/public/770/iosdfsacl-pub.shtml" source="CISCO" patch="1" adv="1">19981105 Cisco IOS DFS Access List Leakage</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/j-016.shtml" source="CIAC" patch="1" adv="1">J-016</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="11.1cc" />
        <vers num="11.1ct" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1465" published="1999-12-31" name="CVE-1999-1465" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Vulnerability in Cisco IOS 11.1 through 11.3 with distributed fast switching (DFS) enabled allows remote attackers to bypass certain access control lists when the router switches traffic from a DFS-enabled input interface to an output interface with a logical subinterface, as described by Cisco bug CSCdk43862.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1401.php" source="XF" patch="1" adv="1">cisco-acl-leakage(1401)</ref>
      <ref url="http://www.cisco.com/warp/public/770/iosdfsacl-pub.shtml" source="CISCO" patch="1" adv="1">19981105 Cisco IOS DFS Access List Leakage</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/j-016.shtml" source="CIAC" patch="1" adv="1">J-016</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers prev="1" num="11.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1466" published="1992-12-10" name="CVE-1999-1466" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Vulnerability in Cisco routers versions 8.2 through 9.1 allows remote attackers to bypass access control lists when extended IP access lists are used on certain interfaces, the IP route cache is enabled, and the access list uses the "established" keyword.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1992-20.html" source="CERT" patch="1" adv="1">CA-1992-20</ref>
      <ref url="http://www.securityfocus.com/bid/53" source="BID" patch="1" adv="1">53</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="8.2" />
        <vers num="8.3" />
        <vers num="9.0" />
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1467" published="1989-10-26" name="CVE-1999-1467" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Vulnerability in rcp on SunOS 4.0.x allows remote attackers from trusted hosts to execute arbitrary commands as root, possibly related to the configuration of the nobody user.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1989-07.html" source="CERT" patch="1" adv="1">CA-1989-07</ref>
      <ref url="http://xforce.iss.net/static/3165.php" source="XF" patch="1" adv="1">sun-rcp(3165)</ref>
      <ref url="http://www.securityfocus.com/bid/5" source="BID" patch="1" adv="1">5</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.3c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1468" published="1991-10-22" name="CVE-1999-1468" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">rdist in various UNIX systems uses popen to execute sendmail, which allows local users to gain root privileges by modifying the IFS (Internal Field Separator) variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-91.20.rdist.vulnerability" source="CERT" patch="1" adv="1">CA-91.20</ref>
      <ref url="http://www.securityfocus.com/bid/31" source="BID" patch="1" adv="1">31</ref>
      <ref url="http://www.alw.nih.gov/Security/8lgm/8lgm-Advisory-01.html" source="MISC">http://www.alw.nih.gov/Security/8lgm/8lgm-Advisory-01.html</ref>
      <ref url="http://www.osvdb.org/8106" source="OSVDB">8106</ref>
      <ref url="http://www.iss.net/security_center/static/7160.php" source="XF">rdist-popen-gain-privileges(7160)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="next" name="next">
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
      <prod vendor="cray" name="unicos">
        <vers num="6.0" />
        <vers num="6.0e" />
        <vers num="6.1" />
      </prod>
      <prod vendor="sgi" name="irix">
        <vers num="3.3" />
        <vers num="3.3.1" />
        <vers num="3.3.2" />
        <vers num="3.3.3" />
        <vers num="4.0" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="4.0.3" />
        <vers num="4.0.3c" />
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1psr_a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1469" published="1999-09-30" name="CVE-1999-1469" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in w3-auth CGI program in miniSQL package allows remote attackers to execute arbitrary commands via an HTTP request with (1) a long URL, or (2) a long User-Agent MIME header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93871926821410&amp;w=2" source="BUGTRAQ" adv="1">19990930 mini-sql Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hughes_technologies" name="w3-auth">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1470" published="1999-06-24" name="CVE-1999-1470" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Eastman Work Management 3.21 stores passwords in cleartext in the COMMON and LOCATOR registry keys, which could allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2303.php" source="XF" patch="1" adv="1">eastman-cleartext-passwords(2303)</ref>
      <ref url="http://www.securityfocus.com/bid/485" source="BID" adv="1">485</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93034788412494&amp;w=2" source="NTBUGTRAQ" adv="1">19990624 Eastman Software Work Management 3.21</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eastman_software" name="work_management">
        <vers num="3.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1471" published="1989-01-01" name="CVE-1999-1471" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in passwd in BSD based operating systems 4.3 and earlier allows local users to gain root privileges by specifying a long shell or GECOS field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1989-01.html" source="CERT" patch="1" adv="1">CA-1989-01</ref>
      <ref url="http://www.securityfocus.com/bid/4" source="BID" patch="1" adv="1">4</ref>
      <ref url="http://www.iss.net/security_center/static/7152.php" source="XF">bsd-passwd-bo(7152)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bsd" name="bsd">
        <vers num="4.2" />
        <vers num="4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1472" published="1999-12-31" name="CVE-1999-1472" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Internet Explorer 4.0 allows remote attackers to read arbitrary text and HTML files on the user's machine via a small IFRAME that uses Dynamic HTML (DHTML) to send the data to the attacker, aka the Freiburg text-viewing issue.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/587.php" source="XF" patch="1" adv="1">http-ie-spy(587)</ref>
      <ref url="http://www.insecure.org/sploits/Internet_explorer_4.0.hack.html" source="MISC" patch="1" adv="1">http://www.insecure.org/sploits/Internet_explorer_4.0.hack.html</ref>
      <ref url="http://support.microsoft.com/support/kb/articles/q176/7/94.asp" source="MSKB" patch="1" adv="1">Q176794</ref>
      <ref url="http://support.microsoft.com/support/kb/articles/q176/6/97.asp" source="MSKB" patch="1" adv="1">Q176697</ref>
      <ref url="http://www.microsoft.com/Windows/ie/security/freiburg.asp" source="CONFIRM">http://www.microsoft.com/Windows/ie/security/freiburg.asp</ref>
      <ref url="http://www.osvdb.org/7819" source="OSVDB">7819</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87710897923098&amp;w=2" source="BUGTRAQ">19971017 Security Hole in Explorer 4.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1473" published="1999-12-31" name="CVE-1999-1473" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">When a Web site redirects the browser to another site, Internet Explorer 3.02 and 4.0 automatically resends authentication information to the second site, aka the "Page Redirect Issue."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/support/kb/articles/q176/6/97.asp" source="MSKB" patch="1" adv="1">Q176697</ref>
      <ref url="http://www.osvdb.org/7818" source="OSVDB">7818</ref>
      <ref url="http://www.iss.net/security_center/static/7426.php" source="XF">ie-page-redirect(7426)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="3.0.2" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1474" published="1999-12-31" name="CVE-1999-1474" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PowerPoint 95 and 97 allows remote attackers to cause an application to be run automatically without prompting the user, possibly through the slide show, when the document is opened in browsers such as Internet Explorer.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/179.php" source="XF" patch="1" adv="1">nt-ppt-patch(179)</ref>
      <ref url="http://www.microsoft.com/windows/ie/security/powerpoint.asp" source="CONFIRM">http://www.microsoft.com/windows/ie/security/powerpoint.asp</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="powerpoint">
        <vers num="95" />
        <vers num="97" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1475" published="1999-11-19" name="CVE-1999-1475" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">ProFTPd 1.2 compiled with the mod_sqlpw module records user passwords in the wtmp log file, which allows local users to obtain the passwords and gain privileges by reading wtmp, e.g. via the last command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/812" source="BID" patch="1" adv="1">812</ref>
      <ref url="http://www.securityfocus.com/archive/1/35483" source="BUGTRAQ" patch="1" adv="1">19991119 ProFTPd - mod_sqlpw.c</ref>
    </refs>
    <vuln_soft>
      <prod vendor="proftpd_project" name="proftpd">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1476" published="1999-12-31" name="CVE-1999-1476" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">A bug in Intel Pentium processor (MMX and Overdrive) allows local users to cause a denial of service (hang) in Intel-based operating systems such as Windows NT and Windows 95, via an invalid instruction, aka the "Invalid Operand with Locked CMPXCHG8B Instruction" problem.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/704.php" source="XF" patch="1" adv="1">pentium-crash(704)</ref>
      <ref url="http://support.microsoft.com/support/kb/articles/q163/8/52.asp" source="MSKB" patch="1" adv="1">Q163852</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intel" name="pentium">
        <vers num="" edition=":mmx" />
      </prod>
      <prod vendor="intel" name="pentuim">
        <vers num="" edition=":overdrive" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1477" published="1999-09-23" name="CVE-1999-1477" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in GNOME libraries 1.0.8 allows local user to gain root access via a long --espeaker argument in programs such as nethack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3349.php" source="XF" patch="1" adv="1">gnome-espeaker-local-bo(3349)</ref>
      <ref url="http://www.securityfocus.com/bid/663" source="BID" patch="1" adv="1">663</ref>
      <ref url="http://www.securityfocus.com/archive/1/28717" source="BUGTRAQ" adv="1">19990923 Linux GNOME exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="gnome_libs">
        <vers num="1.0.8" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1478" published="1999-07-06" name="CVE-1999-1478" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Sun HotSpot Performance Engine VM allows a remote attacker to cause a denial of service on any server running HotSpot via a URL that includes the [ character.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2348.php" source="XF" patch="1" adv="1">sun-hotspot-vm(2348)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93240220324183&amp;w=2" source="NTBUGTRAQ" adv="1">19990716 FW: (Review ID: 85125) Hotspot crashes bringing down webserver</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93138827429589&amp;w=2" source="NTBUGTRAQ" adv="1">19990706 Bug in SUN's Hotspot VM</ref>
      <ref url="http://www.securityfocus.com/bid/522" source="BID">522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="3.0" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1479" published="1998-06-24" name="CVE-1999-1479" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The textcounter.pl by Matt Wright allows remote attackers to execute arbitrary commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2052.php" source="XF" adv="1">http-cgi-textcounter(2052)</ref>
      <ref url="http://www.securityfocus.com/archive/1/9609" source="BUGTRAQ">19980624 textcounter.pl SECURITY HOLE      </ref>
      <ref url="http://www.securityfocus.com/bid/2265" source="BID">2265</ref>
    </refs>
    <vuln_soft>
      <prod vendor="matt_wright" name="textcounter">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1480" published="1998-06-11" name="CVE-1999-1480" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">(1) acledit and (2) aclput in AIX 4.3 allow local users to create or modify files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/429" source="BID" patch="1" adv="1">429</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1481" published="1999-12-31" name="CVE-1999-1481" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Squid 2.2.STABLE5 and below, when using external authentication, allows attackers to bypass access controls via a newline in the user/password pair.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3433.php" source="XF" patch="1" adv="1">squid-proxy-auth-access(3433)</ref>
      <ref url="http://www.squid-cache.org/Versions/v2/2.2/bugs/" source="CONFIRM" patch="1" adv="1">http://www.squid-cache.org/Versions/v2/2.2/bugs/</ref>
      <ref url="http://www.securityfocus.com/bid/741" source="BID" patch="1" adv="1">741</ref>
      <ref url="http://www.securityfocus.com/archive/1/33295" source="BUGTRAQ">19991025 [squid] exploit for external authentication problem</ref>
      <ref url="http://www.securityfocus.com/archive/1/33295" source="BUGTRAQ">19991025 [squid] exploit for external authentication problem</ref>
    </refs>
    <vuln_soft>
      <prod vendor="national_science_foundation" name="squid_web_proxy">
        <vers num="1.0" />
        <vers num="1.0novm" />
        <vers num="1.1" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1482" published="1999-02-19" name="CVE-1999-1482" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">SVGAlib zgv 3.0-7 and earlier allows local users to gain root access via a privilege leak of the iopl(3) privileges to child processes.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-02-15&amp;msg=Pine.LNX.3.96.990219175605.9622A-100000@ferret.lmh.ox.ac.uk" source="BUGTRAQ" patch="1">19990219 Security hole: "zgv"</ref>
    </refs>
    <vuln_soft>
      <prod vendor="svgalib" name="zgv">
        <vers prev="1" num="3.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1483" published="1997-06-19" name="CVE-1999-1483" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in zgv in svgalib 1.2.10 and earlier allows local users to execute arbitrary code via a long HOME environment variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/7041" source="BUGTRAQ" adv="1">19970619 svgalib/zgv</ref>
    </refs>
    <vuln_soft>
      <prod vendor="svgalib" name="svgalib">
        <vers prev="1" num="1.2.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1484" published="1999-09-24" name="CVE-1999-1484" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in MSN Setup BBS 4.71.0.10 ActiveX control (setupbbs.ocx) allows a remote attacker to execute arbitrary commands via the methods (1) vAddNewsServer or (2) bIsNewsServerConfigured.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3310.php" source="XF" patch="1" adv="1">msn-setup-bbs-activex-bo(3310)</ref>
      <ref url="http://www.securityfocus.com/bid/668" source="BID" patch="1" adv="1">668</ref>
      <ref url="http://www.securityfocus.com/archive/1/28719" source="BUGTRAQ" patch="1" adv="1">19990924 Several ActiveX Buffer Overruns</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="msn_setup_bulletin_board_services">
        <vers num="4.71.0.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1485" published="1999-05-31" name="CVE-1999-1485" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">nsd in IRIX 6.5 through 6.5.2 exports a virtual filesystem on a UDP port, which allows remote attackers to view files and cause a possible denial of service by mounting the nsd virtual file system.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2247.php" source="XF" patch="1" adv="1">sgi-nsd-create(2247)</ref>
      <ref url="http://xforce.iss.net/static/2246.php" source="XF" patch="1" adv="1">sgi-nsd-view(2246)</ref>
      <ref url="http://www.securityfocus.com/bid/412" source="BID">412</ref>
      <ref url="http://www.osvdb.org/8564" source="OSVDB">8564</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92818552106912&amp;w=2" source="BUGTRAQ">19990531 IRIX 6.5 nsd virtual filesystem vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1486" published="1998-02-25" name="CVE-1999-1486" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">sadc in IBM AIX 4.1 through 4.3, when called from programs such as timex that are setgid adm, allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/408" source="BID" patch="1" adv="1">408</ref>
      <ref url="http://techsupport.services.ibm.com/aix/fixes/v4/os/bos.acct.4.3.1.0.info" source="CONFIRM">http://techsupport.services.ibm.com/aix/fixes/v4/os/bos.acct.4.3.1.0.info</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/7675" source="XF">aix-sadc-timex(7675)</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IX76853&amp;apar=only" source="AIXAPAR">IX76853</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IX76330&amp;apar=only" source="AIXAPAR">IX76330</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IX75554&amp;apar=only" source="AIXAPAR">IX75554</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
        <vers num="4.2" />
        <vers num="4.2.1" />
        <vers num="4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1487" published="1998-01-21" name="CVE-1999-1487" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in digest in AIX 4.3 allows printq users to gain root privileges by creating and/or modifing any file on the system.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/405" source="BID" patch="1" adv="1">405</ref>
      <ref url="http://www.iss.net/security_center/static/7477.php" source="XF">aix-digest(7477)</ref>
      <ref url="http://www-1.ibm.com/servlet/support/manager?rt=0&amp;rs=0&amp;org=apars&amp;doc=41D8B61D1E1C4FAB852567C9002C546C" source="AIXAPAR" adv="1">IX74599</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
        <vers num="4.2" />
        <vers num="4.2.1" />
        <vers num="4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1488" published="1999-12-31" name="CVE-1999-1488" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">sdrd daemon in IBM SP2 System Data Repository (SDR) allows remote attackers to read files without authentication.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/371" source="BID" patch="1" adv="1">371</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/i-079a.shtml" source="CIAC" patch="1" adv="1">I-079A</ref>
      <ref url="http://www.iss.net/security_center/static/7217.php" source="XF">ibm-sdr-read-files(7217)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="system_data_repository">
        <vers num="sp_2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1489" published="1997-03-04" name="CVE-1999-1489" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in TestChip function in XFree86 SuperProbe in Slackware Linux 3.1 allows local users to gain root privileges via a long -nopr argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/364" source="BID" patch="1" adv="1">364</ref>
      <ref url="http://www.securityfocus.com/archive/1/6384" source="BUGTRAQ" adv="1">19970304 Linux SuperProbe exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1490" published="1998-05-28" name="CVE-1999-1490" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">xosview 1.5.1 in Red Hat 5.1 allows local users to gain root access via a long HOME environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/362" source="BID" patch="1" adv="1">362</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101926021&amp;w=2" source="BUGTRAQ" adv="1">19980528 ALERT: Tiresome security hole in "xosview", RedHat5.1?</ref>
      <ref url="http://www.iss.net/security_center/static/8787.php" source="XF">linux-xosview-bo(8787)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101926034&amp;w=2" source="BUGTRAQ">19980529 Re: Tiresome security hole in "xosview" (xosexp.c)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1491" published="1996-02-02" name="CVE-1999-1491" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">abuse.console in Red Hat 2.1 uses relative pathnames to find and execute the undrv program, which allows local users to execute arbitrary commands via a path that points to a Trojan horse program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/354" source="BID" patch="1" adv="1">354</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167418994&amp;w=2" source="BUGTRAQ" adv="1">19960202 abuse Red Hat 2.1 security hole</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1492" published="1998-05-27" name="CVE-1999-1492" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in (1) diskperf and (2) diskalign in IRIX 6.4 allows local attacker to create arbitrary root owned files, leading to root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2104.php" source="XF" patch="1" adv="1">sgi-diskalign(2104)</ref>
      <ref url="http://xforce.iss.net/static/2103.php" source="XF" patch="1" adv="1">sgi-diskperf(2103)</ref>
      <ref url="http://www.securityfocus.com/bid/348" source="BID" patch="1" adv="1">348</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19980502-01-P3030" source="SGI" patch="1" adv="1">19980502-01-P3030</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1493" published="1991-12-18" name="CVE-1999-1493" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Vulnerability in crp in Hewlett Packard Apollo Domain OS SR10 through SR10.3 allows remote attackers to gain root privileges via insecure system calls, (1) pad_$dm_cmd and (2) pad_$def_pfk().</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1991-23.html" source="CERT" patch="1" adv="1">CA-1991-23</ref>
      <ref url="http://xforce.iss.net/static/7158.php" source="XF">apollo-crp-root-access(7158)</ref>
      <ref url="http://www.securityfocus.com/bid/34" source="BID">34</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="apollo_domain_os">
        <vers prev="1" num="sr10.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1494" published="1994-08-09" name="CVE-1999-1494" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">colorview in Silicon Graphics IRIX 5.1, 5.2, and 6.0 allows local attackers to read arbitrary files via the -text argument.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2112.php" source="XF" patch="1" adv="1">sgi-colorview(2112)</ref>
      <ref url="http://www.tryc.on.ca/archives/bugtraq/1995_1/0614.html" source="BUGTRAQ" patch="1" adv="1">19950307 sigh. another Irix 5.2 hole.</ref>
      <ref url="http://www.securityfocus.com/bid/336" source="BID" patch="1" adv="1">336</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/19950209-01-P" source="SGI" patch="1" adv="1">19950209-00-P</ref>
      <ref url="http://www.securityfocus.com/archive/1/675" source="BUGTRAQ" adv="1">19940809 Re: IRIX 5.2 Security Advisory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="5.1" />
        <vers num="5.1.1" />
        <vers num="5.2" />
        <vers num="6.0" />
        <vers num="6.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1495" published="1999-02-18" name="CVE-1999-1495" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">xtvscreen in SuSE Linux 6.0 allows local users to overwrite arbitrary files via a symlink attack on the pic000.pnm file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1792.php" source="XF">xtvscreen-overwrite(1792)</ref>
      <ref url="http://www.securityfocus.com/bid/325" source="BID" adv="1">325</ref>
      <ref url="http://www.securityfocus.com/archive/1/12580" source="BUGTRAQ">19990218 xtvscreen and suse 6 </ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="suse_linux">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1496" published="1999-06-08" name="CVE-1999-1496" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Sudo 1.5 in Debian Linux 2.1 and Red Hat 6.0 allows local users to determine the existence of arbitrary files by attempting to execute the target filename as a program, which generates a different error message when the file does not exist.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2277.php" source="XF" patch="1" adv="1">sudo-file-exists(2277)</ref>
      <ref url="http://www.securityfocus.com/bid/321" source="BID" adv="1">321</ref>
      <ref url="http://www.securityfocus.com/archive/1/14665" source="BUGTRAQ" adv="1">19990608 unneeded information in sudo</ref>
    </refs>
    <vuln_soft>
      <prod vendor="todd_miller" name="sudo">
        <vers num="1.5" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.1" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1497" published="1999-12-21" name="CVE-1999-1497" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Ipswitch IMail 5.0 and 6.0 uses weak encryption to store passwords in registry keys, which allows local attackers to read passwords for e-mail accounts.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/880" source="BID" adv="1">880</ref>
      <ref url="http://www.securityfocus.com/archive/1/39329" source="BUGTRAQ" adv="1">19991221 [w00giving '99 #11] IMail's password encryption scheme</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="imail">
        <vers num="5.0" />
        <vers num="5.0.5" />
        <vers num="5.0.6" />
        <vers num="5.0.7" />
        <vers num="5.0.8" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1498" published="1998-04-06" name="CVE-1999-1498" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Slackware Linux 3.4 pkgtool allows local attacker to read and write to arbitrary files via a symlink attack on the reply file.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/82" source="BID" adv="1">82</ref>
    </refs>
    <vuln_soft>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1499" published="1998-04-10" name="CVE-1999-1499" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">named in ISC BIND 4.9 and 8.1 allows local users to destroy files via a symlink attack on (1) named_dump.db when root kills the process with a SIGINT, or (2) named.stats when SIGIOT is used.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/80" source="BID" patch="1" adv="1">80</ref>
      <ref url="http://www.securityfocus.com/archive/1/8966" source="BUGTRAQ" adv="1">19980410 BIND 4.9.7 named follows symlinks, clobbers anything</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="bind">
        <vers num="4.9" />
        <vers num="8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1500" published="1999-10-01" name="CVE-1999-1500" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Internet Anywhere POP3 Mail Server 2.3.1 allows remote attackers to cause a denial of service (crash) via (1) LIST, (2) TOP, or (3) UIDL commands using letters as arguments.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/733" source="BID" patch="1" adv="1">733</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93880357530599&amp;w=2" source="NTBUGTRAQ" adv="1">19991001 Vulnerabilities in the Internet Anywhere Mail Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="true_north" name="internet_anywhere_mail_server">
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1501" published="1998-04-08" name="CVE-1999-1501" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">(1) ipxchk and (2) ipxlink in SGI OS2 IRIX 6.3 does not properly clear the IFS environmental variable before executing system calls, which allows local users to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/71" source="BID" patch="1" adv="1">71</ref>
      <ref url="http://www.securityfocus.com/bid/70" source="BID" patch="1" adv="1">70</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=89217373930054&amp;w=2" source="BUGTRAQ">19980408 SGI O2 ipx security issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1502" published="1998-04-08" name="CVE-1999-1502" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflows in Quake 1.9 client allows remote malicious servers to execute arbitrary commands via long (1) precache paths, (2) server name, (3) server address, or (4) argument to the map console command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/69" source="BID" adv="1">69</ref>
      <ref url="http://www.securityfocus.com/bid/68" source="BID" adv="1">68</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=89205623028934&amp;w=2" source="BUGTRAQ" adv="1">19980408 QuakeI client: serious holes.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="id_software" name="quake">
        <vers num="1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1503" published="1998-04-08" name="CVE-1999-1503" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Network Flight Recorder (NFR) 1.5 and 1.6 allows remote attackers to cause a denial of service in nfrd (crash) via a TCP packet with a null header and data field.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/63" source="BID" patch="1" adv="1">63</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nfr" name="nfr">
        <vers num="1.5" />
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1504" published="1998-04-08" name="CVE-1999-1504" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Stalker Internet Mail Server 1.6 allows a remote attacker to cause a denial of service (crash) via a long HELO command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/62" source="BID" adv="1">62</ref>
      <ref url="http://www.securityfocus.com/archive/1/8951" source="BUGTRAQ" adv="1">19980408 Re: AppleShare IP Mail Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stalker" name="stalker_internet_mail_server">
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1505" published="1998-04-07" name="CVE-1999-1505" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in QuakeWorld 2.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary commands via a long initial connect packet.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/60" source="BID" adv="1">60</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=89200537415923&amp;w=2" source="BUGTRAQ" adv="1">19980407 QW vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="id_software" name="quakeworld">
        <vers num="2.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1506" published="1990-01-29" name="CVE-1999-1506" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Vulnerability in SMI Sendmail 4.0 and earlier, on SunOS up to 4.0.3, allows remote attackers to access user bin.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-90.01.sun.sendmail.vulnerability" source="CERT" adv="1">CA-1990-01</ref>
      <ref url="http://www.securityfocus.com/bid/6" source="BID" patch="1" adv="1">6</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="3.5" />
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.3c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1507" published="1993-02-03" name="CVE-1999-1507" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Sun SunOS 4.1 through 4.1.3 allows local attackers to gain root access via insecure permissions on files and directories such as crash.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1993-03.html" source="CERT" patch="1" adv="1">CA-1993-03</ref>
      <ref url="http://www.securityfocus.com/bid/59" source="BID" patch="1" adv="1">59</ref>
      <ref url="http://xforce.iss.net/static/521.php" source="XF">sun-dir(521)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.3c" />
        <vers num="4.1.3u1" />
        <vers num="4.1psr_a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1508" published="1999-11-16" name="CVE-1999-1508" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Web server in Tektronix PhaserLink Printer 840.0 and earlier allows a remote attacker to gain administrator access by directly calling undocumented URLs such as ncl_items.html and ncl_subjects.html.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/806" source="BID" patch="1" adv="1">806</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94286041430870&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19991116 [Fwd: Printer Vulnerability: Tektronix PhaserLink Webserver gives Administrator Password]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tek" name="phaser_network_printer_740">
        <vers num="" />
      </prod>
      <prod vendor="tek" name="phaser_network_printer_750">
        <vers num="" />
      </prod>
      <prod vendor="tek" name="phaser_network_printer_750dp">
        <vers num="" />
      </prod>
      <prod vendor="tek" name="phaser_network_printer_840">
        <vers num="" />
      </prod>
      <prod vendor="tek" name="phaser_network_printer_930">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1509" published="1999-11-04" name="CVE-1999-1509" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Etype Eserv 2.50 web server allows a remote attacker to read any file in the file system via a .. (dot dot) in a URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/773" source="BID" patch="1" adv="1">773</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94183041514522&amp;w=2" source="BUGTRAQ" adv="1">19991104 Eserv 2.50 Web interface Server Directory Traversal Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94177470915423&amp;w=2" source="NTBUGTRAQ">19991104 Eserv 2.50 Web interface Server Directory Traversal Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="etype" name="eserv">
        <vers num="2.50" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1510" published="1999-05-17" name="CVE-1999-1510" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflows in Bisonware FTP server prior to 4.1 allow remote attackers to cause a denial of service, and possibly execute arbitrary commands, via long (1) USER, (2) LIST, or (3) CWD commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3234.php" source="XF" patch="1" adv="1">bisonware-command-bo(3234)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92697301706956&amp;w=2" source="NTBUGTRAQ" patch="1" adv="1">19990517 Vulnerabilities in BisonWare FTP Server 3.5</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bisonware" name="bisonware_ftp_server">
        <vers prev="1" num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1511" published="1999-11-10" name="CVE-1999-1511" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflows in Xtramail 1.11 allow attackers to cause a denial of service (crash) and possibly execute arbitrary commands via (1) a long PASS command in the POP3 service, (2) a long HELO command in the SMTP service, or (3) a long user name in the Control Service.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3488.php" source="XF" adv="1">xtramail-pass-dos(3488)</ref>
      <ref url="http://www.securityfocus.com/bid/791" source="BID" adv="1">791</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94226003804744&amp;w=2" source="BUGTRAQ" adv="1">19991110 Multiples Remotes DoS Attacks in Artisoft XtraMail v1.11 Vulnerability </ref>
    </refs>
    <vuln_soft>
      <prod vendor="artisoft" name="xtramail">
        <vers num="1.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1512" published="1999-12-31" name="CVE-1999-1512" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The AMaViS virus scanner 0.2.0-pre4 and earlier allows remote attackers to execute arbitrary commands as root via an infected mail message with shell metacharacters in the reply-to field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2349.php" source="XF" patch="1" adv="1">amavis-command-execute(2349)</ref>
      <ref url="http://www.securityfocus.com/bid/527" source="BID" patch="1" adv="1">527</ref>
      <ref url="http://www.amavis.org/ChangeLog.txt" source="CONFIRM" adv="1">http://www.amavis.org/ChangeLog.txt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93219846414732&amp;w=2" source="BUGTRAQ" adv="1">19990716 AMaViS virus scanner for Linux - root exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="amavis" name="virus_scanner">
        <vers prev="1" num="0.2_pre4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1513" published="1999-08-30" name="CVE-1999-1513" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Management information base (MIB) for a 3Com SuperStack II hub running software version 2.10 contains an object identifier (.1.3.6.1.4.1.43.10.4.2) that is accessible by a read-only community string, but lists the entire table of community strings, which could allow attackers to conduct unauthorized activities.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93616983223090&amp;w=2" source="BUGTRAQ" adv="1">19990830 One more 3Com SNMP vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="3com" name="superstack_ii_hub">
        <vers num="2.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1514" published="2001-11-28" name="CVE-1999-1514" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Celtech ExpressFS FTP server 2.x allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long USER command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3401.php" source="XF" adv="1">expressfs-command-bo(3401)</ref>
      <ref url="http://www.securityfocus.com/bid/749" source="BID" adv="1">749</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94121377716133&amp;w=2" source="BUGTRAQ" adv="1">19990729 ExpressFS 2.x FTPServer remotely exploitable buffer overflow vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94130292519646&amp;w=2" source="NTBUGTRAQ">19990729 ExpressFS 2.x FTPServer remotely exploitable buffer overflow vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="celtech_software" name="expressfs">
        <vers num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1515" published="1999-08-31" name="CVE-1999-1515" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">A non-default configuration in TenFour TFS Gateway 4.0 allows an attacker to cause a denial of service via messages with incorrect sender and recipient addresses, which causes the gateway to continuously try to return the message every 10 seconds.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3290.php" source="XF" patch="1" adv="1">tfs-gateway-dos(3290)</ref>
      <ref url="http://www.securityfocus.com/bid/613" source="BID" patch="1" adv="1">613</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tenfour" name="tfs_gateway">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1516" published="1999-09-02" name="CVE-1999-1516" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">A buffer overflow in TenFour TFS Gateway SMTP mail server 3.2 allows an attacker to crash the mail server and possibly execute arbitrary code by offering more than 128 bytes in a MAIL FROM string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93677241318492&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19990902 [SECURITY] TenFour TFS SMTP 3.2 Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tenfour" name="tfs_gateway_smtp">
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1517" published="1999-11-01" name="CVE-1999-1517" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">runtar in the Amanda backup system used in various UNIX operating systems executes tar with root privileges, which allows a user to overwrite or read arbitrary files by providing the target files to runtar.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/750" source="BID" patch="1" adv="1">750</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94148942818975&amp;w=2" source="BUGTRAQ" adv="1">19991101 Amanda multiple vendor local root compromises</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1518" published="1999-07-15" name="CVE-1999-1518" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Operating systems with shared memory implementations based on BSD 4.4 code allow a user to conduct a denial of service and bypass memory limits (e.g., as specified with rlimits) using mmap or shmget to allocate memory and cause page faults.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2351.php" source="XF" patch="1" adv="1">bsd-shared-memory-dos(2351)</ref>
      <ref url="http://www.securityfocus.com/bid/526" source="BID" patch="1" adv="1">526</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93207728118694&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19990715 Shared memory DoS's</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="1.1.5.1" />
        <vers num="2.0" />
        <vers num="2.0.5" />
        <vers num="2.1.0" />
        <vers num="2.1.5" />
        <vers num="2.1.6" />
        <vers num="2.1.7.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.8" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.4" edition="" />
        <vers num="1.4" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1519" published="1999-11-17" name="CVE-1999-1519" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Gene6 G6 FTP Server 2.0 allows a remote attacker to cause a denial of service (resource exhaustion) via a long (1) user name or (2) password.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3513.php" source="XF" adv="1">g6ftp-username-dos(3513)</ref>
      <ref url="http://www.securityfocus.com/bid/805" source="BID" adv="1">805</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94286244700573&amp;w=2" source="BUGTRAQ" adv="1">19991117 Remote D.o.S Attack in G6 FTP Server v2.0 (beta 4/5) Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gene6" name="g6_ftp_server">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1520" published="1999-05-11" name="CVE-1999-1520" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">A configuration problem in the Ad Server Sample directory (AdSamples) in Microsoft Site Server 3.0 allows an attacker to obtain the SITE.CSC file, which exposes sensitive SQL database information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2270.php" source="XF" patch="1" adv="1">siteserver-site-csc(2270)</ref>
      <ref url="http://www.securityfocus.com/bid/256" source="BID" patch="1" adv="1">256</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92647407227303&amp;w=2" source="BUGTRAQ" adv="1">19990511 [ALERT] Site Server 3.0 May Expose SQL IDs and PSWs</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="site_server">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1521" published="1999-09-12" name="CVE-1999-1521" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Computalynx CMail 2.4 and CMail 2.3 SP2 SMTP servers are vulnerable to a buffer overflow attack in the MAIL FROM command that may allow a remote attacker to execute arbitrary code on the server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2240.php" source="XF" patch="1" adv="1">cmail-command-bo(2240)</ref>
      <ref url="http://www.securityfocus.com/bid/633" source="BID" adv="1">633</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94121824921783&amp;w=2" source="BUGTRAQ" adv="1">19990729 Vulnerability in CMail SMTP Server Version 2.4: Remotely exploitable buffer</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93720402717560&amp;w=2" source="BUGTRAQ" adv="1">19990912 Many kind of POP3/SMTP server softwares for Windows have buffer overflow bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="computalynx" name="cmail">
        <vers num="2.3sp2" />
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1522" published="1999-10-07" name="CVE-1999-1522" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Vulnerability in htmlparse.pike in Roxen Web Server 1.3.11 and earlier, possibly related to recursive parsing and referer tags in RXML.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93942579008408&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19991007 Roxen security alert</ref>
    </refs>
    <vuln_soft>
      <prod vendor="roxen" name="roxen_web_server">
        <vers prev="1" num="1.3.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1523" published="1999-10-04" name="CVE-1999-1523" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Sambar Web Server 4.2.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1672.php" source="XF" patch="1" adv="1">sambar-logging-bo(1672)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93941351229256&amp;w=2" source="BUGTRAQ" adv="1">19991006 Re: Sample DOS against the Sambar HTTP-Server</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93901161727373&amp;w=2" source="BUGTRAQ" adv="1">19991004 </ref>
    </refs>
    <vuln_soft>
      <prod vendor="sambar" name="sambar_server">
        <vers num="4.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1524" published="1999-08-07" name="CVE-1999-1524" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">FlowPoint DSL router firmware versions prior to 3.0.8 allows a remote attacker to exploit a password recovery feature from the network and conduct brute force password guessing, instead of limiting the feature to the serial console port.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93424680430460&amp;w=2" source="BUGTRAQ" adv="1">19990807 Re: FlowPoint DSL router vulnerability </ref>
    </refs>
    <vuln_soft>
      <prod vendor="flowpoint" name="flowpoint_dsl_router">
        <vers prev="1" num="3.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1525" published="1997-03-14" name="CVE-1999-1525" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Macromedia Shockwave before 6.0 allows a malicious webmaster to read a user's mail box and possibly access internal web servers via the GetNextText command on a Shockwave movie.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/460.php" source="XF" patch="1" adv="1">http-ns-shockwave(460)</ref>
      <ref url="http://xforce.iss.net/static/1586.php" source="XF" patch="1" adv="1">shockwave-file-read-vuln(1586)</ref>
      <ref url="http://xforce.iss.net/static/1585.php" source="XF" patch="1" adv="1">shockwave-internal-access(1585)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420670&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19970314 Shockwave Security Alert</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macromedia" name="shockwave_flash_plugin">
        <vers prev="1" num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1526" published="1999-03-11" name="CVE-1999-1526" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Auto-update feature of Macromedia Shockwave 7 transmits a user's password and hard disk information back to Macromedia.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1931.php" source="XF" patch="1" adv="1">shockwave-updater(1931)</ref>
      <ref url="http://www.securityfocus.com/archive/1/12842" source="BUGTRAQ" adv="1">19990311 [Fwd: Shockwave 7 Security Hole]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macromedia" name="shockwave_flash_plugin">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1527" published="1999-11-23" name="CVE-1999-1527" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Internal HTTP server in Sun Netbeans Java IDE in Netbeans Developer 3.0 Beta and Forte Community Edition 1.0 Beta does not properly restrict access to IP addresses as specified in its configuration, which allows arbitrary remote attackers to access the server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/816" source="BID" patch="1" adv="1">816</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94338883114254&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19991123 NetBeans/ Forte' Java IDE HTTP vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="forte">
        <vers num="community_1.0_beta" />
      </prod>
      <prod vendor="sun" name="netbeans_developer">
        <vers num="3.0_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1528" published="1999-11-14" name="CVE-1999-1528" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">ProSoft Netware Client 5.12 on Macintosh MacOS 9 does not automatically log a user out of the NDS tree when the user logs off the system, which allows other users of the same system access to the unprotected NDS session.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/794" source="BID" patch="1" adv="1">794</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94261444428430&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19991114 MacOS 9 and the MacOS Netware Client</ref>
    </refs>
    <vuln_soft>
      <prod vendor="prosoft_engineering" name="netware_client">
        <vers num="5.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1529" published="1999-11-07" name="CVE-1999-1529" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">A buffer overflow exists in the HELO command in Trend Micro Interscan VirusWall SMTP gateway 3.23/3.3 for NT, which may allow an attacker to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3465.php" source="XF" patch="1" adv="1">viruswall-helo-bo(3465)</ref>
      <ref url="http://www.securityfocus.com/bid/787" source="BID" patch="1" adv="1">787</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94208143007829&amp;w=2" source="NTBUGTRAQ" patch="1">19991108 Patch for VirusWall 3.23.</ref>
      <ref url="http://www.securityfocus.com/archive/1/55551" source="BUGTRAQ" adv="1">20000417 New DOS on Interscan NT/3.32</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94201512111092&amp;w=2" source="BUGTRAQ" adv="1">19991107 Interscan VirusWall NT 3.23/3.3 buffer overflow</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94199707625818&amp;w=2" source="NTBUGTRAQ">19991107 Interscan VirusWall NT 3.23/3.3 buffer overflow.</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94210427406568&amp;w=2" source="BUGTRAQ">19991108 Re: Interscan VirusWall NT 3.23/3.3 buffer overflow.</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94204166130782&amp;w=2" source="BUGTRAQ">19991108 Patch for VirusWall 3.23.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="interscan_viruswall">
        <vers num="3.23" />
        <vers num="3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1530" published="1999-11-08" name="CVE-1999-1530" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">cgiwrap as used on Cobalt RaQ 2.0 and RaQ 3i does not properly identify the user for running certain scripts, which allows a malicious site administrator to view or modify data located at another virtual site on the same system.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/777" source="BID" patch="1" adv="1">777</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94225629200045&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19991109 [Cobalt] Security Advisory - cgiwrap</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94209954200450&amp;w=2" source="BUGTRAQ" adv="1">19991108 Security flaw in Cobalt RaQ2 cgiwrap</ref>
      <ref url="http://www.osvdb.org/35" source="OSVDB">35</ref>
      <ref url="http://www.iss.net/security_center/static/7764.php" source="XF">cobalt-cgiwrap-incorrect-permissions(7764)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="cobalt_raq_2">
        <vers num="" />
      </prod>
      <prod vendor="sun" name="cobalt_raq_3i">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1531" published="1999-11-02" name="CVE-1999-1531" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in IBM HomePagePrint 1.0.7 for Windows98J allows a malicious Web site to execute arbitrary code on a viewer's system via a long IMG_SRC HTML tag.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/763" source="BID" patch="1" adv="1">763</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94157187815629&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19991102 Some holes for Win/UNIX softwares</ref>
      <ref url="http://www.iss.net/security_center/static/7767.php" source="XF">ibm-homepageprint-bo(7767)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="homepageprint">
        <vers num="1.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1532" published="1999-10-29" name="CVE-1999-1532" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Netscape Messaging Server 3.54, 3.55, and 3.6 allows a remote attacker to cause a denial of service (memory exhaustion) via a series of long RCPT TO commands.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/748" source="BID" adv="1">748</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94117465014255&amp;w=2" source="BUGTRAQ" adv="1">19991029 message:Netscape Messaging Server RCPT TO vul.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="messaging_server">
        <vers num="3.54" />
        <vers num="3.55" />
        <vers num="3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1533" published="1999-11-07" name="CVE-1999-1533" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Eicon Technology Diva LAN ISDN modem allows a remote attacker to cause a denial of service (hang) via a long password argument to the login.htm file in its HTTP service.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3317.php" source="XF">diva-lan-isdn-dos(3317)</ref>
      <ref url="http://www.securityfocus.com/bid/665" source="BID">665</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93846522511387&amp;w=2" source="BUGTRAQ">19990926 DoS Exploit in Eicon Diehl LAN ISDN Modem</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="interscan_viruswall">
        <vers num="3.2.3" />
        <vers num="3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1534" published="1999-09-23" name="CVE-1999-1534" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in (1) nlservd and (2) rnavc in Knox Software Arkeia backup product allows local users to obtain root access via a long HOME environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/661" source="BID" patch="1" adv="1">661</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93837184228248&amp;w=2" source="BUGTRAQ" adv="1">19990923 Multiple vendor Knox Arkiea local root/remote DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="knox_software" name="arkeia">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1535" published="1999-07-20" name="CVE-1999-1535" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in AspUpload.dll in Persits Software AspUpload before 1.4.0.2 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long argument in the HTTP request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3291.php" source="XF" patch="1" adv="1">http-aspupload-bo(3291)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93501427820328&amp;w=2" source="NTBUGTRAQ" patch="1" adv="1">19990818 AspUpload Buffer Overflow Fixed</ref>
      <ref url="http://www.securityfocus.com/bid/592" source="BID" adv="1">592</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93256878011447&amp;w=2" source="NTBUGTRAQ" adv="1">19990720 Buffer overflow in AspUpload 1.4</ref>
    </refs>
    <vuln_soft>
      <prod vendor="persits" name="aspupload">
        <vers prev="1" num="1.4.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1536" published="1999-07-30" name="CVE-1999-1536" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">.sbstart startup script in AcuShop Salesbuilder is world writable, which allows local users to gain privileges by appending commands to the file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93347785827287&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19990730 World writable root owned script in SalesBuilder (RedHat 6.0)</ref>
      <ref url="http://www.securityfocus.com/bid/560" source="BID" adv="1">560</ref>
      <ref url="http://www.osvdb.org/13557" source="OSVDB">13557</ref>
    </refs>
    <vuln_soft>
      <prod vendor="acushop" name="salesbuilder">
        <vers num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1537" published="1999-07-07" name="CVE-1999-1537" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IIS 3.x and 4.x does not distinguish between pages requiring encryption and those that do not, which allows remote attackers to cause a denial of service (resource exhaustion) via SSL requests to the HTTPS port for normally unencrypted files, which will cause IIS to perform extra work to send the files over SSL.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/521" source="BID" patch="1" adv="1">521</ref>
      <ref url="http://xforce.iss.net/static/2352.php" source="XF" adv="1">ssl-iis-dos(2352)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93138827329577&amp;w=2" source="NTBUGTRAQ" adv="1">19990707 SSL and IIS.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="3.0" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1538" published="1999-01-14" name="CVE-1999-1538" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information, including the Administrator's password.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91632724913080&amp;w=2" source="NTBUGTRAQ" patch="1">19990114 MS IIS 4.0 Security Advisory</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91638375309890&amp;w=2" source="BUGTRAQ" patch="1">19990114 MS IIS 4.0 Security Advisory</ref>
      <ref url="http://www.securityfocus.com/bid/189" source="BID">189</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1539" published="1999-11-10" name="CVE-1999-1539" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in FTP server in QPC Software's QVT/Term Plus versions 4.2d and 4.3 and QVT/Net 4.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long (1) user name or (2) password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3491.php" source="XF" adv="1">qvtterm-login-dos(3491)</ref>
      <ref url="http://www.securityfocus.com/bid/796" source="BID" adv="1">796</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94223972910670&amp;w=2" source="NTBUGTRAQ" adv="1">19991110 Remote DoS Attack in QVT/Term 'Plus' 4.2d FTP Server Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94225924803704&amp;w=2" source="BUGTRAQ">19991110 Remote DoS Attack in QVT/Term 'Plus' 4.2d FTP Server Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qpc_software" name="qvt_net">
        <vers num="4.3" />
      </prod>
      <prod vendor="qpc_software" name="qvt_term_plus">
        <vers num="4.2d" />
        <vers num="4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1540" published="1999-10-04" name="CVE-1999-1540" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">shell-lock in Cactus Software Shell Lock uses weak encryption (trivial encoding) which allows attackers to easily decrypt and obtain the source code.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3356.php" source="XF" patch="1" adv="1">cactus-shell-lock-retrieve-shell-code(3356)</ref>
      <ref url="http://www.atstake.com/research/advisories/1999/shell-lock.txt" source="L0PHT">19991004</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93916168802365&amp;w=2" source="BUGTRAQ" adv="1">19991005 Cactus Software's shell-lock</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cactus_software" name="shell-lock">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1541" published="1999-10-04" name="CVE-1999-1541" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">shell-lock in Cactus Software Shell Lock allows local users to read or modify decoded shell files before they are executed, via a symlink attack on a temporary file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3358.php" source="XF" adv="1">cactus-shell-lock-root-privs(3358)</ref>
      <ref url="http://www.atstake.com/research/advisories/1999/shell-lock.txt" source="L0PHT">19991004</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93916168802365&amp;w=2" source="BUGTRAQ">19991005 Cactus Software's shell-lock</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cactus_software" name="shell-lock">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1542" published="1999-10-04" name="CVE-1999-1542" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">RPMMail before 1.4 allows remote attackers to execute commands via an e-mail message with shell metacharacters in the "MAIL FROM" command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3353.php" source="XF" patch="1" adv="1">linux-rh-rpmmail(3353)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93923853105687&amp;w=2" source="BUGTRAQ" adv="1">19991006 Fwd: [Re: RH6.0 local/remote command execution]</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93915641729415&amp;w=2" source="BUGTRAQ">19991004 RH6.0 local/remote command execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1543" published="1999-07-10" name="CVE-1999-1543" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">MacOS uses weak encryption for passwords that are stored in the Users &amp; Groups Data File.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/519" source="BID" patch="1" adv="1">519</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93736667813924&amp;w=2" source="BUGTRAQ" adv="1">19990914 MacOS system encryption algorithm 3</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93188174906513&amp;w=2" source="BUGTRAQ" adv="1">19990710 MacOS system encryption algorithm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os">
        <vers num="7.5.3" />
        <vers num="7.6" />
        <vers num="7.6.1" />
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.5" />
        <vers num="8.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1544" published="1999-01-24" name="CVE-1999-1544" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in FTP server in Microsoft IIS 3.0 and 4.0 allows local and sometimes remote attackers to cause a denial of service via a long NLST (ls) command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91722115016183&amp;w=2" source="BUGTRAQ">19990124 Advisory: IIS FTP Exploit/DoS Attack</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="3.0" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1545" published="1999-07-14" name="CVE-1999-1545" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Joe's Own Editor (joe) 2.8 sets the world-readable permission on its crash-save file, DEADJOE, which could allow local users to read files that were being edited by other users.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93226771401036&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19990717 joe 2.8 makes world-readable DEADJOE</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93216103027827&amp;w=2" source="BUGTRAQ">19990714 </ref>
    </refs>
    <vuln_soft>
      <prod vendor="joes_own_editor" name="joe">
        <vers num="2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1546" published="1999-01-29" name="CVE-1999-1546" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">netstation.navio-com.rte 1.1.0.1 configuration script for Navio NC on IBM AIX exports /tmp over NFS as world-readable and world-writable.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1724.php" source="XF">navionc-config-script(1724)</ref>
      <ref url="http://www.securityfocus.com/archive/1/12217" source="BUGTRAQ">19990129 TROJAN: netstation.navio-comm.rte 1.1.0.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="navio_nc_browser">
        <vers num="1.1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1547" published="1999-11-25" name="CVE-1999-1547" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Oracle Web Listener 2.1 allows remote attackers to bypass access restrictions by replacing a character in the URL with its HTTP-encoded (hex) equivalent.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/841" source="BID" adv="1">841</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94390053530890&amp;w=2" source="NTBUGTRAQ" adv="1">19991125 Oracle Web Listener</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94359982417686&amp;w=2" source="BUGTRAQ">19991125 Oracle Web Listener</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="web_listener">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1548" published="1999-11-24" name="CVE-1999-1548" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cabletron SmartSwitch Router (SSR) 8000 firmware 2.x can only handle 200 ARP requests per second allowing a denial of service attack to succeed with a flood of ARP requests exceeding that limit.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://razor.bindview.com/publish/advisories/adv_Cabletron.html" source="BINDVIEW" patch="1" adv="1">19991124 Cabletron SmartSwitch Router 8000 Firmware v2.x</ref>
      <ref url="http://www.securityfocus.com/bid/841" source="BID">821</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cabletron" name="smartswitch_router_8000_firmware">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1549" published="1999-11-16" name="CVE-1999-1549" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Lynx 2.x does not properly distinguish between internal and external HTML, which may allow a local attacker to read a "secure" hidden form value from a temporary file and craft a LYNXOPTIONS: URL that causes Lynx to modify the user's configuration file and execute commands.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/804" source="BID" adv="1">804</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94286509804526&amp;w=2" source="BUGTRAQ" adv="1">19991116 lynx 2.8.x - 'special URLs' anti-spoofing protection is weak</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_kansas" name="lynx">
        <vers num="2.7" />
        <vers num="2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1550" published="1999-11-08" name="CVE-1999-1550" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">bigconf.conf in F5 BIG/ip 2.1.2 and earlier allows remote attackers to read arbitrary files by specifying the target file in the "file" parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94225879703021&amp;w=2" source="BUGTRAQ" patch="1" adv="1">19991109 </ref>
      <ref url="http://www.securityfocus.com/bid/778" source="BID" adv="1">778</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94217879020184&amp;w=2" source="BUGTRAQ" adv="1">19991109 Re: BigIP - bigconf.cgi holes </ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94217006208374&amp;w=2" source="BUGTRAQ" adv="1">19991108 BigIP - bigconf.cgi holes</ref>
      <ref url="http://www.iss.net/security_center/static/7771.php" source="XF">bigip-bigconf-view-files(7771)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="f5" name="big-ip">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1551" published="1999-03-02" name="CVE-1999-1551" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Ipswitch IMail Service 5.0 allows an attacker to cause a denial of service (crash) and possibly execute arbitrary commands via a long URL.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/505" source="BID" patch="1">505</ref>
      <ref url="http://xforce.iss.net/static/1898.php" source="XF">imail-websvc-overflow(1898)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92038879607336&amp;w=2" source="BUGTRAQ">19990302 Multiple IMail Vulnerabilites</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="imail">
        <vers num="5.0" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1552" published="1994-07-20" name="CVE-1999-1552" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">dpsexec (DPS Server) when running under XDM in IBM AIX 3.2.5 and earlier does not properly check privileges, which allows local users to overwrite arbitrary files and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/358" source="BID" patch="1" adv="1">358</ref>
      <ref url="http://lists.insecure.org/lists/bugtraq/1994/Jul/0038.html" source="BUGTRAQ">19940720 xnews and XDM</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.2.4" />
        <vers prev="1" num="3.2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1553" published="1999-05-01" name="CVE-1999-1553" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in XCmail 0.99.6 with autoquote enabled allows remote attackers to execute arbitrary commands via a long subject line.</descript>
    </desc>
    <sols>
      <sol source="nvd">The authors were notified of this problem and it was fixed in devel-release 0.99.7.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1859.php" source="XF">xcmail-reply-overflow(1859)</ref>
      <ref url="http://www.securityfocus.com/bid/311" source="BID">311</ref>
      <ref url="http://www.securityfocus.com/archive/1/12730" source="BUGTRAQ">19990301 [0z0n3] XCmail remotely exploitable vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xcmail" name="xcmail">
        <vers num="0.99.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1554" published="1990-10-31" name="CVE-1999-1554" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">/usr/sbin/Mail on SGI IRIX 3.3 and 3.3.1 does not properly set the group ID to the group ID of the user who started Mail, which allows local users to read the mail of other users.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1990-08.html" source="CERT" patch="1" adv="1">CA-1990-08</ref>
      <ref url="http://www.securityfocus.com/bid/13" source="BID" patch="1" adv="1">13</ref>
      <ref url="http://www.iss.net/security_center/static/3164.php" source="XF">sgi-irix-reset(3164)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="3.3" />
        <vers num="3.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1555" published="1998-06-11" name="CVE-1999-1555" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Cheyenne InocuLAN Anti-Virus Server in Inoculan 4.0 before Service Pack 2 creates an update directory with "EVERYONE FULL CONTROL" permissions, which allows local users to cause Inoculan's antivirus update feature to install a Trojan horse dll.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1536.php" source="XF" patch="1" adv="1">inoculan-bad-permissions(1536)</ref>
      <ref url="http://www.securityfocus.com/archive/1/9515" source="BUGTRAQ" patch="1" adv="1">19980611 Cheyenne Inoculan vulnerability on NT</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cheyenne" name="inoculan_anti-virus_server">
        <vers prev="1" num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1556" published="1998-06-29" name="CVE-1999-1556" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Microsoft SQL Server 6.5 uses weak encryption for the password for the SQLExecutiveCmdExec account and stores it in an accessible portion of the registry, which could allow local users to gain privileges by reading and decrypting the CmdExecAccount value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/7354" source="XF" adv="1">mssql-sqlexecutivecmdexec-password(7354)</ref>
      <ref url="http://www.securityfocus.com/bid/109" source="BID" adv="1">109</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=90222453431645&amp;w=2" source="NTBUGTRAQ" adv="1">19980629 MS SQL Server 6.5 stores password in unprotected registry keys</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="sql_server">
        <vers num="6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1557" published="2005-05-02" name="CVE-1999-1557" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in the login functions in IMAP server (imapd) in Ipswitch IMail 5.0 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long user name or (2) a long password.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1895.php" source="XF" patch="1">imail-imap-overflow(1895)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92038879607336&amp;w=2" source="BUGTRAQ">19990301 Multiple IMail Vulnerabilites</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="imail">
        <vers prev="1" num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1558" published="1998-07-16" name="CVE-1999-1558" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Vulnerability in loginout in Digital OpenVMS 7.1 and earlier allows unauthorized access when external authentication is enabled.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/161" source="BID" patch="1" adv="1">161</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/i-071a.shtml" source="CIAC" patch="1" adv="1">I-071A</ref>
      <ref url="http://www.iss.net/security_center/static/7151.php" source="XF">openvms-loginout-unauth-access(7151)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digital" name="digital_openvms">
        <vers num="7.1" />
      </prod>
      <prod vendor="digital" name="digital_openvms_axp">
        <vers num="7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1559" published="1999-03-31" name="CVE-1999-1559" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Xylan OmniSwitch before 3.2.6 allows remote attackers to bypass the login prompt via a CTRL-D (control d) character, which locks other users out of the switch because it only supports one session at a time.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2064.php" source="XF" adv="1">xylan-omniswitch-login(2064)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92299263017061&amp;w=2" source="BUGTRAQ">19990331 Xylan OmniSwitch "features"</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alcatel" name="omniswitch">
        <vers prev="1" num="3.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1560" published="1999-07-20" name="CVE-1999-1560" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in a script in Texas A&amp;M University (TAMU) Tiger allows local users to execute arbitrary commands as the Tiger user, usually root.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2369.php" source="XF" patch="1" adv="1">tiger-script-execute(2369)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93252050203589&amp;w=2" source="BUGTRAQ" adv="1">19990720 tiger vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tamu" name="tiger">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1561" published="1999-08-20" name="CVE-1999-1561" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Nullsoft SHOUTcast server stores the administrative password in plaintext in a configuration file (sc_serv.conf), which could allow a local user to gain administrative privileges on the server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/24852" source="BUGTRAQ" patch="1" adv="1">19990820 Winamp SHOUTcast server: Gain Administrator Password</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nullsoft" name="shoutcast_server">
        <vers num="1.9.7" edition="" />
        <vers num="1.9.7" edition=":win32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1562" published="1999-09-05" name="CVE-1999-1562" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">gFTP FTP client 1.13, and other versions before 2.0.0, records a password in plaintext in (1) the log window, or (2) in a log file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/26915" source="BUGTRAQ" patch="1" adv="1">19990905 gftp</ref>
      <ref url="http://www.securityfocus.com/bid/3446" source="BID">3446</ref>
      <ref url="http://www.debian.org/security/2001/dsa-084" source="DEBIAN">DSA-084</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gftp" name="ftp_client">
        <vers num="1.13" />
        <vers prev="1" num="2.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1563" published="2000-10-14" name="CVE-1999-1563" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Nachuatec D435 and D445 printer allows remote attackers to cause a denial of service via ICMP redirect storm.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/35075" source="BUGTRAQ" adv="1">19991116 NEUROCOM: Nashuatec D445/435 vulnerabilities updated</ref>
      <ref url="http://www.securityfocus.com/archive/1/30849" source="BUGTRAQ" adv="1">19991014 NEUROCOM: Nashuatec printer, 3 vulnerabilities found</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nachuatec" name="d435">
        <vers num="" />
      </prod>
      <prod vendor="nachuatec" name="d445">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1564" published="1999-09-02" name="CVE-1999-1564" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">FreeBSD 3.2 and possibly other versions allows a local user to cause a denial of service (panic) with a large number accesses of an NFS v3 mounted directory from a large number of processes.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/26166" source="BUGTRAQ" adv="1">19990902 [ Kernel panic with FreeBSD-3.2-19990830-STABLE ]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1565" published="1999-08-20" name="CVE-1999-1565" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Man2html 2.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/24784" source="BUGTRAQ" patch="1" adv="1">19990820 [SECURITY] New versions of man2html fixes postinst glitch</ref>
      <ref url="http://www.osvdb.org/6291" source="OSVDB">6291</ref>
    </refs>
    <vuln_soft>
      <prod vendor="earl_hood" name="man2html">
        <vers prev="1" num="2.1" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1566" published="1999-05-08" name="CVE-1999-1566" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in iParty server 1.2 and earlier allows remote attackers to cause a denial of service (crash) by connecting to default port 6004 and sending repeated extended characters.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/13600" source="BUGTRAQ" adv="1">19990508 iParty Daemon Vulnerability w/ Exploit Code (worse than thought?)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intel" name="iparty">
        <vers prev="1" num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1567" published="1999-03-08" name="CVE-1999-1567" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Seapine Software TestTrack server allows a remote attacker to cause a denial of service (high CPU) via (1) TestTrackWeb.exe and (2) ttcgi.exe by connecting to port 99 and disconnecting without sending any data.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/1948.php" source="XF">testtrack-dos(1948)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="seapine_software" name="testtrack">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1568" published="1999-01-01" name="CVE-1999-1568" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Off-by-one error in NcFTPd FTP server before 2.4.1 allows a remote attacker to cause a denial of service (crash) via a long PORT command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91981352617720&amp;w=2" source="BUGTRAQ">19990223 NcFTPd remote buffer overflow</ref>
      <ref url="http://xforce.iss.net/static/1833.php" source="XF">ncftpd-port-bo(1833)</ref>
      <ref url="http://www.securityfocus.com/archive/1/12699" source="BUGTRAQ">19990223 Comments on NcFTPd "theoretical root compromise"</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ncftpd" name="ncftpd_ftp_server">
        <vers prev="1" num="2.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1569" published="2001-07-17" name="CVE-1999-1569" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Quake 1 and NetQuake servers allow remote attackers to cause a denial of service (resource exhaustion or forced disconnection) via a flood of spoofed UDP connection packets, which exceeds the server's player limit.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6871.php" source="XF" adv="1">quake-spoofed-client-dos(6871)</ref>
      <ref url="http://www.securityfocus.com/bid/3051" source="BID" adv="1">3051</ref>
      <ref url="http://www.securityfocus.com/archive/1/197268" source="BUGTRAQ">20010716 Quake client and server denial-of-service</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91012172524181&amp;w=2" source="BUGTRAQ" adv="1">19981101 Quake problem?</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101925989&amp;w=2" source="BUGTRAQ">19980502 NetQuake Protocol problem resulting in smurf like effect.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="id_software" name="quake">
        <vers num="1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1570" published="2002-05-01" name="CVE-1999-1570" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in sar for OpenServer 5.0.5 allows local users to gain root privileges via a long -o parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/4089" source="BID" patch="1" adv="1">4089</ref>
      <ref url="http://www.iss.net/security_center/static/8989.php" source="XF" patch="1" adv="1">openserver-sar-bo(8989)</ref>
      <ref url="ftp://stage.caldera.com/pub/security/openserver/CSSA-2002-SCO.17/CSSA-2002-SCO.17.txt" source="CALDERA" patch="1" adv="1">CSSA-2002-SCO.17</ref>
      <ref url="http://online.securityfocus.com/archive/1/27074" source="BUGTRAQ">19990909 19 SCO 5.0.5+Skunware98 buffer overflows</ref>
      <ref url="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=102098949103708&amp;w=2" source="VULN-DEV">20020509 Sar -o exploitation process info.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="caldera" name="openserver">
        <vers num="5.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1571" published="1999-11-04" name="CVE-1999-1571" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in sar for SCO OpenServer 5.0.0 through 5.0.5 may allow local users to gain root privileges via a long -f parameter, a different vulnerability than CVE-1999-1570.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://online.securityfocus.com/advisories/1843" source="MISC" patch="1" adv="1">http://online.securityfocus.com/advisories/1843</ref>
      <ref url="http://www.iss.net/security_center/static/8989.php" source="XF" adv="1">openserver-sar-bo(8989)</ref>
      <ref url="http://online.securityfocus.com/archive/1/27074" source="BUGTRAQ">19990909 19 SCO 5.0.5+Skunware98 buffer overflows</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93762097815861&amp;w=2" source="BUGTRAQ" adv="1">19990917 Re: recent SCO 5.0.x vulnerabilities</ref>
      <ref url="ftp://stage.caldera.com/pub/security/sse/sse037c/sse037c.ltr" source="CONFIRM">ftp://stage.caldera.com/pub/security/sse/sse037c/sse037c.ltr</ref>
      <ref url="ftp://stage.caldera.com/pub/security/sse/security_bulletins/SB-99.17c" source="SCO">SB-99.17c</ref>
      <ref url="http://www.securityfocus.com/bid/643" source="BID">643</ref>
      <ref url="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=102098949103708&amp;w=2" source="VULN-DEV">20020509 Sar -o exploitation process info.</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94183363719024&amp;w=2" source="BUGTRAQ">19991105 SCO Security Bulletin 99.17</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94053017801639&amp;w=2" source="BUGTRAQ">19991020 Re: recent SCO 5.0.x vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="openserver">
        <vers num="5.0.0" />
        <vers num="5.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1572" published="1996-07-16" name="CVE-1999-1572" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">cpio on FreeBSD 2.1.0, Debian GNU/Linux 3.0, and possibly other operating systems, uses a 0 umask when creating files using the -O (archive) or -F options, which creates the files with mode 0666 and allows local users to read or overwrite those files.</descript>
    </desc>
    <sols>
      <sol source="nvd">Fixed in rev 1.3 of cpio/main.c.</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/19167" source="XF">cpio-o-archive-insecure-permissions(19167)</ref>
      <ref url="http://www.trustix.org/errata/2005/0003/" source="TRUSTIX">2005-0003</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-080.html" source="REDHAT">RHSA-2005:080</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-073.html" source="REDHAT">RHSA-2005:073</ref>
      <ref url="http://www.freebsd.org/cgi/query-pr.cgi?pr=bin/1391" source="MISC">http://www.freebsd.org/cgi/query-pr.cgi?pr=bin/1391</ref>
      <ref url="http://www.debian.org/security/2005/dsa-664" source="DEBIAN">DSA-664</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10888" source="OVAL">oval:org.mitre.oval:def:10888</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2005-806.html" source="REDHAT">RHSA-2005:806</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:032" source="MANDRAKE">MDKSA-2005:032</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2005-212.pdf" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2005-212.pdf</ref>
      <ref url="http://secunia.com/advisories/17532" source="SECUNIA">17532</ref>
      <ref url="http://secunia.com/advisories/17063" source="SECUNIA">17063</ref>
      <ref url="http://secunia.com/advisories/14357" source="SECUNIA">14357</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110763404701519&amp;w=2" source="BUGTRAQ">20050204 [USN-75-1] cpio vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="2.1.0" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="10.0" />
        <vers num="10.1" />
        <vers num="9.2" />
        <vers num="cs2.1" />
        <vers num="cs3.0" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":advanced_server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":workstation" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="4.0" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1573" published="1999-12-28" name="CVE-1999-1573" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unknown vulnerabilities in the "r-cmnds" (1) remshd, (2) rexecd, (3) rlogind, (4) rlogin, (5) remsh, (6) rcp, (7) rexec, and (8) rdist for HP-UX 10.00 through 11.00 allow attackers to gain privileges or access files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/13217" source="CERT-VN">VU#13217</ref>
      <ref url="http://www.securityfocus.com/advisories/1471" source="HP" patch="1">HPSBUX9812-090</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/j-022.shtml" source="CIAC" patch="1">J-022</ref>
      <ref url="http://www.auscert.org.au/render.html?it=490" source="AUSCERT" patch="1">ESB-98.186</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/7860" source="XF" adv="1">hp-rcmnds-gain-privileges(7860)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5550" source="OVAL">oval:org.mitre.oval:def:5550</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.00" />
        <vers num="10.01" />
        <vers num="10.10" />
        <vers num="10.20" />
        <vers num="10.30" />
        <vers num="11.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1574" published="1998-07-06" name="CVE-1999-1574" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the lex routines of nslookup for AIX 4.3 may allow attackers to cause a core dump and possibly execute arbitrary code via "long input strings."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/182777" source="CERT-VN" patch="1">VU#182777</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/7867" source="XF">aix-nslookup-lex-bo(7867)</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IX79909&amp;apar=only" source="AIXAPAR">IX79909</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1575" published="1999-09-10" name="CVE-1999-1575" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">The Kodak/Wang (1) Image Edit (imgedit.ocx), (2) Image Annotation (imgedit.ocx), (3) Image Scan (imgscan.ocx), (4) Thumbnail Image (imgthumb.ocx), (5) Image Admin (imgadmin.ocx), (6) HHOpen (hhopen.ocx), (7) Registration Wizard (regwizc.dll), and (8) IE Active Setup (setupctl.dll) ActiveX controls for Internet Explorer (IE) 4.01 and 5.0 are marked as "Safe for Scripting," which allows remote attackers to create and modify files and execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/9162" source="CERT-VN">VU#9162</ref>
      <ref url="http://www.kb.cert.org/vuls/id/41408" source="CERT-VN">VU#41408</ref>
      <ref url="http://www.kb.cert.org/vuls/id/26924" source="CERT-VN">VU#26924</ref>
      <ref url="http://www.kb.cert.org/vuls/id/24839" source="CERT-VN">VU#24839</ref>
      <ref url="http://www.kb.cert.org/vuls/id/23412" source="CERT-VN">VU#23412</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/7097" source="XF">wang-kodak-activex-control(7097)</ref>
      <ref url="http://www.securityfocus.com/archive/1/28719" source="BUGTRAQ">19990924 Several ActiveX Buffer Overruns</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-037.mspx" source="MS">MS99-037</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.0.1" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1576" published="1999-09-27" name="CVE-1999-1576" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Adobe Acrobat ActiveX control (pdf.ocx, PDF.PdfCtrl.1) 1.3.188 for Acrobat Reader 4.0 allows remote attackers to execute arbitrary code via the pdf.setview method.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/25919" source="CERT-VN">VU#25919</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/3318" source="XF" patch="1">adobe-acrobat-pdf-bo(3318)</ref>
      <ref url="http://www.securityfocus.com/bid/666" source="BID" patch="1">666</ref>
      <ref url="http://www.securityfocus.com/archive/1/28719" source="BUGTRAQ" adv="1">19990924 Several ActiveX Buffer Overruns</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1577" published="1999-10-31" name="CVE-1999-1577" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in HHOpen ActiveX control (hhopen.ocx) 1.0.0.1 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands via long arguments to the OpenHelp method.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/29795" source="CERT-VN">VU#29795</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/3314" source="XF">ie-hhopen-bo(3314)</ref>
      <ref url="http://www.securityfocus.com/bid/0669" source="BID">669</ref>
      <ref url="http://www.securityfocus.com/archive/1/28719" source="BUGTRAQ">19990924 Several ActiveX Buffer Overruns</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.0.1" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1578" published="1999-09-24" name="CVE-1999-1578" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in Registration Wizard ActiveX control (regwizc.dll, InvokeRegWizard) 3.0.0.0 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/37556" source="CERT-VN" patch="1" adv="1">VU#37556</ref>
      <ref url="http://www.securityfocus.com/bid/671" source="BID" patch="1">671</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/3311" source="XF">ie-registration-wiz-bo(3311)</ref>
      <ref url="http://www.securityfocus.com/archive/1/28719" source="BUGTRAQ">19990924 Several ActiveX Buffer Overruns</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.0.1" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1579" published="2000-12-14" name="CVE-1999-1579" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Cenroll ActiveX control (xenroll.dll) for Terminal Server Editions of Windows NT 4.0 and Windows NT Server 4.0 before SP6 allows remote attackers to cause a denial of service (resource consumption) by creating a large number of arbitrary files on the target machine.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/3062" source="CERT-VN">VU#3062</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/7107" source="XF" patch="1">winnt-xenroll-dos(7107)</ref>
      <ref url="http://www.securityfocus.com/bid/6827" source="BID">6827</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;242366" source="MSKB">Q242366</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1580" published="1995-08-23" name="CVE-1999-1580" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">SunOS sendmail 5.59 through 5.65 uses popen to process a forwarding host argument, which allows local users to gain root privileges by modifying the IFS (Internal Field Separator) variable and passing crafted values to the -oR option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-95.11.sun.sendmail-oR.vul" source="CERT" patch="1" adv="1">CA-1995-11</ref>
      <ref url="http://www.kb.cert.org/vuls/id/3278" source="CERT-VN" adv="1">VU#3278</ref>
      <ref url="http://www.securityfocus.com/bid/7829" source="BID">7829</ref>
      <ref url="http://www.auscert.org.au/render.html?it=1853&amp;cid=1978" source="AUSCERT" adv="1">AA-95.09</ref>
      <ref url="http://www.alw.nih.gov/Security/8lgm/8lgm-Advisory-21.html" source="MISC">http://www.alw.nih.gov/Security/8lgm/8lgm-Advisory-21.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sendmail" name="sendmail">
        <vers num="5.59" />
        <vers num="5.61" />
        <vers num="5.65" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.3c" />
        <vers num="4.1.3u1" />
        <vers num="4.1.4" />
        <vers num="4.1.4jl" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="1999-1581" published="1997-12-23" name="CVE-1999-1581" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Memory leak in Simple Network Management Protocol (SNMP) agent (snmp.exe) for Windows NT 4.0 before Service Pack 4 allows remote attackers to cause a denial of service (memory consumption) via a large number of SNMP packets with Object Identifiers (OIDs) that cannot be decoded.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <access />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/4923" source="CERT-VN">VU#4923</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/8231" source="XF">winnt-snmp-oid-memory-leak(8231)</ref>
      <ref url="http://support.microsoft.com/kb/q178381/" source="MSKB">Q178381</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1582" published="1998-07-15" name="CVE-1999-1582" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">By design, the "established" command on the Cisco PIX firewall allows connections from one host to arbitrary ports of a target host if an alternative conduit has already been allowed, which can cause administrators to configure less restrictive access controls than intended if they do not understand this functionality.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/6733" source="CERT-VN">VU#6733</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/8052" source="XF">cisco-pix-established-bypass(8052)</ref>
      <ref url="http://www.cisco.com/warp/public/707/pixest-pub.shtml" source="CISCO">19980715 PIX Firewall "established" Command</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="pix_firewall">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1583" published="1999-09-30" name="CVE-1999-1583" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in nslookup for AIX 4.3 allows local users to execute arbitrary code via a long hostname command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/872443" source="CERT-VN" patch="1">VU#872443</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY02120&amp;apar=only" source="AIXAPAR" patch="1">IY02120</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/8031" source="XF">aix-nslookup-hostname-bo(8031)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1584" published="1999-12-31" name="CVE-1999-1584" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unknown vulnerability in (1) loadmodule, and (2) modload if modload is installed with setuid/setgid privileges, in SunOS 4.1.1 through 4.1.3c, and Open Windows 3.0, allows local users to gain root privileges via environment variables, a different vulnerability than CVE-1999-1586.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1993-18.html" source="CERT" patch="1" adv="1">CA-93.18</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-22-00124-1" source="SUN" patch="1" adv="1">00124</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="openwindows">
        <vers num="3.0" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.3c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1585" published="1999-12-31" name="CVE-1999-1585" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The (1) rcS and (2) mountall programs in Sun Solaris 2.x, possibly before 2.4, start a privileged shell on the system console if fsck fails while the system is booting, which allows attackers with physical access to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-22-00124-1" source="SUN" patch="1" adv="1">00124</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1586" published="1999-12-31" name="CVE-1999-1586" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">loadmodule in SunOS 4.1.x, as used by xnews, does not properly sanitize its environment, which allows local users to gain privileges, a different vulnerability than CVE-1999-1584.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1995-12.html" source="CERT" patch="1" adv="1">CA-95.12</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/498" source="XF" patch="1">sun-loadmodule(498)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/g-02.shtml" source="CIAC" patch="1" adv="1">G-02</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.3c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1587" published="1999-12-31" name="CVE-1999-1587" modified="2011-03-07" discovered="1996-08-30" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">/usr/ucb/ps in Sun Microsystems Solaris 8 and 9, and certain earlier releases, allows local users to view the environment variables and values of arbitrary processes via the -e option.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25460" source="XF" patch="1">solaris-ps-information-disclosure(25460)</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102215-1" source="SUNALERT" patch="1">102215</ref>
      <ref url="http://securitytracker.com/id?1015833" source="SECTRACK" patch="1">1015833</ref>
      <ref url="http://secunia.com/advisories/19426" source="SECUNIA" patch="1" adv="1">19426</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1123" source="VUPEN">ADV-2006-1123</ref>
      <ref url="http://www.sunmanagers.org/archives/1996/1383.html" source="MISC">http://www.sunmanagers.org/archives/1996/1383.html</ref>
      <ref url="http://www.securityfocus.com/bid/19662" source="BID">19662</ref>
      <ref url="http://www.osvdb.org/24200" source="OSVDB">24200</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1470" source="OVAL" sig="1">oval:org.mitre.oval:def:1470</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="8.0" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1588" published="1999-12-31" name="CVE-1999-1588" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in nlps_server in Sun Solaris x86 2.4, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code as root via a long string beginning with "NLPS:002:002:" to the listen (aka System V listener) port, TCP port 2766.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/data/vulnerabilities/exploits/nlps_server.c" source="MISC">http://www.securityfocus.com/data/vulnerabilities/exploits/nlps_server.c</ref>
      <ref url="http://www.securityfocus.com/bid/2319" source="BID">2319</ref>
      <ref url="http://security-protocols.com/sploits/unsorted_exploits/nlps_server.c" source="MISC">http://security-protocols.com/sploits/unsorted_exploits/nlps_server.c</ref>
      <ref url="http://lsd-pl.net/files/get?SOLARIS/solx86_nlps_server" source="MISC">http://lsd-pl.net/files/get?SOLARIS/solx86_nlps_server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1589" published="1999-12-31" name="CVE-1999-1589" modified="2008-09-05" discovered="1992-05-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unspecified vulnerability in crontab in IBM AIX 3.2 allows local users to gain root privileges via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-1992-10.html" source="CERT" patch="1">CA-1992-10</ref>
      <ref url="http://www.securityfocus.com/bid/357" source="BID" patch="1">357</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="1.2.1" />
        <vers num="1.3" />
        <vers num="2.2.1" />
        <vers num="3.1" />
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="1999-1590" published="1999-12-31" name="CVE-1999-1590" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:N/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Muhammad A. Muquit wwwcount (Count.cgi) 2.3 allows remote attackers to read arbitrary GIF files via ".." sequences in the image parameter, a different vulnerability than CVE-1999-0021.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://seclists.org/bugtraq/1997/Oct/0058.html" source="BUGTRAQ" adv="1">19971010 Security flaw in Count.cgi (wwwcount)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wwwcount" name="wwwcount">
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1591" published="1999-12-31" name="CVE-1999-1591" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Microsoft Internet Information Services (IIS) server 4.0 SP4, without certain hotfixes released for SP4, does not require authentication credentials under certain conditions, which allows remote attackers to bypass authentication requirements, as demonstrated by connecting via Microsoft Visual InterDev 6.0.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/190" source="BID">190</ref>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/1998-1999/msg00277.html" source="NTBUGTRAQ">19990119 Re: IIS4.0 and Visual Interdev</ref>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/1998-1999/msg00276.html" source="NTBUGTRAQ">19990118 IIS4.0 and Visual Interdev</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="visual_interdev">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1592" published="1999-12-31" name="CVE-1999-1592" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in sendmail 5, as installed on Sun SunOS 4.1.3_U1 and 4.1.4, have unspecified attack vectors and impact.  NOTE: this might overlap CVE-1999-0129.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/243" source="BID" patch="1">243</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-22-00159-1" source="SUN">00159</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sendmail" name="sendmail">
        <vers num="5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="1999-1593" published="2009-01-14" name="CVE-1999-1593" modified="2009-01-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Windows Internet Naming Service (WINS) allows remote attackers to cause a denial of service (connectivity loss) or steal credentials via a 1Ch registration that causes WINS to change the domain controller to point to a malicious server.  NOTE: this problem may be limited when Windows 95/98 clients are used, or if the primary domain controller becomes unavailable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www2.sans.org/reading_room/whitepapers/win2k/185.php" source="MISC">https://www2.sans.org/reading_room/whitepapers/win2k/185.php</ref>
      <ref url="http://www.securityfocus.com/bid/2221" source="BID">2221</ref>
      <ref url="http://seclists.org/bugtraq/2001/Jan/0298.html" source="BUGTRAQ">20010119 Re: Invalid WINS entries</ref>
      <ref url="http://seclists.org/bugtraq/2001/Jan/0289.html" source="BUGTRAQ">20010118 Re: Invalid WINS entries</ref>
      <ref url="http://seclists.org/bugtraq/2001/Jan/0276.html" source="BUGTRAQ">20010117 Re: Invalid WINS entries</ref>
      <ref url="http://seclists.org/bugtraq/2001/Jan/0274.html" source="BUGTRAQ">20010117 Re: Invalid WINS entries</ref>
      <ref url="http://seclists.org/bugtraq/2001/Jan/0271.html" source="BUGTRAQ">20010118 Re: Invalid WINS entries</ref>
      <ref url="http://seclists.org/bugtraq/2001/Jan/0269.html" source="BUGTRAQ">20010117 Re: Invalid WINS entries</ref>
      <ref url="http://seclists.org/bugtraq/2001/Jan/0264.html" source="BUGTRAQ">20010117 Invalid WINS entries</ref>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/1998-1999/msg00371.html" source="NTBUGTRAQ">19990302 NT Domain DoS and Security Exploit with SAMBA Server</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0001" published="1999-12-23" name="CVE-2000-0001" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">RealMedia server allows remote attackers to cause a denial of service via a long ramgen request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/888" source="BID">888</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realserver">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0002" published="1999-12-22" name="CVE-2000-0002" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in ZBServer Pro 1.50 allows remote attackers to execute commands via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=36B0596E.8D111D66@teleline.es" source="BUGTRAQ">20000128 ZBServer 1.50-r1x exploit (WinNT)</ref>
      <ref url="http://www.securityfocus.com/bid/889" source="BID">889</ref>
      <ref url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind9912&amp;L=NTBUGTRAQ&amp;P=R3556" source="NTBUGTRAQ">19991223 Local / Remote GET Buffer Overflow Vulnerability in ZBServer 1.5 Pro Edition for Win98/NT</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94598388530358&amp;w=2" source="BUGTRAQ">19991223 Local / Remote GET Buffer Overflow Vulnerability in ZBServer 1.5 Pro Edition for Win98/NT</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zbsoft" name="zbserver">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0003" published="1999-12-30" name="CVE-2000-0003" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in UnixWare rtpm program allows local users to gain privileges via a long environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94908470928258&amp;w=2" source="BUGTRAQ">20000127 New SCO patches...</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="unixware">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0004" published="1999-12-01" name="CVE-2000-0004" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ZBServer Pro allows remote attackers to read source code for executable files by inserting a . (dot) into the URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind9912&amp;L=NTBUGTRAQ&amp;P=R3556" source="NTBUGTRAQ">19991223 Local / Remote GET Buffer Overflow Vulnerability in ZBServer 1.5 Pro Edition for Win98/NT</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94606572912422&amp;w=2" source="BUGTRAQ">19991223 Re: Local / Remote GET Buffer Overflow Vulnerability in ZBServer 1.5 Pro Edition for Win98/NT</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zbsoft" name="zbserver">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0005" published="1999-01-02" name="CVE-2000-0005" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">HP-UX aserver program allows local users to gain privileges via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5635" source="OVAL">oval:org.mitre.oval:def:5635</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="aserver">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="9000">
        <vers num="7_800" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.00" />
        <vers num="10.01" />
        <vers num="10.08" />
        <vers num="10.09" />
        <vers num="10.10" />
        <vers num="10.16" />
        <vers num="10.20" />
        <vers num="10.24" />
        <vers num="10.30" />
        <vers num="10.34" />
        <vers num="11.00" />
        <vers num="7.00" />
        <vers num="7.02" />
        <vers num="7.04" />
        <vers num="7.06" />
        <vers num="7.08" />
        <vers num="8.00" />
        <vers num="8.01" />
        <vers num="8.02" />
        <vers num="8.04" />
        <vers num="8.05" />
        <vers num="8.06" />
        <vers num="8.07" />
        <vers num="8.08" />
        <vers num="8.09" />
        <vers num="9.00" />
        <vers num="9.01" />
        <vers num="9.03" />
        <vers num="9.04" />
        <vers num="9.05" />
        <vers num="9.06" />
        <vers num="9.07" />
        <vers num="9.08" />
        <vers num="9.09" />
        <vers num="9.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0006" published="1999-12-25" name="CVE-2000-0006" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="1.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">strace allows local users to read arbitrary files via memory mapped file names.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4554.php" source="XF" adv="1">linux-strace(4554)</ref>
      <ref url="http://online.securityfocus.com/archive/1/39831" source="BUGTRAQ">19991225 strace can lie</ref>
    </refs>
    <vuln_soft>
      <prod vendor="paul_kranenburg" name="strace">
        <vers num="" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.3.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0007" published="1999-12-29" name="CVE-2000-0007" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Trend Micro PC-Cillin does not restrict access to its internal proxy port, allowing remote attackers to conduct a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4491.php" source="XF" adv="1">pccillin-proxy-remote-dos(4491)</ref>
      <ref url="http://www.securityfocus.com/bid/1740" source="BID">1740</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="pc-cillin">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0008" published="1999-12-26" name="CVE-2000-0008" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">FTPPro allows local users to read sensitive information, which is stored in plain text.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="1st_choice_software" name="ftppro">
        <vers num="7.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0009" published="1999-12-29" name="CVE-2000-0009" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The bna_pass program in Optivity NETarchitect uses the PATH environmental variable for finding the "rm" program, which allows local users to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/907" source="BID">907</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nortel" name="optivity_net_architect">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0010" published="1999-12-26" name="CVE-2000-0010" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">WebWho+ whois.cgi program allows remote attackers to execute commands via shell metacharacters in the TLD parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="tony_greenwood" name="webwho+">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0011" published="1999-12-31" name="CVE-2000-0011" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in AnalogX SimpleServer:WWW HTTP server allows remote attackers to execute commands via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.analogx.com/contents/download/network/sswww.htm" source="MISC">http://www.analogx.com/contents/download/network/sswww.htm</ref>
      <ref url="http://www.securityfocus.com/bid/906" source="BID">906</ref>
      <ref url="http://www.osvdb.org/1184" source="OSVDB">1184</ref>
    </refs>
    <vuln_soft>
      <prod vendor="analogx" name="simpleserver_www">
        <vers num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0012" published="1999-12-27" name="CVE-2000-0012" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in w3-msql CGI program in miniSQL package allows remote attackers to execute commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/898" source="BID">898</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hughes" name="msql">
        <vers num="2.0.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0013" published="1999-12-31" name="CVE-2000-0013" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">IRIX soundplayer program allows local users to gain privileges by including shell metacharacters in a .wav file, which is executed via the midikeys program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/909" source="BID">909</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0014" published="1999-12-28" name="CVE-2000-0014" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denial of service in Savant web server via a null character in the requested URL.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/897" source="BID">897</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michael_lamont" name="savant_webserver">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0015" published="1999-12-31" name="CVE-2000-0015" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">CascadeView TFTP server allows local users to gain privileges via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/910" source="BID">910</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ascend" name="cascadeview_ux">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0016" published="1999-10-01" name="CVE-2000-0016" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Internet Anywhere POP3 Mail Server allows remote attackers to cause a denial of service or execute commands via a long username.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/730" source="BID">730</ref>
    </refs>
    <vuln_soft>
      <prod vendor="true_north" name="internet_anywhere_mail_server">
        <vers num="2.3" />
        <vers num="2.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0017" published="1999-12-21" name="CVE-2000-0017" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Linux linuxconf package allows remote attackers to gain root privileges via a long parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0018" published="1999-12-22" name="CVE-2000-0018" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">wmmon in FreeBSD allows local users to gain privileges via the .wmmonrc configuration file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/885" source="BID">885</ref>
      <ref url="http://www.osvdb.org/1169" source="OSVDB">1169</ref>
    </refs>
    <vuln_soft>
      <prod vendor="windowmaker" name="wmmon">
        <vers num="1.0b2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0019" published="1999-03-04" name="CVE-2000-0019" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">IMail POP3 daemon uses weak encryption, which allows local users to read files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="ipswitch" name="imail">
        <vers num="2006" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0020" published="1999-12-20" name="CVE-2000-0020" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">DNS PRO allows remote attackers to conduct a denial of service via a large number of connections.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="man_and_mice" name="dns_pro">
        <vers num="5.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0021" published="1999-12-01" name="CVE-2000-0021" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Lotus Domino HTTP server allows remote attackers to determine the real path of the server via a request to a non-existent script in /cgi-bin.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/881" source="BID">881</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lotus" name="domino_server">
        <vers num="4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0022" published="1999-12-21" name="CVE-2000-0022" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Lotus Domino HTTP server does not properly disable anonymous access for the cgi-bin directory.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/881" source="BID">881</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lotus" name="domino_server">
        <vers num="4.6" />
        <vers num="4.6.x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0023" published="1999-12-21" name="CVE-2000-0023" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Lotus Domino HTTP server allows remote attackers to cause a denial of service via a long URL.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/881" source="BID">881</ref>
      <ref url="http://www.osvdb.org/51" source="OSVDB">51</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lotus" name="domino_server">
        <vers num="4.6" />
        <vers num="4.6.x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0024" published="1999-12-21" name="CVE-2000-0024" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape characters, aka the "Escape Character Parsing" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q246401" source="MSKB">Q246401</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-061.asp" source="MS">MS99-061</ref>
      <ref url="http://www.acrossecurity.com/aspr/ASPR-1999-11-10-1-PUB.txt" source="MISC">http://www.acrossecurity.com/aspr/ASPR-1999-11-10-1-PUB.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
      </prod>
      <prod vendor="microsoft" name="site_server">
        <vers num="3.0" />
      </prod>
      <prod vendor="microsoft" name="site_server_commerce">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0025" published="1999-12-21" name="CVE-2000-0025" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IIS 4.0 and Site Server 3.0 allow remote attackers to read source code for ASP files if the file is in a virtual directory whose name includes extensions such as .com, .exe, .sh, .cgi, or .dll, aka the "Virtual Directory Naming" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q238606" source="MSKB">Q238606</ref>
      <ref url="http://www.osvdb.org/8098" source="OSVDB">8098</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-058.mspx" source="MS">MS99-058</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
      </prod>
      <prod vendor="microsoft" name="site_server">
        <vers num="3.0" />
      </prod>
      <prod vendor="microsoft" name="site_server_commerce">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0026" published="1999-12-21" name="CVE-2000-0026" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in UnixWare i2odialogd daemon allows remote attackers to gain root access via a long username/password authorization string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/876" source="BID">876</ref>
      <ref url="http://www.osvdb.org/6310" source="OSVDB">6310</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94606167110764&amp;w=2" source="BUGTRAQ">19991223 FYI, SCO Security patches available.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="windowmaker" name="wmmon">
        <vers num="1.0b2" />
      </prod>
      <prod vendor="sco" name="unixware">
        <vers num="7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0027" published="1999-12-27" name="CVE-2000-0027" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">IBM Network Station Manager NetStation allows local users to gain privileges via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/900" source="BID">900</ref>
      <ref url="http://www.securityfocus.com/archive/1/39962" source="BUGTRAQ">19991227 IBM NetStation/UnixWare local root exploit</ref>
      <ref url="http://www.iss.net/security_center/static/5381.php" source="XF">ibm-netstat-race-condition(5381)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="network_station_manager">
        <vers num="2.0r1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0028" published="1999-12-23" name="CVE-2000-0028" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the external.NavigateAndFind function.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="3.0" />
        <vers num="3.0.2" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="4.0" edition="a_mac_os" />
        <vers num="4.0.1" edition="sp2" />
        <vers num="4.1" />
        <vers num="4.5" />
        <vers num="5.0" />
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0029" published="1999-12-27" name="CVE-2000-0029" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">UnixWare pis and mkpis commands allow local users to gain privileges via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/901" source="BID">901</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94780294009285&amp;w=2" source="BUGTRAQ">20000113 Info on some security holes reported against SCO Unixware.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="unixware">
        <vers num="7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0030" published="1999-12-22" name="CVE-2000-0030" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Solaris dmispd dmi_cmd allows local users to fill up restricted disk space by adding files to the /var/dmi/db database.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/878" source="BID">878</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0031" published="2000-10-20" name="CVE-2000-0031" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">The initscripts package in Red Hat Linux allows local users to gain privileges via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="6.0" />
        <vers num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0032" published="1999-12-22" name="CVE-2000-0032" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Solaris dmi_cmd allows local users to crash the dmispd daemon by adding a malformed file to the /var/dmi/db database.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/878" source="BID">878</ref>
      <ref url="http://www.osvdb.org/7582" source="OSVDB">7582</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0033" published="1999-12-27" name="CVE-2000-0033" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">InterScan VirusWall SMTP scanner does not properly scan messages with malformed attachments.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/899" source="BID">899</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="interscan_viruswall">
        <vers num="3.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0034" published="1999-12-22" name="CVE-2000-0034" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Netscape 4.7 records user passwords in the preferences.js file during an IMAP or POP session, even if the user has not enabled "remember passwords."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="netscape" name="communicator">
        <vers num="4.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0035" published="1999-12-28" name="CVE-2000-0035" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">resend command in Majordomo allows local users to gain privileges via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/902" source="BID">902</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94780294009285&amp;w=2" source="BUGTRAQ">20000113 Info on some security holes reported against SCO Unixware.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="great_circle_associates" name="majordomo">
        <vers prev="1" num="1.94.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0036" published="1999-12-22" name="CVE-2000-0036" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Outlook Express 5 for Macintosh downloads attachments to HTML mail without prompting the user, aka the "HTML Mail Attachment" vulnerability.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-060.asp" source="MS">MS99-060</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q249082" source="MSKB">Q249082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.5" edition="" />
        <vers num="4.5" edition=":macintosh" />
      </prod>
      <prod vendor="microsoft" name="outlook_express">
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":macos" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0037" published="1999-12-28" name="CVE-2000-0037" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Majordomo wrapper allows local users to gain privileges by specifying an alternate configuration file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/903" source="BID">903</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-005.html" source="REDHAT">RHSA-2000:005</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94780294009285&amp;w=2" source="BUGTRAQ">20000113 Info on some security holes reported against SCO Unixware.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="great_circle_associates" name="majordomo">
        <vers num="1.94.4" />
        <vers num="1.94.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0038" published="1999-12-23" name="CVE-2000-0038" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">glFtpD includes a default glftpd user account with a default password and a UID of 0.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="glftpd" name="glftpd">
        <vers prev="1" num="1.17.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0039" published="1999-12-29" name="CVE-2000-0039" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">AltaVista search engine allows remote attackers to read files above the document root via a .. (dot dot) in the query.cgi CGI program.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/896" source="BID">896</ref>
      <ref url="http://www.osvdb.org/15" source="OSVDB">15</ref>
    </refs>
    <vuln_soft>
      <prod vendor="altavista" name="search_intranet">
        <vers num="2.0b" />
        <vers num="2.3a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0040" published="1999-12-23" name="CVE-2000-0040" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">glFtpD allows local users to gain privileges via metacharacters in the SITE ZIPCHK command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="glftpd" name="glftpd">
        <vers num="1.17.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0041" published="1999-12-28" name="CVE-2000-0041" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Macintosh systems generate large ICMP datagrams in response to malformed datagrams, allowing them to be used as amplifiers in a flood attack.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/890" source="BID">890</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os">
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0042" published="1999-12-29" name="CVE-2000-0042" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in CSM mail server allows remote attackers to cause a denial of service or execute commands via a long HELO command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/895" source="BID">895</ref>
    </refs>
    <vuln_soft>
      <prod vendor="csm" name="mail_server">
        <vers num="1999-07b" />
        <vers num="1999-07f" />
        <vers num="1999-07g" />
        <vers num="1999-07h" />
        <vers num="1999-07i" />
        <vers num="1999-07m" />
        <vers num="2000-01a" />
        <vers num="2000.8.a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0043" published="1999-12-30" name="CVE-2000-0043" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in CamShot WebCam HTTP server allows remote attackers to execute commands via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/905" source="BID">905</ref>
    </refs>
    <vuln_soft>
      <prod vendor="camshot" name="webcam_http_server">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0044" published="2000-01-06" name="CVE-2000-0044" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Macros in War FTP 1.70 and 1.67b2 allow local or remote attackers to read arbitrary files or execute commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/919" source="BID">919</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jgaa" name="warftpd">
        <vers prev="1" num="1.67b2" />
        <vers num="1.70b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0045" published="2000-01-11" name="CVE-2000-0045" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">MySQL allows local users to modify passwords for arbitrary MySQL users via the GRANT privilege.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/926" source="BID">926</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="3.22.27" />
        <vers num="3.22.29" />
        <vers num="3.23.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0046" published="2000-01-10" name="CVE-2000-0046" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in ICQ 99b 1.1.1.1 client allows remote attackers to execute commands via a malformed URL within an ICQ message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/929" source="BID">929</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mirabilis" name="icq">
        <vers num="0.99b_1.1.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0047" published="1999-10-01" name="CVE-2000-0047" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Yahoo Pager/Messenger client allows remote attackers to cause a denial of service via a long URL within a message.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="yahoo" name="pager">
        <vers num="733" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0048" published="2000-01-12" name="CVE-2000-0048" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">get_it program in Corel Linux Update allows local users to gain root access by specifying an alternate PATH for the cp program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://linux.corel.com/support/clos_patch1.htm" source="CONFIRM">http://linux.corel.com/support/clos_patch1.htm</ref>
      <ref url="http://www.securityfocus.com/bid/928" source="BID">928</ref>
    </refs>
    <vuln_soft>
      <prod vendor="corel" name="linux">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0049" published="2000-01-04" name="CVE-2000-0049" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Winamp client allows remote attackers to execute commands via a long entry in a .pls file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/925" source="BID">925</ref>
      <ref url="http://www.osvdb.org/12022" source="OSVDB">12022</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nullsoft" name="winamp">
        <vers num="2.0" />
        <vers num="2.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0050" published="2000-01-04" name="CVE-2000-0050" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The Allaire Spectra Webtop allows authenticated users to access other Webtop sections by specifying explicit URLs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.allaire.com/handlers/index.cfm?ID=13976&amp;Method=Full" source="ALLAIRE" patch="1" adv="1">ASB00-01</ref>
      <ref url="http://www.securityfocus.com/bid/915" source="BID">915</ref>
    </refs>
    <vuln_soft>
      <prod vendor="allaire" name="spectra">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0051" published="2000-01-04" name="CVE-2000-0051" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Allaire Spectra Configuration Wizard allows remote attackers to cause a denial of service by repeatedly resubmitting data collections for indexing via a URL.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.allaire.com/handlers/index.cfm?ID=13977&amp;Method=Full" source="ALLAIRE" patch="1" adv="1">ASB00-02</ref>
      <ref url="http://www.securityfocus.com/bid/916" source="BID">916</ref>
    </refs>
    <vuln_soft>
      <prod vendor="allaire" name="spectra">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0052" published="2000-01-04" name="CVE-2000-0052" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Red Hat userhelper program in the usermode package allows local users to gain root access via PAM and a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/search.php3?type=2&amp;pattern=linux-pam-userhelper" source="XF">linux-pam-userhelper</ref>
      <ref url="http://www.securityfocus.com/bid/913" source="BID">913</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-001.html" source="REDHAT">RHSA-2000:001</ref>
      <ref url="http://www.l0pht.com/advisories/pam_advisory" source="L0PHT">20000104 PamSlam</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="6.0" />
        <vers num="6.1" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":i386" />
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":i386" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux">
        <vers num="3.5b2" />
        <vers num="4.2" />
        <vers num="4.4" />
        <vers num="6.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0053" published="2000-01-04" name="CVE-2000-0053" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Microsoft Commercial Internet System (MCIS) IMAP server allows remote attackers to cause a denial of service via a malformed IMAP request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-001.asp" source="MS">MS00-001</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q246731" source="MSKB">Q246731</ref>
      <ref url="http://www.securityfocus.com/bid/912" source="BID">912</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="commercial_internet_system">
        <vers num="2.0" />
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0054" published="1999-01-03" name="CVE-2000-0054" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">search.cgi in the SolutionScripts Home Free package allows remote attackers to view directories via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/921" source="BID">921</ref>
    </refs>
    <vuln_soft>
      <prod vendor="solution_scripts" name="home_free">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0055" published="2000-01-06" name="CVE-2000-0055" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Solaris chkperm command allows local users to gain root access via a long -n option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/918" source="BID">918</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.3" />
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":ppc" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="2.6" edition="hw3" />
        <vers num="2.6" edition="hw3:x86" />
        <vers num="2.6" edition="hw5" />
        <vers num="2.6" edition="hw5:x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0056" published="2000-01-05" name="CVE-2000-0056" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IMail IMONITOR status.cgi CGI script allows remote attackers to cause a denial of service with many calls to status.cgi.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/914" source="BID">914</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="imail">
        <vers num="5.0.8" />
        <vers num="6.0" />
        <vers num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0057" published="2000-01-04" name="CVE-2000-0057" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cold Fusion CFCACHE tag places temporary cache files within the web document root, allowing remote attackers to obtain sensitive system information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.allaire.com/handlers/index.cfm?ID=13978&amp;Method=Full" source="ALLAIRE" patch="1" adv="1">ASB00-03</ref>
      <ref url="http://www.securityfocus.com/bid/917" source="BID">917</ref>
    </refs>
    <vuln_soft>
      <prod vendor="allaire" name="coldfusion_server">
        <vers num="4.0" />
        <vers num="4.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0058" published="2000-01-05" name="CVE-2000-0058" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Network HotSync program in Handspring Visor does not have authentication, which allows remote attackers to retrieve email and files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/920" source="BID">920</ref>
      <ref url="http://www.security-express.com/archives/bugtraq/2000-01/0085.html" source="BUGTRAQ">20000105 Handspring Visor Network HotSync Security Hole</ref>
    </refs>
    <vuln_soft>
      <prod vendor="handspring" name="visor_network_hotsync">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0059" published="2000-01-04" name="CVE-2000-0059" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">PHP3 with safe_mode enabled does not properly filter shell metacharacters from commands that are executed by popen, which could allow remote attackers to execute commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/911" source="BID">911</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0060" published="1999-12-27" name="CVE-2000-0060" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in aVirt Rover POP3 server 1.1 allows remote attackers to cause a denial of service via a long user name.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/894" source="BID">894</ref>
      <ref url="http://www.iss.net/security_center/static/3765.php" source="XF">avirt-rover-pop3-dos(3765)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94647711311057&amp;w=2" source="NTBUGTRAQ">19991227 Local / Remote Remote DoS Attack in Rover POP3 Server V1.1 NT From aVirt</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94633851427858&amp;w=2" source="BUGTRAQ">19991227 Local / Remote Remote DoS Attack in Rover POP3 Server V1.1 NT From aVirt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avirt" name="rover">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0061" published="2000-01-07" name="CVE-2000-0061" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Internet Explorer 5 does not modify the security zone for a document that is being loaded into a window until after the document has been loaded, which could allow remote attackers to execute Javascript in a different security context while the document is loading.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/923" source="BID">923</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="5.0" />
        <vers num="5.01" />
        <vers num="5.5" edition="preview" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0062" published="2000-01-04" name="CVE-2000-0062" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The DTML implementation in the Z Object Publishing Environment (Zope) allows remote attackers to conduct unauthorized activities.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000104222219.B41650@schvin.net" source="BUGTRAQ">20000104 [petrilli@digicool.com: [Zope] SECURITY ALERT]</ref>
      <ref url="http://www.securityfocus.com/bid/922" source="BID">922</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zope" name="zope">
        <vers num="1.10.3" />
        <vers num="2.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0063" published="2000-01-17" name="CVE-2000-0063" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">cgiproc CGI script in Nortel Contivity HTTP server allows remote attackers to read arbitrary files by specifying the filename in a parameter to the script.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/938" source="BID">938</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nortel" name="contivity">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0064" published="2000-01-17" name="CVE-2000-0064" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">cgiproc CGI script in Nortel Contivity HTTP server allows remote attackers to cause a denial of service via a malformed URL that includes shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/938" source="BID">938</ref>
      <ref url="http://www.osvdb.org/7583" source="OSVDB">7583</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nortel" name="contivity">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0065" published="2000-01-17" name="CVE-2000-0065" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in InetServ 3.0 allows remote attackers to execute commands via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="avtronics" name="inetserv">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0066" published="2000-01-13" name="CVE-2000-0066" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WebSite Pro allows remote attackers to determine the real pathname of webdirectories via a malformed URL request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="oreilly" name="website_professional">
        <vers num="2.3.18" />
        <vers num="2.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0067" published="2000-01-11" name="CVE-2000-0067" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">CyberCash Merchant Connection Kit (MCK) allows local users to modify files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="cybercash" name="merchant_connection_kit">
        <vers num="3.2.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0068" published="1999-12-14" name="CVE-2000-0068" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">daynad program in Intel InBusiness E-mail Station does not require authentication, which allows remote attackers to modify its configuration, delete files, or read mail.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94704437920965&amp;w=2" source="BUGTRAQ">20000104 [rootshell] Security Bulletin #27</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intel" name="inbusiness_email_station">
        <vers prev="1" num="1.04" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0069" published="2000-01-01" name="CVE-2000-0069" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The recover program in Solstice Backup allows local users to restore sensitive files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="sun" name="solstice_backup">
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0070" published="2000-01-12" name="CVE-2000-0070" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">NtImpersonateClientOfPort local procedure call in Windows NT 4.0 allows local users to gain privileges, aka "Spoofed LPC Port Request."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.bindview.com/security/advisory/adv_NtImpersonate.html" source="BINDVIEW" patch="1" adv="1">20000113 Local Promotion Vulnerability in Windows NT 4</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q247869" source="MSKB">Q247869</ref>
      <ref url="http://xforce.iss.net/search.php3?type=2&amp;pattern=nt-spoofed-lpc-port" source="XF">nt-spoofed-lpc-port</ref>
      <ref url="http://www.securityfocus.com/bid/934" source="BID">934</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-003.asp" source="MS">MS00-003</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0071" published="2000-01-11" name="CVE-2000-0071" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non-existent files with .ida or .idq extensions.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94780058006791&amp;w=2" source="BUGTRAQ">20000113 SV: IIS still revealing paths for web directories</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94770020309953&amp;w=2" source="BUGTRAQ">20000111 IIS still revealing paths for web directories</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0072" published="2000-01-17" name="CVE-2000-0072" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Visual Casel (Vcasel) does not properly prevent users from executing files, which allows local users to use a relative pathname to specify an alternate file which has an approved name and possibly gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/937" source="BID">937</ref>
      <ref url="http://www.iss.net/security_center/static/3867.php" source="XF">vcasel-filename-trusting(3867)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94823061421676&amp;w=2" source="BUGTRAQ">20000118 Warning: VCasel security hole.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="computer_power_solutions" name="visual_casel">
        <vers num="3.0" />
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0073" published="1999-11-17" name="CVE-2000-0073" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Rich Text Format (RTF) reader allows attackers to cause a denial of service via a malformed control word.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-005.asp" source="MS">MS00-005</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q249973" source="MSKB">Q249973</ref>
      <ref url="http://xforce.iss.net/search.php3?type=2&amp;pattern=win-malformed-rtf-control-word" source="XF">win-malformed-rtf-control-word</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0074" published="2000-01-11" name="CVE-2000-0074" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PowerScripts PlusMail CGI program allows remote attackers to execute commands via a password file with improper permissions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="powerscripts" name="plusmail">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0075" published="2000-01-13" name="CVE-2000-0075" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Super Mail Transfer Package (SMTP), later called MsgCore, has a memory leak which allows remote attackers to cause a denial of service by repeating multiple HELO, MAIL FROM, RCPT TO, and DATA commands in the same session.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/930" source="BID">930</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nosque" name="msgcore">
        <vers num="1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0076" published="1999-12-30" name="CVE-2000-0076" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">nviboot boot script in the Debian nvi package allows local users to delete files via malformed entries in vi.recover.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1439" source="BID">1439</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94709988232618&amp;w=2" source="BUGTRAQ">19991230 vibackup.sh</ref>
    </refs>
    <vuln_soft>
      <prod vendor="berkeley" name="nvi">
        <vers num="1.7x" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0077" published="2000-01-02" name="CVE-2000-0077" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The October 1998 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the ps and grep commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5549" source="OVAL">oval:org.mitre.oval:def:5549</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10" />
        <vers num="11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0078" published="2000-01-02" name="CVE-2000-0078" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The June 1999 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the awk command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5728" source="OVAL">oval:org.mitre.oval:def:5728</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10" />
        <vers num="11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0079" published="2000-01-18" name="CVE-2000-0079" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The W3C CERN httpd HTTP server allows remote attackers to determine the real pathnames of some commands via a request for a nonexistent URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/936" source="BID">936</ref>
    </refs>
    <vuln_soft>
      <prod vendor="w3c" name="cern_httpd">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0080" published="2000-01-10" name="CVE-2000-0080" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">AIX techlibss allows local users to overwrite files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/931" source="BID">931</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94757136413681&amp;w=2" source="BUGTRAQ">20000110 2nd attempt: AIX techlibss follows links</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0081" published="2000-01-10" name="CVE-2000-0081" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Hotmail does not properly filter JavaScript code from a user's mailbox, which allows a remote attacker to execute the code by using hexadecimal codes to specify the javascript: protocol, e.g. j&amp;#x41;vascript.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="hotmail">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0082" published="2000-01-02" name="CVE-2000-0082" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WebTV email client allows remote attackers to force the client to send email without the user's knowledge via HTML.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.wired.com/news/technology/0,1282,33420,00.html" source="MISC" adv="1">http://www.wired.com/news/technology/0,1282,33420,00.html</ref>
      <ref url="http://net4tv.com/voice/story.cfm?StoryID=1823" source="MISC" adv="1">http://net4tv.com/voice/story.cfm?StoryID=1823</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="webtv">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0083" published="2000-04-18" name="CVE-2000-0083" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">HP asecure creates the Audio Security File audio.sec with insecure permissions, which allows local users to cause a denial of service or gain additional privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/advisory.html?id=2031" source="HP">HPSBUX0001-109</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10" />
        <vers num="11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0084" published="2000-01-06" name="CVE-2000-0084" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CuteFTP uses weak encryption to store password information in its tree.dat file.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="globalscape" name="cuteftp">
        <vers prev="1" num="2.x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0085" published="2000-01-04" name="CVE-2000-0085" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Hotmail does not properly filter JavaScript code from a user's mailbox, which allows a remote attacker to execute code via the LOWSRC or DYNRC parameters in the IMG tag.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="hotmail">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0086" published="2000-01-18" name="CVE-2000-0086" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Netopia Timbuktu Pro sends user IDs and passwords in cleartext, which allows remote attackers to obtain them via sniffing.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/935" source="BID">935</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netopia" name="timbuktu_pro">
        <vers num="2.0" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0087" published="2000-01-12" name="CVE-2000-0087" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Netscape Mail Notification (nsnotify) utility in Netscape Communicator uses IMAP without SSL, even if the user has set a preference for Communicator to use an SSL connection, allowing a remote attacker to sniff usernames and passwords in plaintext.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.iss.net/security_center/static/4385.php" source="XF">netscape-mail-notify-plaintext(4385)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94790377622943&amp;w=2" source="BUGTRAQ">20000113 Misleading sense of security in Netscape</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="communicator">
        <vers num="4.7" />
      </prod>
      <prod vendor="netscape" name="navigator">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0088" published="2000-01-20" name="CVE-2000-0088" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the conversion utilities for Japanese, Korean and Chinese Word 5 documents allows an attacker to execute commands, aka the "Malformed Conversion Data" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/946" source="BID">946</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-002.mspx" source="MS">MS00-002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="" />
        <vers num="2000" edition=":" />
        <vers num="2000" edition="::korean" />
        <vers num="2000" edition="::japanese" />
        <vers num="2000" edition="::chinese" />
        <vers num="97" edition="" />
        <vers num="97" edition=":" />
        <vers num="97" edition="::chinese" />
        <vers num="97" edition="::korean" />
        <vers num="97" edition="::japanese" />
      </prod>
      <prod vendor="microsoft" name="office_converter_pack">
        <vers num="2000.0" />
      </prod>
      <prod vendor="microsoft" name="powerpoint">
        <vers num="2000" edition="" />
        <vers num="2000" edition=":" />
        <vers num="2000" edition="::chinese" />
        <vers num="2000" edition="::korean" />
        <vers num="2000" edition="::japanese" />
        <vers num="97" edition="" />
        <vers num="97" edition=":" />
        <vers num="97" edition="::chinese" />
        <vers num="97" edition="::korean" />
        <vers num="97" edition="::japanese" />
      </prod>
      <prod vendor="microsoft" name="word">
        <vers num="2000" edition="" />
        <vers num="2000" edition=":" />
        <vers num="2000" edition="::chinese" />
        <vers num="2000" edition="::japanese" />
        <vers num="2000" edition="::korean" />
        <vers num="97" edition="" />
        <vers num="97" edition=":" />
        <vers num="97" edition="::japanese" />
        <vers num="97" edition="::korean" />
        <vers num="97" edition="::chinese" />
        <vers num="98" edition="" />
        <vers num="98" edition=":" />
        <vers num="98" edition="::korean" />
        <vers num="98" edition="::chinese" />
        <vers num="98" edition="::japanese" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0089" published="2000-02-04" name="CVE-2000-0089" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The rdisk utility in Microsoft Terminal Server Edition and Windows NT 4.0 stores registry hive information in a temporary file with permissions that allow local users to read it, aka the "RDISK Registry Enumeration File" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q249108" source="MSKB">Q249108</ref>
      <ref url="http://www.securityfocus.com/bid/947" source="BID">947</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-004.mspx" source="MS">MS00-004</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:enterprise" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0090" published="2000-01-17" name="CVE-2000-0090" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">VMWare 1.1.2 allows local users to cause a denial of service via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/943" source="BID">943</ref>
      <ref url="http://www.osvdb.org/1205" source="OSVDB">1205</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="workstation">
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0091" published="2000-01-21" name="CVE-2000-0091" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in vchkpw/vpopmail POP authentication package allows remote attackers to gain root privileges via a long username or password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.inter7.com/vpopmail/ChangeLog" source="MISC">http://www.inter7.com/vpopmail/ChangeLog</ref>
      <ref url="http://www.inter7.com/vpopmail/" source="MISC">http://www.inter7.com/vpopmail/</ref>
      <ref url="http://www.securityfocus.com/bid/942" source="BID">942</ref>
    </refs>
    <vuln_soft>
      <prod vendor="inter7" name="vpopmail">
        <vers num="vchkpw_3.4.1" />
        <vers num="vchkpw_3.4.11" />
        <vers num="vchkpw_3.4.2" />
        <vers num="vchkpw_3.4.3" />
        <vers num="vchkpw_3.4.4" />
        <vers num="vchkpw_3.4.5" />
        <vers num="vchkpw_3.4.6" />
        <vers num="vchkpw_3.4.7" />
        <vers num="vchkpw_3.4.8" />
        <vers num="vchkpw_3.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0092" published="2000-01-19" name="CVE-2000-0092" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">The BSD make program allows local users to modify files via a symlink attack when the -j option is being used.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:01.make.asc" source="FREEBSD">FreeBSD-SA-00:01</ref>
      <ref url="http://www.securityfocus.com/bid/939" source="BID">939</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.4" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.4.1" edition="" />
        <vers num="1.4.1" edition=":x86" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0093" published="2000-01-21" name="CVE-2000-0093" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">An installation of Red Hat uses DES password encryption with crypt() for the initial password, instead of md5.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0094" published="2000-02-16" name="CVE-2000-0094" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">procfs in BSD systems allows local users to gain root privileges by modifying the /proc/pid/mem interface via a modified file descriptor for stderr.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/3995" source="XF">netbsd-procfs(3995)</ref>
      <ref url="http://www.securityfocus.com/bid/940" source="BID">940</ref>
      <ref url="http://www.osvdb.org/20760" source="OSVDB">20760</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2000-001.txt.asc" source="NETBSD">NetBSD-SA2000-001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0095" published="2000-01-24" name="CVE-2000-0095" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The PMTU discovery procedure used by HP-UX 10.30 and 11.00 for determining the optimum MTU generates large amounts of traffic in response to small packets, allowing remote attackers to cause the system to be used as a packet amplifier.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/advisory.html?id=2041" source="HP">HPSBUX0001-110</ref>
      <ref url="http://www.securityfocus.com/bid/944" source="BID">944</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.30" />
        <vers num="11.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0096" published="2000-01-26" name="CVE-2000-0096" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in qpopper 3.0 beta versions allows local users to gain privileges via a long LIST command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/948" source="BID">948</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qualcomm" name="qpopper">
        <vers num="3.0" />
        <vers num="3.0beta1" />
        <vers num="3.0beta10" />
        <vers num="3.0beta11" />
        <vers num="3.0beta12" />
        <vers num="3.0beta13" />
        <vers num="3.0beta14" />
        <vers num="3.0beta15" />
        <vers num="3.0beta16" />
        <vers num="3.0beta17" />
        <vers num="3.0beta18" />
        <vers num="3.0beta19" />
        <vers num="3.0beta2" />
        <vers num="3.0beta20" />
        <vers num="3.0beta21" />
        <vers num="3.0beta22" />
        <vers num="3.0beta23" />
        <vers num="3.0beta24" />
        <vers num="3.0beta25" />
        <vers num="3.0beta26" />
        <vers num="3.0beta27" />
        <vers num="3.0beta28" />
        <vers num="3.0beta29" />
        <vers num="3.0beta3" />
        <vers num="3.0beta4" />
        <vers num="3.0beta5" />
        <vers num="3.0beta6" />
        <vers num="3.0beta7" />
        <vers num="3.0beta8" />
        <vers num="3.0beta9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0097" published="2000-01-26" name="CVE-2000-0097" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The WebHits ISAPI filter in Microsoft Index Server allows remote attackers to read arbitrary files, aka the "Malformed Hit-Highlighting Argument" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-006.asp" source="MS">MS00-006</ref>
      <ref url="http://www.securityfocus.com/bid/950" source="BID">950</ref>
      <ref url="http://www.osvdb.org/1210" source="OSVDB">1210</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="index_server">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0098" published="2000-01-26" name="CVE-2000-0098" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Index Server allows remote attackers to determine the real path for a web directory via a request to an Internet Data Query file that does not exist.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-006.asp" source="MS">MS00-006</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="index_server">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0099" published="2000-01-18" name="CVE-2000-0099" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in UnixWare ppptalk command allows local users to gain privileges via a long prompt argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94848865112897&amp;w=2" source="BUGTRAQ">20000119 Unixware ppptalk</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="unixware">
        <vers num="7.0.0" />
        <vers num="7.0.1" />
        <vers num="7.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0100" published="1999-12-29" name="CVE-2000-0100" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The SMS Remote Control program is installed with insecure permissions, which allows local users to gain privileges by modifying or replacing the program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-012.asp" source="MS">MS00-012</ref>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/current/0045.html" source="NTBUGTRAQ">20000115 Security Vulnerability with SMS 2.0 Remote Control</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="systems_management_server">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0101" published="2000-02-01" name="CVE-2000-0101" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Make-a-Store OrderPage shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="make-a-store" name="orderpage">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0102" published="2000-02-01" name="CVE-2000-0102" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The SalesCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="salescart" name="salescart">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0103" published="2000-02-01" name="CVE-2000-0103" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The SmartCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="netsmart" name="smartcart">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0104" published="2000-02-01" name="CVE-2000-0104" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Shoptron shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="web_express" name="shoptron">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0105" published="2000-02-01" name="CVE-2000-0105" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Outlook Express 5.01 and Internet Explorer 5.01 allow remote attackers to view a user's email messages via a script that accesses a variable that references subsequent email messages that are read by the client.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/962" source="BID">962</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="outlook_express">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0106" published="2000-02-01" name="CVE-2000-0106" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The EasyCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="easycart" name="easycart">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0107" published="2000-02-01" name="CVE-2000-0107" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Linux apcd program allows local attackers to modify arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/958" source="BID">958</ref>
      <ref url="http://www.debian.org/security/2000/20000201" source="DEBIAN">20000201</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0108" published="2000-02-01" name="CVE-2000-0108" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Intellivend shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="intelligent_vending_systems" name="intellivend">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0109" published="2000-01-31" name="CVE-2000-0109" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The mcsp Client Site Processor system (MultiCSP) in Standard and Poor's ComStock is installed with several accounts that have no passwords or easily guessable default passwords.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="comstock" name="multicsp">
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0110" published="2000-02-01" name="CVE-2000-0110" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The WebSiteTool shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="baron_consulting_group" name="websitetool">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0111" published="2000-01-29" name="CVE-2000-0111" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The RightFax web client uses predictable session numbers, which allows remote attackers to hijack user sessions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/953" source="BID">953</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avt" name="rightfax">
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0112" published="2000-02-02" name="CVE-2000-0112" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The default installation of Debian GNU/Linux uses an insecure Master Boot Record (MBR) which allows a local user to boot from a floppy disk during the installation.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/960" source="BID">960</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94973075614088&amp;w=2" source="BUGTRAQ">20000202 vulnerability in Linux Debian default boot configuration</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.0" edition="r5" />
        <vers num="2.1" />
        <vers num="2.2" edition="" />
        <vers num="2.2" edition=":pre_potato" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0113" published="2000-01-27" name="CVE-2000-0113" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The SyGate Remote Management program does not properly restrict access to its administration service, which allows remote attackers to cause a denial of service, or access network traffic statistics.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.sybergen.com/support/fix.htm" source="CONFIRM">http://www.sybergen.com/support/fix.htm</ref>
      <ref url="http://www.securityfocus.com/bid/952" source="BID">952</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94973281714994&amp;w=2" source="BUGTRAQ">20000203 UPDATE: Sygate 3.11 Port 7323 Telnet Hole</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94952641025328&amp;w=2" source="BUGTRAQ">20000202 SV: SyGate 3.11 Port 7323 / Remote Admin hole</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94934808714972&amp;w=2" source="BUGTRAQ">20000128 SyGate 3.11 Port 7323 / Remote Admin hole</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sybergen" name="sygate">
        <vers num="2.0" />
        <vers num="3.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0114" published="2000-02-02" name="CVE-2000-0114" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Frontpage Server Extensions allows remote attackers to determine the name of the anonymous account via an RPC POST request to shtml.dll in the /_vti_bin/ virtual directory.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="3.0" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0115" published="2000-01-21" name="CVE-2000-0115" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IIS allows local users to cause a denial of service via invalid regular expressions in a Visual Basic script in an ASP page.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0116" published="2000-01-29" name="CVE-2000-0116" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Firewall-1 does not properly filter script tags, which allows remote attackers to bypass the "Strip Script Tags" restriction by including an extra &lt; in front of the SCRIPT tag.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/954" source="BID">954</ref>
      <ref url="http://www.osvdb.org/1212" source="OSVDB">1212</ref>
    </refs>
    <vuln_soft>
      <prod vendor="checkpoint" name="firewall-1">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0117" published="2000-01-30" name="CVE-2000-0117" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The siteUserMod.cgi program in Cobalt RaQ2 servers allows any Site Administrator to modify passwords for other users, site administrators, and possibly admin (root).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/951" source="BID">951</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="cobalt_raq">
        <vers num="1.0" />
      </prod>
      <prod vendor="sun" name="cobalt_raq_2">
        <vers num="" />
      </prod>
      <prod vendor="sun" name="cobalt_raq_3i">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0118" published="1999-06-09" name="CVE-2000-0118" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The Red Hat Linux su program does not log failed password guesses if the su process is killed before it times out, which allows local attackers to conduct brute force password guessing.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94935300520617&amp;w=2" source="BUGTRAQ">20000130 RedHat 6.1 /and others/ PAM</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="3.0.3" />
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" edition="" />
        <vers num="5.2" edition=":sparc" />
        <vers num="5.2" edition=":i386" />
        <vers num="5.2" edition=":alpha" />
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":i386" />
        <vers num="6.0" edition=":sparc" />
        <vers num="6.0" edition=":alpha" />
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":i386" />
        <vers num="6.1" edition=":alpha" />
        <vers num="6.1" edition=":sparc" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="" edition=":x86" />
        <vers num="1.1" />
        <vers num="1.1.1a" />
        <vers num="1.1.2" />
        <vers num="1.1.3" edition="u1" />
        <vers num="1.1.4" edition="" />
        <vers num="1.1.4" edition=":jl" />
        <vers num="1.2" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0119" published="1999-12-22" name="CVE-2000-0119" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The default configurations for McAfee Virus Scan and Norton Anti-Virus virus checkers do not check files in the RECYCLED folder that is used by the Windows Recycle Bin utility, which allows attackers to store malicious code without detection.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94936267131123&amp;w=2" source="BUGTRAQ">20000130 Bypass Virus Checking</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcafee" name="virusscan">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="norton_antivirus">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0120" published="2000-01-01" name="CVE-2000-0120" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Remote Access Service invoke.cfm template in Allaire Spectra 1.0 allows users to bypass authentication via the bAuthenticated parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4025.php" source="XF" adv="1">allaire-spectra-ras-access(4025)</ref>
      <ref url="http://www.securityfocus.com/bid/955" source="BID">955</ref>
    </refs>
    <vuln_soft>
      <prod vendor="allaire" name="spectra">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0121" published="2000-02-01" name="CVE-2000-0121" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">The Recycle Bin utility in Windows NT and Windows 2000 allows local users to read or modify files by creating a subdirectory with the victim's SID in the recycler directory, aka the "Recycle Bin Creation" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q248399" source="MSKB">Q248399</ref>
      <ref url="http://www.securityfocus.com/bid/963" source="BID">963</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-007.mspx" source="MS">MS00-007</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0122" published="2000-02-03" name="CVE-2000-0122" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Frontpage Server Extensions allows remote attackers to determine the physical path of a virtual directory via a GET request to the htimage.exe CGI program.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/964" source="BID">964</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34719" source="XF">frontpage-cern-information-disclosure(34719)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/470458/100/0/threaded" source="BUGTRAQ">20070603 CERN &amp;#304;mage Map Dispatcher</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="frontpage">
        <vers num="2000" />
        <vers num="98" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0123" published="2000-02-01" name="CVE-2000-0123" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The shopping cart application provided with Filemaker allows remote users to modify sensitive purchase information via hidden form fields.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="filemaker" name="filemaker">
        <vers num="" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0124" published="2000-02-03" name="CVE-2000-0124" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">surfCONTROL SuperScout does not properly asign a category to web sites with a . (dot) at the end, which may allow users to bypass web access restrictions.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/965" source="BID">965</ref>
    </refs>
    <vuln_soft>
      <prod vendor="surfcontrol" name="superscout">
        <vers num="2.6.1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0125" published="2000-02-03" name="CVE-2000-0125" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">wwwthreads does not properly cleanse numeric data or table names that are passed to SQL queries, which allows remote attackers to gain privileges for wwwthreads forums.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.10.10002031027120.15921-100000@eight.wiretrip.net" source="BUGTRAQ">20000203 RFP2K01 - "How I hacked Packetstorm" (wwwthreads advisory)</ref>
      <ref url="http://www.securityfocus.com/bid/967" source="BID">967</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wired_community_software" name="wwwthreads">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0126" published="2000-01-26" name="CVE-2000-0126" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sample Internet Data Query (IDQ) scripts in IIS 3 and 4 allow remote attackers to read files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="3.0" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0127" published="2000-02-03" name="CVE-2000-0127" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Webspeed configuration program does not properly disable access to the WSMadmin utility, which allows remote attackers to gain privileges via wsisa.dll.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/969" source="BID">969</ref>
      <ref url="http://www.progress.com/services/support/cgi-bin/techweb-kbase.cgi/webkb.html?kbid=19412&amp;keywords=security%20Webspeed" source="CONFIRM">http://www.progress.com/services/support/cgi-bin/techweb-kbase.cgi/webkb.html?kbid=19412&amp;keywords=security%20Webspeed</ref>
    </refs>
    <vuln_soft>
      <prod vendor="progress" name="webspeed">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0128" published="2000-02-04" name="CVE-2000-0128" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Finger Server 0.82 allows remote attackers to execute commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.glazed.org/finger/changelog.txt" source="CONFIRM">http://www.glazed.org/finger/changelog.txt</ref>
      <ref url="http://www.osvdb.org/7610" source="OSVDB">7610</ref>
    </refs>
    <vuln_soft>
      <prod vendor="daniel_beckham" name="the_finger_server">
        <vers num="0.80_beta" />
        <vers num="0.81_beta" />
        <vers num="0.82_beta" />
        <vers num="0.83_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0129" published="2000-02-04" name="CVE-2000-0129" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Buffer overflow in the SHGetPathFromIDList function of the Serv-U FTP server allows attackers to cause a denial of service by performing a LIST command on a malformed .lnk file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="microsoft" name="windows_95">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0130" published="2000-01-27" name="CVE-2000-0130" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in SCO scohelp program allows remote attackers to execute commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94908470928258&amp;w=2" source="BUGTRAQ" patch="1">20000127 New SCO patches...</ref>
      <ref url="ftp://ftp.sco.com/SSE/security_bulletins/SB-00.02a" source="SCO">SB-00.02a</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="unixware">
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0131" published="2000-02-01" name="CVE-2000-0131" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in War FTPd 1.6x allows users to cause a denial of service via long MKD and CWD commands.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/966" source="BID">966</ref>
      <ref url="http://www.osvdb.org/4677" source="OSVDB">4677</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94960703721503&amp;w=2" source="BUGTRAQ">20000201 war-ftpd 1.6x DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jgaa" name="warftpd">
        <vers num="1.66x4s" />
        <vers num="1.67.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0132" published="2000-01-31" name="CVE-2000-0132" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Microsoft Java Virtual Machine allows remote attackers to read files via the getSystemResourceAsStream function.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/957" source="BID">957</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="virtual_machine">
        <vers num="2000" />
        <vers num="3000" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0133" published="2000-02-01" name="CVE-2000-0133" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflows in Tiny FTPd 0.52 beta3 FTP server allows users to execute commands via the STOR, RNTO, MKD, XMKD, RMD, XRMD, APPE, SIZE, and RNFR commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/961" source="BID">961</ref>
    </refs>
    <vuln_soft>
      <prod vendor="h._nomura" name="tiny_ftpdaemon">
        <vers prev="1" num="0.52" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0134" published="2000-02-01" name="CVE-2000-0134" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Check It Out shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="adgrafix_corporation" name="check_it_out">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0135" published="2000-02-01" name="CVE-2000-0135" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The @Retail shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="atretail" name="atretail">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0136" published="2000-02-01" name="CVE-2000-0136" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Cart32 shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="mcmurtrey_whitaker_and_associates" name="cart32">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0137" published="2000-02-01" name="CVE-2000-0137" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The CartIt shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="cartit" name="cartit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0138" published="2000-05-02" name="CVE-2000-0138" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">A system has a distributed denial of service (DDOS) attack master, agent, or zombie installed, such as (1) Trinoo, (2) Tribe Flood Network (TFN), (3) Tribe Flood Network 2000 (TFN2K), (4) stacheldraht, (5) mstream, or (6) shaft.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/alerts/advise48.php3" source="ISS">20000502 "mstream" Distributed Denial of Service Tool</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95722093124322&amp;w=2" source="BUGTRAQ">20000429 Re: Source code to mstream, a DDoS tool</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95715370208598&amp;w=2" source="BUGTRAQ">20000429 Re: Source code to mstream, a DDoS tool</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0139" published="1999-12-03" name="CVE-2000-0139" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Internet Anywhere POP3 Mail Server allows local users to cause a denial of service via a malformed RETR command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/982" source="BID">982</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95021326417936&amp;w=2" source="BUGTRAQ">20000210 remote DoS on Internet Anywhere Mail Server Ver.3.1.3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="true_north" name="internet_anywhere_mail_server">
        <vers num="3.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0140" published="2000-02-10" name="CVE-2000-0140" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Internet Anywhere POP3 Mail Server allows remote attackers to cause a denial of service via a large number of connections.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/980" source="BID">980</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95021326417936&amp;w=2" source="BUGTRAQ">20000210 remote DoS on Internet Anywhere Mail Server Ver.3.1.3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="true_north" name="internet_anywhere_mail_server">
        <vers num="3.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0141" published="2000-02-11" name="CVE-2000-0141" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Infopop Ultimate Bulletin Board (UBB) allows remote attackers to execute commands via shell metacharacters in the topic hidden field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ultimatebb.com/home/versions.shtml" source="MISC">http://www.ultimatebb.com/home/versions.shtml</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-8&amp;msg=20000211224935.A13236@infomag.ape.relarn.ru" source="BUGTRAQ">20000211 perl-cgi hole in UltimateBB by Infopop Corp.</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-22&amp;msg=NDBBLKOPOLNKELHPDEFKIEPGCAAA.renzo.toma@veronica.nl" source="BUGTRAQ">20000225 FW: Important UBB News For Licensed Users</ref>
      <ref url="http://www.securityfocus.com/bid/991" source="BID">991</ref>
    </refs>
    <vuln_soft>
      <prod vendor="infopop" name="ultimate_bulletin_board">
        <vers num="5.43" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0142" published="2000-02-11" name="CVE-2000-0142" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The authentication protocol in Timbuktu Pro 2.0b650 allows remote attackers to cause a denial of service via connections to port 407 and 1417.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="netopia" name="timbuktu_pro">
        <vers num="2.0" />
        <vers num="5.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0143" published="2000-02-11" name="CVE-2000-0143" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The SSH protocol server sshd allows local users without shell access to redirect a TCP connection through a service that uses the standard system password database for authentication, such as POP or FTP.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="openbsd" name="openssh">
        <vers num="1.2" />
        <vers prev="1" num="1.2.1" />
      </prod>
      <prod vendor="ssh" name="ssh">
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.12" />
        <vers num="1.2.13" />
        <vers num="1.2.14" />
        <vers num="1.2.15" />
        <vers num="1.2.16" />
        <vers num="1.2.17" />
        <vers num="1.2.18" />
        <vers num="1.2.19" />
        <vers num="1.2.2" />
        <vers num="1.2.20" />
        <vers num="1.2.21" />
        <vers num="1.2.22" />
        <vers num="1.2.23" />
        <vers num="1.2.24" />
        <vers num="1.2.25" />
        <vers num="1.2.26" />
        <vers num="1.2.27" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0144" published="2000-02-07" name="CVE-2000-0144" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Axis 700 Network Scanner does not properly restrict access to administrator URLs, which allows users to bypass the password protection via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/971" source="BID">971</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0034.html" source="BUGTRAQ">20000207 Infosec.20000207.axis700.a</ref>
    </refs>
    <vuln_soft>
      <prod vendor="axis" name="700_network_document_server">
        <vers num="1.0" />
        <vers num="1.10" />
        <vers num="1.11" />
        <vers num="1.12" />
        <vers num="1.13" />
        <vers num="1.14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0145" published="2000-02-05" name="CVE-2000-0145" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The libguile.so library file used by gnucash in Debian GNU/Linux is installed with world-writable permissions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0146" published="2000-02-07" name="CVE-2000-0146" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Java Server in the Novell GroupWise Web Access Enhancement Pack allows remote attackers to cause a denial of service via a long URL to the servlet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/972" source="BID" patch="1" adv="1">972</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0049.html" source="BUGTRAQ">20000207 Novell GroupWise 5.5 Enhancement Pack Web Access Denial of Servic e</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="groupwise">
        <vers num="5.5" edition="" />
        <vers num="5.5" edition=":enhancement_pack" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0147" published="2000-02-08" name="CVE-2000-0147" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">snmpd in SCO OpenServer has an SNMP community string that is writable by default, which allows local attackers to modify the host's configuration.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0045.html" source="NAI" patch="1" adv="1">20000207 SNMPD default writable community string</ref>
      <ref url="ftp://ftp.sco.com/SSE/security_bulletins/SB-00.04a" source="SCO" patch="1" adv="1">SB-00.04a</ref>
      <ref url="http://www.securityfocus.com/bid/973" source="BID">973</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="openserver">
        <vers num="5.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0148" published="2000-02-08" name="CVE-2000-0148" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">MySQL 3.22 allows remote attackers to bypass password authentication and access a database via a short check string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/975" source="BID">975</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0053.html" source="BUGTRAQ">20000208 Remote access vulnerability in all MySQL server versions</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="3.22.26" />
        <vers num="3.22.27" />
        <vers num="3.22.29" />
        <vers num="3.22.30" />
        <vers num="3.23.10" />
        <vers num="3.23.8" />
        <vers num="3.23.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0149" published="2000-02-08" name="CVE-2000-0149" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Zeus web server allows remote attackers to view the source code for CGI programs via a null character (%00) at the end of a URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/3982" source="XF">zeus-server-null-string(3982)</ref>
      <ref url="http://www.securityfocus.com/bid/977" source="BID">977</ref>
      <ref url="http://www.osvdb.org/254" source="OSVDB">254</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0057.html" source="BUGTRAQ">20000208 Zeus Web Server: Null Terminated Strings</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zeus_technologies" name="zeus_web_server">
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers num="3.1.3" />
        <vers num="3.1.4" />
        <vers num="3.1.5" />
        <vers num="3.1.6" />
        <vers num="3.1.7" />
        <vers num="3.1.8" />
        <vers num="3.1.9" />
        <vers num="3.3" />
        <vers num="3.3.1" />
        <vers num="3.3.2" />
        <vers num="3.3.3" />
        <vers num="3.3.4" />
        <vers num="3.3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0150" published="2000-02-12" name="CVE-2000-0150" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Check Point Firewall-1 allows remote attackers to bypass port access restrictions on an FTP server by forcing it to send malicious packets that Firewall-1 misinterprets as a valid 227 response to a client's PASV attempt.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/328867" source="CERT-VN">VU#328867</ref>
      <ref url="http://www.securityfocus.com/bid/979" source="BID">979</ref>
      <ref url="http://www.osvdb.org/4417" source="OSVDB">4417</ref>
    </refs>
    <vuln_soft>
      <prod vendor="checkpoint" name="firewall-1">
        <vers num="3.0" />
        <vers num="4.0" />
      </prod>
      <prod vendor="cisco" name="pix_firewall">
        <vers num="4.1(6)" />
        <vers num="4.1(6b)" />
        <vers num="4.2(1)" />
        <vers num="4.2(2)" />
        <vers num="4.3" />
        <vers num="4.4(4)" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0151" published="2000-02-01" name="CVE-2000-0151" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">GNU make follows symlinks when it reads a Makefile from stdin, which allows other local users to execute commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/981" source="BID" patch="1" adv="1">981</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="make">
        <vers num="3.77.44" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0152" published="2000-03-30" name="CVE-2000-0152" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Remote attackers can cause a denial of service in Novell BorderManager 3.5 by pressing the enter key in a telnet connection to port 2000.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/976" source="BID">976</ref>
      <ref url="http://www.osvdb.org/7468" source="OSVDB">7468</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="bordermanager">
        <vers num="3.0" />
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0153" published="1999-03-26" name="CVE-2000-0153" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">FrontPage Personal Web Server (PWS) allows remote attackers to read files via a .... (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-15&amp;msg=000801bf780a$9ad4b2e0$0100007f@localhost" source="BUGTRAQ" adv="1">20000216 Doubledot bug in FrontPage FrontPage Personal Web Server.</ref>
      <ref url="http://www.securityfocus.com/bid/989" source="BID">989</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="frontpage">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="personal_web_server">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0154" published="2000-02-16" name="CVE-2000-0154" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">The ARCserve agent in UnixWare allows local attackers to modify arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/988" source="BID" patch="1" adv="1">988</ref>
      <ref url="http://www.sco.com/security/" source="MISC">http://www.sco.com/security/</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-15&amp;msg=000101bf78af$94528870$4d2f45a1@jmagdych.na.nai.com" source="NAI">20000215 ARCserve symlink vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="unixware">
        <vers num="7.1" />
        <vers num="7.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0155" published="2000-02-18" name="CVE-2000-0155" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Windows NT Autorun executes the autorun.inf file on non-removable media, which allows local attackers to specify an alternate program to execute when other users access a drive.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/993" source="BID" patch="1" adv="1">993</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-15&amp;msg=000701bf79cd$fdb5a620$4c4342a6@mightye.org" source="BUGTRAQ">20000218 AUTORUN.INF Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_95">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0156" published="2000-02-16" name="CVE-2000-0156" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Internet Explorer 4.x and 5.x allows remote web servers to access files on the client that are outside of its security domain, aka the "Image Source Redirect" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/3996" source="XF">ie-image-source-redirect(3996)</ref>
      <ref url="http://www.osvdb.org/7827" source="OSVDB">7827</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-009.mspx" source="MS">MS00-009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="5.0" />
        <vers num="5.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0157" published="2000-02-01" name="CVE-2000-0157" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">NetBSD ptrace call on VAX allows local users to gain privileges by modifying the PSL contents in the debugging process.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/992" source="BID">992</ref>
      <ref url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA1999-012.txt.asc" source="NETBSD">1999-012</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0158" published="2000-02-16" name="CVE-2000-0158" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in MMDF server allows remote attackers to gain privileges via a long MAIL FROM command to the SMTP daemon.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-15&amp;msg=000001bf78af$6d0d47a0$4d2f45a1@jmagdych.na.nai.com" source="NAI" patch="1" adv="1">20000215 Remote Vulnerability in the MMDF SMTP Daemon</ref>
      <ref url="ftp://ftp.sco.com/SSE/security_bulletins/SB-00.06a" source="SCO" patch="1" adv="1">SB-00.06a</ref>
      <ref url="http://www.securityfocus.com/bid/997" source="BID">997</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-15&amp;msg=200002181449.JAA03436@dragonfly.corp.home.net" source="BUGTRAQ">20000218 MMDF</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="openserver">
        <vers num="5.0" />
        <vers num="5.0.2" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0159" published="2000-02-17" name="CVE-2000-0159" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">HP Ignite-UX does not save /etc/passwd when it creates an image of a trusted system, which can set the password field to a blank and allow an attacker to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-15&amp;msg=20000217160216.13708.qmail@underground.org" source="HP">HPSBUX0002-111</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0160" published="2000-02-21" name="CVE-2000-0160" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">The Microsoft Active Setup ActiveX component in Internet Explorer 4.x and 5.x allows a remote attacker to install software components without prompting the user by stating that the software's manufacturer is Microsoft.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-15&amp;msg=20000221103938.T21312@securityfocus.com" source="BUGTRAQ">20000221 Microsoft signed software can be install software without prompting users</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.x" />
        <vers num="5" />
      </prod>
      <prod vendor="microsoft" name="outlook">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0161" published="2000-02-18" name="CVE-2000-0161" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Sample web sites on Microsoft Site Server 3.0 Commerce Edition do not validate an identification number, which allows remote attackers to execute SQL commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/994" source="BID">994</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-010.asp" source="MS">MS00-010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="site_server">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0162" published="2000-02-18" name="CVE-2000-0162" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">The Microsoft virtual machine (VM) in Internet Explorer 4.x and 5.x allows a remote attacker to read files via a malicious Java applet that escapes the Java sandbox, aka the "VM File Reading" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-011.asp" source="MS">MS00-011</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":windows_98" />
        <vers num="4.0" edition=":windows_nt" />
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":windows_95" />
        <vers num="4.1" edition=":windows_nt_4.0" />
        <vers num="5" edition="" />
        <vers num="5" edition=":windows_nt_4.0" />
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":windows_98" />
        <vers num="5.0" edition=":windows_95" />
      </prod>
      <prod vendor="microsoft" name="visual_studio">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0163" published="2000-02-21" name="CVE-2000-0163" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">asmon and ascpu in FreeBSD allow local users to gain root privileges via a configuration file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/advisory.html?id=2092" source="FREEBSD">FreeBSD-SA-00:03</ref>
      <ref url="http://www.securityfocus.com/bid/996" source="BID">996</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0164" published="2000-02-20" name="CVE-2000-0164" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The installation of Sun Internet Mail Server (SIMS) creates a world-readable file that allows local users to obtain passwords.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1004" source="BID" adv="1">1004</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-15&amp;msg=Pine.SOL.4.21.0002200031320.22675-100000@klayman.hq.formus.pl" source="BUGTRAQ">20000220 Sun Internet Mail Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris_isp_server">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0165" published="1999-11-13" name="CVE-2000-0165" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Delegate application proxy has several buffer overflows which allow a remote attacker to execute commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-15&amp;msg=Pine.BSF.4.21.0002192249290.10784-100000@freefall.freebsd.org" source="FREEBSD">FreeBSD-SA-00:04</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/k-023.shtml" source="CIAC">K-023</ref>
    </refs>
    <vuln_soft>
      <prod vendor="etl" name="delegate">
        <vers num="5.9" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0166" published="2000-02-21" name="CVE-2000-0166" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the InterAccess telnet server TelnetD allows remote attackers to execute commands via a long login name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=NCBBKFKDOLAGKIAPMILPGEJHCCAA.labs@ussrback.com" source="BUGTRAQ">20000221 Local / Remote Exploiteable Buffer Overflow Vulnerability in InterAccess TelnetD Server 4.0 for Windows NT</ref>
      <ref url="http://www.securityfocus.com/bid/995" source="BID">995</ref>
    </refs>
    <vuln_soft>
      <prod vendor="interaccess" name="interaccess_telnetd_server">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0167" published="2000-02-15" name="CVE-2000-0167" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">IIS Inetinfo.exe allows local users to cause a denial of service by creating a mail file with a long name and a .txt.eml extension in the pickup directory.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0002&amp;L=ntbugtraq&amp;F=&amp;S=&amp;P=8800" source="NTBUGTRAQ">20000215 Crashing Inetinfo.exe by using a longfilename in the \mailroot\pickup directory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0168" published="2000-03-04" name="CVE-2000-0168" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Windows 9x operating systems allow an attacker to cause a denial of service via a pathname that includes file device names, aka the "DOS Device in Path Name" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=NCBBKFKDOLAGKIAPMILPCENECCAA.labs@ussrback.com" source="BUGTRAQ">20000306 con\con is a old thing (anyway is cool)</ref>
      <ref url="http://www.securityfocus.com/templates/advisory.html?id=2126" source="MS">MS00-017</ref>
      <ref url="http://www.securityfocus.com/bid/1043" source="BID">1043</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_95">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0169" published="2000-03-15" name="CVE-2000-0169" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Batch files in the Oracle web listener ows-bin directory allow remote attackers to execute commands via a malformed URL that includes '?&amp;'.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1053" source="BID">1053</ref>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q1/0211.html" source="NTBUGTRAQ">20000314 Oracle Web Listener 4.0.x</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0170" published="2000-02-26" name="CVE-2000-0170" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the man program in Linux allows local users to gain privileges via the MANPAGER environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1011" source="BID">1011</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="6.0" />
        <vers num="6.2" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux">
        <vers num="3.5b2" />
        <vers num="4.2" />
        <vers num="4.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0171" published="2000-03-11" name="CVE-2000-0171" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">atsadc in the atsar package for Linux does not properly check the permissions of an output file, which allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1048" source="BID">1048</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0102.html" source="BUGTRAQ">20000311 TESO advisory -- atsadc</ref>
    </refs>
    <vuln_soft>
      <prod vendor="at_computing" name="atsar_linux">
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0172" published="2000-03-03" name="CVE-2000-0172" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The mtr program only uses a seteuid call when attempting to drop privileges, which could allow local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1038" source="BID">1038</ref>
    </refs>
    <vuln_soft>
      <prod vendor="matt_kimball_and_roger_wolff" name="mtr">
        <vers num="0.28" />
        <vers num="0.41" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux">
        <vers num="3.5b2" />
        <vers num="4.2" />
        <vers num="4.4" />
        <vers num="6.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0173" published="2000-03-10" name="CVE-2000-0173" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Vulnerability in the EELS system in SCO UnixWare 7.1.x allows remote attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="ftp://ftp.sco.com/SSE/security_bulletins/SB-00.08a" source="SCO" patch="1" adv="1">SB-00.08a</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="unixware">
        <vers num="7.1" />
        <vers num="7.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0174" published="2000-03-09" name="CVE-2000-0174" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">StarOffice StarScheduler web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1040" source="BID">1040</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0063.html" source="BUGTRAQ">20000308 [SAFER 000309.EXP.1.4] StarScheduler (StarOffice) vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="staroffice">
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0175" published="2000-03-09" name="CVE-2000-0175" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in StarOffice StarScheduler web server allows remote attackers to gain root access via a long GET command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1039" source="BID">1039</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0063.html" source="BUGTRAQ">20000308 [SAFER 000309.EXP.1.4] StarScheduler (StarOffice) vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="staroffice">
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0176" published="2000-02-29" name="CVE-2000-0176" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The default configuration of Serv-U 2.5d and earlier allows remote attackers to determine the real pathname of the server by requesting a URL for a directory or file that does not exist.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1016" source="BID" patch="1" adv="1">1016</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0417.html" source="BUGTRAQ">20000228 Serv-U FTP-Server v2.4a showing real path</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cat_soft" name="serv-u">
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.5a" />
        <vers num="2.5b" />
        <vers num="2.5c" />
        <vers num="2.5d" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0177" published="2000-03-02" name="CVE-2000-0177" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">DNSTools CGI applications allow remote attackers to execute arbitrary commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1028" source="BID">1028</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0000.html" source="BUGTRAQ">20000302 DNSTools v1.08 has no input validation</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dnstools_software" name="dnstools">
        <vers prev="1" num="1.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0178" published="2000-02-28" name="CVE-2000-0178" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">ServerIron switches by Foundry Networks have predictable TCP/IP sequence numbers, which allows remote attackers to spoof or hijack sessions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.foundrynet.com/bugTraq.html" source="MISC" adv="1">http://www.foundrynet.com/bugTraq.html</ref>
      <ref url="http://www.securityfocus.com/bid/1017" source="BID">1017</ref>
    </refs>
    <vuln_soft>
      <prod vendor="foundrynet" name="serveriron">
        <vers num="5.1.10t12" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0179" published="2000-02-28" name="CVE-2000-0179" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">HP OpenView OmniBack 2.55 allows remote attackers to cause a denial of service via a large number of connections to port 5555.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1015" source="BID" patch="1" adv="1">1015</ref>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0006-115" source="HP">HPSBUX0006-115</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0387.html" source="BUGTRAQ">20000228 HP Omniback remote DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_omniback_ii">
        <vers num="2.55" />
        <vers num="3.0" />
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0180" published="2000-03-14" name="CVE-2000-0180" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sojourn search engine allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1052" source="BID" patch="1" adv="1">1052</ref>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q1/0201.html" source="NTBUGTRAQ" adv="1">20000313 SOJOURN Search engine exposes files</ref>
      <ref url="http://xforce.iss.net/static/4197.php" source="XF">sojourn-file-read(4197)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="generation_terrorists_designs_and_concepts" name="sojourn">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0181" published="2000-03-11" name="CVE-2000-0181" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Firewall-1 3.0 and 4.0 leaks packets with private IP address information, which could allow remote attackers to determine the real IP address of the host that is making the connection.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1054" source="BID">1054</ref>
      <ref url="http://www.osvdb.org/1256" source="OSVDB">1256</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0119.html" source="BUGTRAQ">20000311 Our old friend Firewall-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="checkpoint" name="firewall-1">
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0182" published="2000-02-23" name="CVE-2000-0182" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">iPlanet Web Server 4.1 allows remote attackers to cause a denial of service via a large number of GET commands, which consumes memory and causes a kernel panic.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="iplanet" name="iplanet_web_server">
        <vers num="4.1_enterprise" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0183" published="2000-03-10" name="CVE-2000-0183" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in ircII 4.4 IRC client allows remote attackers to execute commands via the DCC chat capability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1046" source="BID">1046</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-008.html" source="REDHAT">RHSA-2000:008</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0093.html" source="BUGTRAQ">20000310 Fwd: ircii-4.4 buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michael_sandrof" name="ircii">
        <vers num="4.4.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0184" published="2000-03-09" name="CVE-2000-0184" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Linux printtool sets the permissions of printer configuration files to be world-readable, which allows local attackers to obtain printer share passwords.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1037" source="BID">1037</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0082.html" source="BUGTRAQ">20000309</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="7.0" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":sparc" />
        <vers num="6.1" edition=":i386" />
        <vers num="6.1" edition=":alpha" />
        <vers num="6.2" edition="" />
        <vers num="6.2" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0185" published="2000-03-08" name="CVE-2000-0185" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">RealMedia RealServer reveals the real IP address of a Real Server, even if the address is supposed to be private.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1049" source="BID">1049</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0069.html" source="BUGTRAQ">20000308 RealServer exposes internal IP addresses</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realserver">
        <vers num="5.0" />
        <vers num="7.0" />
      </prod>
      <prod vendor="realnetworks" name="realserver_g2">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0186" published="2000-02-28" name="CVE-2000-0186" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the dump utility in the Linux ext2fs backup package allows local users to gain privileges via a long command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1020" source="BID">1020</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-100.html" source="REDHAT">RHSA-2000:100</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.4" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="6.1" />
        <vers num="7.0" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="5.1" />
        <vers num="5.2" edition="" />
        <vers num="5.2" edition=":i386" />
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":i386" />
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":i386" />
        <vers num="6.2" edition="" />
        <vers num="6.2" edition=":i386" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux">
        <vers num="4.2" />
        <vers num="4.4" />
        <vers num="6.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0187" published="2000-02-27" name="CVE-2000-0187" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">EZShopper 3.0 loadpage.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1014" source="BID" patch="1" adv="1">1014</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0356.html" source="BUGTRAQ">20000227 EZ Shopper 3.0 shopping cart CGI remote command execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alex_heiphetz_group" name="ezshopper">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0188" published="2000-02-27" name="CVE-2000-0188" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">EZShopper 3.0 search.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1014" source="BID" patch="1" adv="1">1014</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0356.html" source="BUGTRAQ">20000227 EZ Shopper 3.0 shopping cart CGI remote command execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alex_heiphetz_group" name="ezshopper">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0189" published="2000-03-01" name="CVE-2000-0189" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ColdFusion Server 4.x allows remote attackers to determine the real pathname of the server via an HTTP request to the application.cfm or onrequestend.cfm files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1021" source="BID">1021</ref>
    </refs>
    <vuln_soft>
      <prod vendor="allaire" name="coldfusion_server">
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0190" published="2000-03-02" name="CVE-2000-0190" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">AOL Instant Messenger (AIM) client allows remote attackers to cause a denial of service via a message with a malformed ASCII value.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0016.html" source="BUGTRAQ">20000303 Aol Instant Messenger DoS vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aol" name="instant_messenger">
        <vers prev="1" num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0191" published="2000-02-29" name="CVE-2000-0191" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Axis StorPoint CD allows remote attackers to access administrator URLs without authentication via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=41256894.00492503.00@mailgw.backupcentralen.se" source="BUGTRAQ" patch="1" adv="1">20000229 Infosec.20000229.axisstorpointcd.a</ref>
      <ref url="http://www.securityfocus.com/bid/1025" source="BID" patch="1" adv="1">1025</ref>
      <ref url="http://www.osvdb.org/19" source="OSVDB">19</ref>
    </refs>
    <vuln_soft>
      <prod vendor="axis" name="storpoint_cd">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0192" published="2000-03-05" name="CVE-2000-0192" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The default installation of Caldera OpenLinux 2.3 includes the CGI program rpm_query, which allows remote attackers to determine what packages are installed on the system.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1036" source="BID">1036</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0029.html" source="BUGTRAQ">20000304 OpenLinux 2.3: rpm_query</ref>
    </refs>
    <vuln_soft>
      <prod vendor="caldera" name="openlinux">
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0193" published="2000-03-02" name="CVE-2000-0193" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The default configuration of Dosemu in Corel Linux 1.0 allows local users to execute the system.com program and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1030" source="BID" patch="1" adv="1">1030</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200003020436.PAA20168@jawa.chilli.net.au" source="BUGTRAQ">20000302 Corel Linux 1.0 dosemu default configuration: Local root vuln</ref>
    </refs>
    <vuln_soft>
      <prod vendor="corel" name="linux">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0194" published="2000-02-24" name="CVE-2000-0194" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">buildxconf in Corel Linux allows local users to modify or create arbitrary files via the -x or -f parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1007" source="BID">1007</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0323.html" source="BUGTRAQ">20000224 Corel Linux 1.0 local root compromise</ref>
    </refs>
    <vuln_soft>
      <prod vendor="corel" name="linux">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0195" published="2000-02-24" name="CVE-2000-0195" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">setxconf in Corel Linux allows local users to gain root access via the -T parameter, which executes the user's .xserverrc file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1008" source="BID">1008</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0323.html" source="BUGTRAQ">20000224 Corel Linux 1.0 local root compromise</ref>
    </refs>
    <vuln_soft>
      <prod vendor="corel" name="linux">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0196" published="2000-02-28" name="CVE-2000-0196" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in mhshow in the Linux nmh package allows remote attackers to execute commands via malformed MIME headers in an email message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1018" source="BID">1018</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-006.html" source="REDHAT">RHSA-2000:006</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nmh" name="nmh">
        <vers num="1.0.2" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="5.2" edition="" />
        <vers num="5.2" edition=":sparc" />
        <vers num="5.2" edition=":i386" />
        <vers num="5.2" edition=":alpha" />
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":i386" />
        <vers num="6.0" edition=":alpha" />
        <vers num="6.0" edition=":sparc" />
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":i386" />
        <vers num="6.1" edition=":alpha" />
        <vers num="6.1" edition=":sparc" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux">
        <vers num="3.5b2" />
        <vers num="4.2" />
        <vers num="4.4" />
        <vers num="6.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0197" published="2000-02-14" name="CVE-2000-0197" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The Windows NT scheduler uses the drive mapping of the interactive user who is currently logged onto the system, which allows the local user to gain privileges by providing a Trojan horse batch file in place of the original batch file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1050" source="BID" patch="1">1050</ref>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/current/0202.html" source="NTBUGTRAQ">20000313 AT Jobs - Denial of serice/Privilege Elevation</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0198" published="2000-03-15" name="CVE-2000-0198" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in POP3 and IMAP servers in the MERCUR mail server suite allows remote attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1051" source="BID">1051</ref>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/current/0206.html" source="NTBUGTRAQ">20000314 Local / Remote Multiples Remote DoS Attacks in MERCUR v3.2* for Windows 98/NT Vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/current/0137.html" source="BUGTRAQ">20000314 Local / Remote Multiples Remote DoS Attacks in MERCUR v3.2* for Windows 98/NT Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="atrium_software" name="mercur_imap4_server">
        <vers num="3.20.01" />
      </prod>
      <prod vendor="atrium_software" name="mercur_mailserver">
        <vers num="3.2" />
      </prod>
      <prod vendor="atrium_software" name="mercur_pop3_server">
        <vers num="3.20.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0199" published="2000-03-14" name="CVE-2000-0199" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">When a new SQL Server is registered in Enterprise Manager for Microsoft SQL Server 7.0 and the "Always prompt for login name and password" option is not set, then the Enterprise Manager uses weak encryption to store the login ID and password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1055" source="BID" patch="1" adv="1">1055</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="sql_server">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0200" published="2000-03-06" name="CVE-2000-0200" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Clip Art Gallery allows remote attackers to cause a denial of service or execute commands via a malformed CIL (clip art library) file, aka the "Clip Art Buffer Overrun" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1034" source="BID">1034</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-015.mspx" source="MS">MS00-015</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="clip_art">
        <vers num="1.0" />
      </prod>
      <prod vendor="microsoft" name="greetings">
        <vers num="2000" />
      </prod>
      <prod vendor="microsoft" name="home_publishing">
        <vers num="2000" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0201" published="2000-03-01" name="CVE-2000-0201" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">The window.showHelp() method in Internet Explorer 5.x does not restrict HTML help files (.chm) to be executed from the local host, which allows remote attackers to execute arbitrary commands via Microsoft Networking.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1033" source="BID">1033</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0" />
        <vers num="5.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0202" published="2000-03-08" name="CVE-2000-0202" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Microsoft SQL Server 7.0 and Microsoft Data Engine (MSDE) 1.0 allow remote attackers to gain privileges via a malformed Select statement in an SQL query.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1041" source="BID">1041</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-014.mspx" source="MS">MS00-014</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="data_engine">
        <vers num="1.0" />
      </prod>
      <prod vendor="microsoft" name="sql_server">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0203" published="2000-02-28" name="CVE-2000-0203" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Trend Micro OfficeScan client tmlisten.exe allows remote attackers to cause a denial of service via malformed data to port 12345.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.antivirus.com/download/ofce_patch_35.htm" source="MISC" patch="1" adv="1">http://www.antivirus.com/download/ofce_patch_35.htm</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=412FC0AFD62ED31191B40008C7E9A11A0D481D@srvnt04.previnet.it" source="BUGTRAQ" adv="1">20000228 Re: TrendMicro OfficeScan tmlisten.exe DoS</ref>
      <ref url="http://www.securityfocus.com/bid/1013" source="BID">1013</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=D129BBE1730AD2118A0300805FC1C2FE038AF28B@209-76-212-10.trendmicro.com" source="BUGTRAQ">20000315 Trend Micro release patch for "OfficeScan DoS &amp; Message Replay" V ulnerabilies</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="officescan">
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0204" published="2000-02-28" name="CVE-2000-0204" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Trend Micro OfficeScan client allows remote attackers to cause a denial of service by making 5 connections to port 12345, which raises CPU utilization to 100%.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=D129BBE1730AD2118A0300805FC1C2FE038AF28B@209-76-212-10.trendmicro.com" source="BUGTRAQ">20000315 Trend Micro release patch for "OfficeScan DoS &amp; Message Replay" V ulnerabilies</ref>
      <ref url="http://www.securityfocus.com/bid/1013" source="BID">1013</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0340.html" source="BUGTRAQ">20000226 DOS in Trendmicro OfficeScan</ref>
      <ref url="http://www.antivirus.com/download/ofce_patch_35.htm" source="MISC">http://www.antivirus.com/download/ofce_patch_35.htm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="officescan">
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0205" published="2000-03-03" name="CVE-2000-0205" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Trend Micro OfficeScan allows remote attackers to replay administrative commands and modify the configuration of OfficeScan clients.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.antivirus.com/download/ofce_patch_35.htm" source="MISC" patch="1" adv="1">http://www.antivirus.com/download/ofce_patch_35.htm</ref>
      <ref url="http://www.securityfocus.com/bid/1013" source="BID">1013</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0015.html" source="BUGTRAQ" adv="1">20000303 TrendMicro OfficeScan, numerous security holes, remote files modification.</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=D129BBE1730AD2118A0300805FC1C2FE038AF28B@209-76-212-10.trendmicro.com" source="BUGTRAQ">20000315 Trend Micro release patch for "OfficeScan DoS &amp; Message Replay" V ulnerabilies</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="officescan">
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0206" published="2000-03-05" name="CVE-2000-0206" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">The installation of Oracle 8.1.5.x on Linux follows symlinks and creates the orainstRoot.sh file with world-writeable permissions, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1035" source="BID">1035</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0023.html" source="BUGTRAQ">20000305 Oracle installer problem</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="oracle8i">
        <vers num="8.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0207" published="2000-03-01" name="CVE-2000-0207" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SGI InfoSearch CGI program infosrch.cgi allows remote attackers to execute commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1031" source="BID">1031</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20000501-01-P" source="SGI">20000501-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="infosearch">
        <vers num="1.0" />
      </prod>
      <prod vendor="sgi" name="irix">
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.2m" />
        <vers num="6.5.3" />
        <vers num="6.5.3f" />
        <vers num="6.5.3m" />
        <vers num="6.5.4" />
        <vers num="6.5.6" />
        <vers num="6.5.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0208" published="2000-02-29" name="CVE-2000-0208" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The htdig (ht://Dig) CGI program htsearch allows remote attackers to read arbitrary files by enclosing the file name with backticks (`) in parameters to htsearch.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1026" source="BID">1026</ref>
    </refs>
    <vuln_soft>
      <prod vendor="htdig" name="htdig">
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers num="3.1.3" />
        <vers num="3.1.4" />
        <vers num="3.2.0b1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0209" published="2000-02-27" name="CVE-2000-0209" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Buffer overflow in Lynx 2.x allows remote attackers to crash Lynx and possibly execute commands via a long URL in a malicious web page.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1012" source="BID">1012</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_kansas" name="lynx">
        <vers num="2.7" />
        <vers num="2.8" />
        <vers num="2.8.3_dev22" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0210" published="2000-02-21" name="CVE-2000-0210" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">The lit program in Sun Flex License Manager (FlexLM) follows symlinks, which allows local users to modify arbitrary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/998" source="BID">998</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="workshop">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0211" published="2000-02-23" name="CVE-2000-0211" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Windows Media server allows remote attackers to cause a denial of service via a series of client handshake packets that are sent in an improper sequence, aka the "Misordered Windows Media Services Handshake" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1000" source="BID">1000</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-013.mspx" source="MS">MS00-013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_media_services">
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0212" published="2000-02-24" name="CVE-2000-0212" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">InterAccess TelnetID Server 4.0 allows remote attackers to conduct a denial of service via malformed terminal client configuration information.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/4033" source="XF">interaccess-telnet-dos(4033)</ref>
      <ref url="http://www.securityfocus.com/bid/1001" source="BID">1001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pragma_systems" name="interaccess_telnetd_server">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0213" published="2000-02-23" name="CVE-2000-0213" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Sambar server includes batch files ECHO.BAT and HELLO.BAT in the CGI directory, which allow remote attackers to execute commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1002" source="BID" patch="1" adv="1">1002</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=38B3E60A.6A84FEC3@cybcom.net" source="BUGTRAQ" adv="1">20000223 Sambar Server alert!</ref>
      <ref url="http://www.sambar.com/session/highlight?url=/syshelp/history.htm&amp;words=security+&amp;color=red" source="CONFIRM" adv="1">http://www.sambar.com/session/highlight?url=/syshelp/history.htm&amp;words=security+&amp;color=red</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sambar" name="sambar_server">
        <vers prev="1" num="4.2" edition="beta7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0214" published="2000-02-24" name="CVE-2000-0214" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">FTP Explorer uses weak encryption for storing the username, password, and profile of FTP sites.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.10.10002242035500.30645-100000@unreal.sekure.org" source="BUGTRAQ" adv="1">20000224 How the password could be recover using FTP Explorer's  registry!</ref>
      <ref url="http://www.securityfocus.com/bid/1003" source="BID">1003</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ftpx" name="ftp_explorer">
        <vers num="1.00.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0215" published="2000-02-08" name="CVE-2000-0215" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in SCO cu program in UnixWare 7.x allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1019" source="BID">1019</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="unixware">
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.1" />
        <vers num="7.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0216" published="2000-02-29" name="CVE-2000-0216" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft email clients in Outlook, Exchange, and Windows Messaging automatically respond to Read Receipt and Delivery Receipt tags, which could allow an attacker to flood a mail system with responses by forging a Read Receipt request that is redirected to a large distribution list.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q1/0176.html" source="NTBUGTRAQ" adv="1">20000229 mailbombing DoS easily exploitable against mail systems using MS mail clients.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="outlook">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_messaging">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0217" published="2000-02-24" name="CVE-2000-0217" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">The default configuration of SSH allows X forwarding, which could allow a remote attacker to control a client's X sessions via a malicious xauth program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1006" source="BID">1006</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openssh">
        <vers num="1.2" />
      </prod>
      <prod vendor="ssh" name="ssh">
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.12" />
        <vers num="1.2.13" />
        <vers num="1.2.14" />
        <vers num="1.2.15" />
        <vers num="1.2.16" />
        <vers num="1.2.17" />
        <vers num="1.2.18" />
        <vers num="1.2.19" />
        <vers num="1.2.2" />
        <vers num="1.2.20" />
        <vers num="1.2.21" />
        <vers num="1.2.22" />
        <vers num="1.2.23" />
        <vers num="1.2.24" />
        <vers num="1.2.25" />
        <vers num="1.2.26" />
        <vers num="1.2.27" />
        <vers num="1.2.28" />
        <vers num="1.2.29" />
        <vers num="1.2.3" />
        <vers num="1.2.30" />
        <vers num="1.2.31" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
      </prod>
      <prod vendor="ssh" name="ssh2">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.12" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0218" published="2000-02-03" name="CVE-2000-0218" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Linux mount and umount allows local users to gain root privileges via a long relative pathname.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/7004" source="OSVDB">7004</ref>
      <ref url="http://www.osvdb.org/6980" source="OSVDB">6980</ref>
      <ref url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2000-002.0.txt" source="CALDERA">CSSA-2000-002.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="caldera" name="openlinux">
        <vers num="2.3" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0219" published="2000-02-23" name="CVE-2000-0219" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Red Hat 6.0 allows local users to gain root access by booting single user and hitting ^C at the password prompt.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1005" source="BID" patch="1" adv="1">1005</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200002230248.NAA19185@cairo.anu.edu.au" source="BUGTRAQ" adv="1">20000223 redhat 6.0: single user boot security hole</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0220" published="2000-02-24" name="CVE-2000-0220" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ZoneAlarm sends sensitive system and network information in cleartext to the Zone Labs server if a user requests more information about an event.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="zonelabs" name="zonealarm">
        <vers num="2.0.26" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0221" published="2000-02-25" name="CVE-2000-0221" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Nautica Marlin bridge allows remote attackers to cause a denial of service via a zero length UDP packet to the SNMP port.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1009" source="BID">1009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nortel" name="nautica_marlin">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0222" published="2000-02-15" name="CVE-2000-0222" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The installation for Windows 2000 does not activate the Administrator password until the system has rebooted, which allows remote attackers to connect to the ADMIN$ share without a password until the reboot occurs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000215155750.M4500@safe.hsc.fr" source="BUGTRAQ" adv="1">20000215 Windows 2000 installation process weakness</ref>
      <ref url="http://www.securityfocus.com/bid/990" source="BID">990</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0223" published="2000-03-10" name="CVE-2000-0223" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the wmcdplay CD player program for the WindowMaker desktop allows local users to gain root privileges via a long parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1047" source="BID">1047</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0107.html" source="BUGTRAQ">20000311 TESO advisory -- wmcdplay</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sam_hawker" name="wmcdplay">
        <vers num="1.0_beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0224" published="2000-02-15" name="CVE-2000-0224" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">ARCserve agent in SCO UnixWare 7.x allows local attackers to gain root privileges via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-15&amp;msg=000101bf78af$94528870$4d2f45a1@jmagdych.na.nai.com" source="NAI">20000215 ARCserve symlink vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="unixware">
        <vers num="7.1" />
        <vers num="7.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0225" published="2000-03-07" name="CVE-2000-0225" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Pocsag POC32 program does not properly prevent remote users from accessing its server port, even if the option has been disabled.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1032" source="BID" adv="1">1032</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=003601bf854b$6893a090$0100a8c0@FIREWALKER" source="BUGTRAQ">20000303 Pocsag remote access to client can't be disabled.</ref>
      <ref url="http://www.osvdb.org/259" source="OSVDB">259</ref>
    </refs>
    <vuln_soft>
      <prod vendor="deti_fliegl" name="poc32">
        <vers num="2.05" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0226" published="2000-03-20" name="CVE-2000-0226" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IIS 4.0 allows attackers to cause a denial of service by requesting a large buffer in a POST or PUT command which consumes memory, aka the "Chunked Transfer Encoding Buffer Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-018.asp" source="MS" patch="1" adv="1">MS00-018</ref>
      <ref url="http://www.securityfocus.com/bid/1066" source="BID">1066</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0227" published="2000-03-23" name="CVE-2000-0227" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The Linux 2.2.x kernel does not restrict the number of Unix domain sockets as defined by the wmem_max paremeter, which allows local users to cause a denial of service by requesting a large number of sockets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4186.php" source="XF">linux-domain-socket-dos(4186)</ref>
      <ref url="http://www.securityfocus.com/bid/1072" source="BID">1072</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0254.html" source="BUGTRAQ">20000323 Local Denial-of-Service attack against Linux</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95421263519558&amp;w=2" source="BUGTRAQ">20000328 Re: Local Denial-of-Service attack against Linux</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.2.12" />
        <vers num="2.2.14" />
        <vers num="2.3.99" edition="pre2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0228" published="2000-03-17" name="CVE-2000-0228" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Windows Media License Manager allows remote attackers to cause a denial of service by sending a malformed request that causes the manager to halt, aka the "Malformed Media License Request" Vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-016.asp" source="MS" patch="1" adv="1">MS00-016</ref>
      <ref url="http://www.securityfocus.com/bid/1058" source="BID">1058</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_media_rights_manager">
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0229" published="2000-03-22" name="CVE-2000-0229" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">gpm-root in the gpm package does not properly drop privileges, which allows local users to gain privileges by starting a utility from gpm-root.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1069" source="BID">1069</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-045.html" source="REDHAT">RHSA-2000:045</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-009.html" source="REDHAT">RHSA-2000:009</ref>
      <ref url="http://www.novell.com/linux/security/advisories/suse_security_announce_45.html" source="SUSE">20000405 Security hole in gpm &lt; 1.18.1</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0242.html" source="BUGTRAQ">20000322 gpm-root</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alessandro_rubini" name="gpm">
        <vers num="1.18.1" />
        <vers num="1.19" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" edition="" />
        <vers num="2.2" edition=":pre_potato" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":i386" />
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":i386" />
        <vers num="6.2" edition="" />
        <vers num="6.2" edition=":i386" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="5.3" />
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0230" published="2000-03-13" name="CVE-2000-0230" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in imwheel allows local users to gain root privileges via the imwheel-solo script and a long HOME environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1060" source="BID">1060</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-016.html" source="REDHAT">RHSA-2000:016</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0168.html" source="BUGTRAQ">20000316 TESO &amp; C-Skills development advisory -- imwheel</ref>
    </refs>
    <vuln_soft>
      <prod vendor="halloween" name="halloween_linux">
        <vers num="4.0" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="6.1" />
        <vers num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0231" published="2000-03-16" name="CVE-2000-0231" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Linux kreatecd trusts a user-supplied path that is used to find the cdrecord program, allowing local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1061" source="BID">1061</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0162.html" source="BUGTRAQ">20000316 "TESO &amp; C-Skills development advisory -- kreatecd" at:</ref>
    </refs>
    <vuln_soft>
      <prod vendor="halloween" name="halloween_linux">
        <vers num="4.0" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0232" published="2000-03-30" name="CVE-2000-0232" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Microsoft TCP/IP Printing Services, aka Print Services for Unix, allows an attacker to cause a denial of service via a malformed TCP/IP print request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-021.asp" source="MS" patch="1" adv="1">MS00-021</ref>
      <ref url="http://www.securityfocus.com/bid/1082" source="BID">1082</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0306.html" source="BUGTRAQ">20000330 Remote DoS Attack in Windows 2000/NT 4.0 TCP/IP Print Request Server Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="terminal_server">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0233" published="2000-03-15" name="CVE-2000-0233" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SuSE Linux IMAP server allows remote attackers to bypass IMAP authentication and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/vendor/2000-q1/0035.html" source="SUSE">20000327 Security hole in SuSE Linux IMAP Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="suse_linux_imap_server">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0234" published="2000-03-31" name="CVE-2000-0234" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The default configuration of Cobalt RaQ2 and RaQ3 as specified in access.conf allows remote attackers to view sensitive contents of a .htaccess file.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/advisory.html?id=2150" source="CONFIRM">http://www.securityfocus.com/templates/advisory.html?id=2150</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000330220757.28456.qmail@securityfocus.com" source="BUGTRAQ">20000330 Cobalt apache configuration exposes .htaccess</ref>
      <ref url="http://www.securityfocus.com/bid/1083" source="BID">1083</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="cobalt_raq_2">
        <vers num="" />
      </prod>
      <prod vendor="sun" name="cobalt_raq_3i">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0235" published="2000-03-27" name="CVE-2000-0235" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the huh program in the orville-write package allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:10-orville-write.asc" source="FREEBSD">FreeBSD-SA-00:10</ref>
      <ref url="http://www.securityfocus.com/bid/1070" source="BID">1070</ref>
      <ref url="http://www.osvdb.org/1263" source="OSVDB">1263</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0236" published="2000-03-17" name="CVE-2000-0236" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Netscape Enterprise Server with Directory Indexing enabled allows remote attackers to list server directories via web publishing tags such as ?wp-ver-info and ?wp-cs-dump.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=38D2173D.24E39DD0@relaygroup.com" source="BUGTRAQ">20000317 [SAFER 000317.EXP.1.5] Netscape Enterprise Server and '?wp' tags</ref>
      <ref url="http://www.securityfocus.com/bid/1063" source="BID">1063</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="enterprise_server">
        <vers num="3.0" />
        <vers num="3.5.1" />
        <vers num="3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0237" published="2000-03-11" name="CVE-2000-0237" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Netscape Enterprise Server with Web Publishing enabled allows remote attackers to list arbitrary directories via a GET request for the /publisher directory, which provides a Java applet that allows the attacker to browse the directories.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1075" source="BID" patch="1" adv="1">1075</ref>
      <ref url="http://zsh.stupidphat.com/advisory.cgi?000311-1" source="MISC">http://zsh.stupidphat.com/advisory.cgi?000311-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="enterprise_server">
        <vers num="3.5" />
        <vers num="3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0238" published="2000-03-17" name="CVE-2000-0238" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in the web server for Norton AntiVirus for Internet Email Gateways allows remote attackers to cause a denial of service via a long URL.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1064" source="BID" adv="1">1064</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=s8d1f3e3.036@kib.co.kodiak.ak.us" source="BUGTRAQ">20000317 DoS with NAVIEG</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="norton_antivirus">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":internet_email_gateways" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0239" published="2000-03-15" name="CVE-2000-0239" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in the MERCUR WebView WebMail server allows remote attackers to cause a denial of service via a long mail_user parameter in the GET request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ussrback.com/labs36.html" source="BUGTRAQ">20000315 Local / Remote  DoS Attack in MERCUR WebView WebMail-Client 1.0</ref>
      <ref url="http://www.securityfocus.com/bid/1056" source="BID">1056</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95325335825295&amp;w=2" source="BUGTRAQ">20000315 Local / Remote  DoS Attack in MERCUR WebView WebMail-Client 1.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="atrium_software" name="mercur_imap4_server">
        <vers num="3.20.01" />
      </prod>
      <prod vendor="atrium_software" name="mercur_mailserver">
        <vers num="3.2" />
      </prod>
      <prod vendor="atrium_software" name="mercur_pop3_server">
        <vers num="3.20.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0240" published="2000-03-21" name="CVE-2000-0240" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">vqSoft vqServer program allows remote attackers to read arbitrary files via a /........../ in the URL, a variation of a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1067" source="BID" patch="1" adv="1">1067</ref>
      <ref url="http://www.vqsoft.com/vq/server/faqs/dotdotbug.html" source="CONFIRM">http://www.vqsoft.com/vq/server/faqs/dotdotbug.html</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=4.1.20000321084646.0095c7f0@olga.swip.net" source="BUGTRAQ">20000321 vqserver /........../</ref>
      <ref url="http://www.osvdb.org/270" source="OSVDB">270</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vqsoft" name="vqserver">
        <vers num="1.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0241" published="2000-03-21" name="CVE-2000-0241" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">vqSoft vqServer stores sensitive information such as passwords in cleartext in the server.cfg file, which allows attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=4.1.20000321084646.0095c7f0@olga.swip.net" source="BUGTRAQ" adv="1">20000321 vqserver /........../</ref>
      <ref url="http://www.securityfocus.com/bid/1068" source="BID" adv="1">1068</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vqsoft" name="vqserver">
        <vers num="1.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0242" published="2000-03-25" name="CVE-2000-0242" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WindMail allows remote attackers to read arbitrary files or execute commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1073" source="BID" patch="1" adv="1">1073</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-03-22&amp;msg=20000325224146.6839.qmail@securityfocus.com" source="BUGTRAQ">20000325 Windmail allow web user get any file</ref>
    </refs>
    <vuln_soft>
      <prod vendor="geocel" name="windmail">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0243" published="2000-03-25" name="CVE-2000-0243" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">AnalogX SimpleServer:WWW HTTP server 1.03 allows remote attackers to cause a denial of service via a short GET request to cgi-bin.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1076" source="BID" patch="1" adv="1">1076</ref>
      <ref url="http://www.analogx.com/contents/download/network/sswww.htm" source="MISC">http://www.analogx.com/contents/download/network/sswww.htm</ref>
      <ref url="http://xforce.iss.net/static/4189.php" source="XF">simpleserver-exception-dos(4189)</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=web-5645555@post2.rnci.com" source="BUGTRAQ">20000324 AnalogX SimpleServer 1.03 Remote Crash" at: </ref>
      <ref url="http://www.osvdb.org/1265" source="OSVDB">1265</ref>
    </refs>
    <vuln_soft>
      <prod vendor="analogx" name="simpleserver_www">
        <vers num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0244" published="2000-03-29" name="CVE-2000-0244" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Citrix ICA (Independent Computing Architecture) protocol uses weak encryption (XOR) for user authentication.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1077" source="BID" patch="1" adv="1">1077</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.BSO.4.20.0003290949280.2640-100000@naughty.monkey.org" source="BUGTRAQ">20000328 Citrix ICA Basic Encryption</ref>
    </refs>
    <vuln_soft>
      <prod vendor="citrix" name="metaframe">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":unix" />
        <vers prev="1" num="1.8" edition="" />
        <vers prev="1" num="1.8" edition=":windows_nt_4.0_tse" />
        <vers prev="1" num="1.8" edition=":windows_2000" />
      </prod>
      <prod vendor="citrix" name="winframe">
        <vers num="3.5_1.8_for_windows_nt" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0245" published="2000-03-27" name="CVE-2000-0245" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Vulnerability in SGI IRIX objectserver daemon allows remote attackers to create user accounts.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200003290852.aa27218@blaze.arl.mil" source="BUGTRAQ" patch="1" adv="1">20000328 Objectserver vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/4206" source="XF">irix-objectserver-create-accounts(4206)</ref>
      <ref url="http://www.securityfocus.com/bid/1079" source="BID">1079</ref>
      <ref url="http://www.osvdb.org/1267" source="OSVDB">1267</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/k-030.shtml" source="CIAC">K-030</ref>
      <ref url="ftp://sgigate.sgi.com/security/20000303-01-PX" source="SGI">20000303-01-PX</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="5.2" />
        <vers num="5.3" edition="" />
        <vers num="5.3" edition=":xfs" />
        <vers num="6.0" />
        <vers num="6.0.1" edition="" />
        <vers num="6.0.1" edition=":xfs" />
        <vers num="6.1" />
        <vers num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0246" published="2000-03-30" name="CVE-2000-0246" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the "Virtualized UNC Share" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-019.asp" source="MS">MS00-019</ref>
      <ref url="http://www.securityfocus.com/bid/1081" source="BID">1081</ref>
      <ref url="http://www.microsoft.com/technet/support/kb.asp?ID=249599" source="MSKB">Q249599</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="commercial_internet_system">
        <vers num="2.0" />
        <vers num="2.5" />
      </prod>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
      <prod vendor="microsoft" name="proxy_server">
        <vers num="2.0" />
      </prod>
      <prod vendor="microsoft" name="site_server">
        <vers num="3.0" />
      </prod>
      <prod vendor="microsoft" name="site_server_commerce">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0247" published="2000-03-22" name="CVE-2000-0247" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unknown vulnerability in Generic-NQS (GNQS) allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0236.html" source="BUGTRAQ" patch="1" adv="1">20000322 Local root compromise in GNQS 3.50.6 and 3.50.7</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/4306" source="XF" adv="1">generic-nqs-local-root(4306)</ref>
      <ref url="http://www.securityfocus.com/bid/1842" source="BID" adv="1">1842</ref>
      <ref url="http://ftp.gnqs.org/pub/gnqs/source/by-version-number/v3.50/Generic-NQS-3.50.8-ChangeLog.txt" source="MISC">http://ftp.gnqs.org/pub/gnqs/source/by-version-number/v3.50/Generic-NQS-3.50.8-ChangeLog.txt</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:13.generic-nqs.asc" source="FREEBSD">FreeBSD-SA-00:13</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnqs" name="gnqs">
        <vers num="3.50.6" />
        <vers num="3.50.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0248" published="2000-04-24" name="CVE-2000-0248" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The web GUI for the Linux Virtual Server (LVS) software in the Red Hat Linux Piranha package has a backdoor password that allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/alerts/advise46.php3" source="ISS" patch="1" adv="1">20000424 Backdoor Password in Red Hat Linux Virtual Server Package</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="6.2" edition="" />
        <vers num="6.2" edition=":alpha" />
        <vers num="6.2" edition=":sparc" />
        <vers num="6.2" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0249" published="2000-04-26" name="CVE-2000-0249" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The AIX Fast Response Cache Accelerator (FRCA) allows local users to modify arbitrary files via the configuration capability in the frcactrl program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/alerts/advise47.php3" source="ISS">20000426 Insecure file handling in IBM AIX frcactrl program</ref>
      <ref url="http://www.securityfocus.com/bid/1152" source="BID">1152</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0250" published="2000-04-14" name="CVE-2000-0250" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The crypt function in QNX uses weak encryption, which allows local users to decrypt passwords.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1114" source="BID">1114</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0072.html" source="BUGTRAQ" adv="1">20000414 qnx crypt comprimised</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qnx" name="qnx">
        <vers num="4.25a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0251" published="2000-04-06" name="CVE-2000-0251" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">HP-UX 11.04 VirtualVault (VVOS) sends data to unprivileged processes via an interface that has multiple aliased IP addresses.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1090" source="BID">1090</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0021.html" source="HP">HPSBUX0004-112</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.4" />
      </prod>
      <prod vendor="hp" name="vvos">
        <vers num="3.50" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0252" published="2000-04-11" name="CVE-2000-0252" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The dansie shopping cart application cart.pl allows remote attackers to execute commands via a shell metacharacters in a form variable.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1115" source="BID" adv="1">1115</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0051.html" source="BUGTRAQ" adv="1">20000411 Back Door in Commercial Shopping Cart</ref>
      <ref url="http://xforce.iss.net/static/4975.php" source="XF">dansie-shell-metacharacters</ref>
    </refs>
    <vuln_soft>
      <prod vendor="craig_dansie" name="dansie_shopping_cart">
        <vers num="3.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0253" published="2000-04-11" name="CVE-2000-0253" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The dansie shopping cart application cart.pl allows remote attackers to modify sensitive purchase information via hidden form fields.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4621.php" source="XF" adv="1">shopping-cart-form-tampering</ref>
      <ref url="http://www.securityfocus.com/bid/1115" source="BID" adv="1">1115</ref>
    </refs>
    <vuln_soft>
      <prod vendor="craig_dansie" name="dansie_shopping_cart">
        <vers num="3.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0254" published="2000-04-14" name="CVE-2000-0254" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The dansie shopping cart application cart.pl allows remote attackers to obtain the shopping cart database and configuration information via a URL that references either the env, db, or vars form variables.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4954.php" source="XF" adv="1">dansie-form-variables</ref>
      <ref url="http://www.securityfocus.com/bid/1115" source="BID" adv="1">1115</ref>
    </refs>
    <vuln_soft>
      <prod vendor="craig_dansie" name="dansie_shopping_cart">
        <vers num="3.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0255" published="2000-04-05" name="CVE-2000-0255" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Nbase-Xyplex EdgeBlaster router allows remote attackers to cause a denial of service via a scan for the FormMail CGI program.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1091" source="BID" adv="1">1091</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0022.html" source="BUGTRAQ" adv="1">20000405 SilverBack Security Advisory: Nbase-Xyplex DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nbase-xyplex" name="edgeblaster">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0256" published="2000-04-19" name="CVE-2000-0256" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflows in htimage.exe and Imagemap.exe in FrontPage 97 and 98 Server Extensions allow a user to conduct activities that are not otherwise available through the web site, aka the "Server-Side Image Map Components" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1117" source="BID" patch="1" adv="1">1117</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-028.asp" source="MS" patch="1" adv="1">MS00-028</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34720" source="XF">frontpage-cern-bo(34720)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/470458/100/0/threaded" source="BUGTRAQ">20070603 CERN &amp;#304;mage Map Dispatcher</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="frontpage">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="personal_web_server">
        <vers num="2.0" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0257" published="2000-04-19" name="CVE-2000-0257" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the NetWare remote web administration utility allows remote attackers to cause a denial of service or execute commands via a long URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1118" source="BID" patch="1" adv="1">1118</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.21.0004171825340.10088-100000@nimue.tpi.pl" source="BUGTRAQ" adv="1">20000418 Novell Netware 5.1 (server 5.00h, Dec 11, 1999)...</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="netware">
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0258" published="2000-04-12" name="CVE-2000-0258" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IIS 4.0 and 5.0 allows remote attackers to cause a denial of service by sending many URLs with a large number of escaped characters, aka the "Myriad Escaped Characters" Vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-023.asp" source="MS">MS00-023</ref>
      <ref url="http://www.securityfocus.com/bid/1101" source="BID">1101</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0259" published="2000-04-12" name="CVE-2000-0259" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The default permissions for the Cryptography\Offload registry key used by the OffloadModExpo in Windows NT 4.0 allows local users to obtain compromise the cryptographic keys of other users.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1105" source="BID" patch="1" adv="1">1105</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-024.asp" source="MS" patch="1" adv="1">MS00-024</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="terminal_server">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0260" published="2000-04-14" name="CVE-2000-0260" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the dvwssr.dll DLL in Microsoft Visual Interdev 1.0 allows users to cause a denial of service or execute commands, aka the "Link View Server-Side Component" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-025.asp" source="MS">MS00-025</ref>
      <ref url="http://www.securityfocus.com/bid/1109" source="BID">1109</ref>
      <ref url="http://www.osvdb.org/282" source="OSVDB">282</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="frontpage">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="visual_interdev">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0261" published="2000-04-12" name="CVE-2000-0261" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The AVM KEN! web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=383085010.956159226625.JavaMail.root@web305-mc.mail.com" source="BUGTRAQ">20000418 AVM's Statement</ref>
      <ref url="http://www.securityfocus.com/bid/1103" source="BID">1103</ref>
      <ref url="http://www.osvdb.org/1282" source="OSVDB">1282</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0073.html" source="BUGTRAQ">20000415 (no subject)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avm" name="ken">
        <vers num="1.3.10" />
        <vers num="1.4.30" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0262" published="2000-04-12" name="CVE-2000-0262" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The AVM KEN! ISDN Proxy server allows remote attackers to cause a denial of service via a malformed request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=383085010.956159226625.JavaMail.root@web305-mc.mail.com" source="BUGTRAQ">20000418 AVM's Statement</ref>
      <ref url="http://www.securityfocus.com/bid/1103" source="BID">1103</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0073.html" source="BUGTRAQ">20000415 (no subject)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avm" name="ken">
        <vers num="1.3.10" />
        <vers num="1.4.30" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0263" published="2000-04-16" name="CVE-2000-0263" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The X font server xfs in Red Hat Linux 6.x allows an attacker to cause a denial of service via a malformed request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1111" source="BID" adv="1">1111</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0079.html" source="BUGTRAQ" adv="1">20000416 xfs</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":sparc" />
        <vers num="6.0" edition=":i386" />
        <vers num="6.0" edition=":alpha" />
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":sparc" />
        <vers num="6.1" edition=":i386" />
        <vers num="6.1" edition=":alpha" />
        <vers num="6.2" edition="" />
        <vers num="6.2" edition=":alpha" />
        <vers num="6.2" edition=":sparc" />
        <vers num="6.2" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0264" published="2000-04-17" name="CVE-2000-0264" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Panda Security 3.0 with registry editing disabled allows users to edit the registry and gain privileges by directly executing a .reg file or using other methods.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://updates.pandasoftware.com/docs/us/Avoidvulnerability.zip" source="CONFIRM">http://updates.pandasoftware.com/docs/us/Avoidvulnerability.zip</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=38FB45F2.550EA000@teleline.es" source="BUGTRAQ">20000417 bugs in Panda Security 3.0</ref>
      <ref url="http://www.securityfocus.com/bid/1119" source="BID">1119</ref>
    </refs>
    <vuln_soft>
      <prod vendor="panda" name="panda_security">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0265" published="2000-04-17" name="CVE-2000-0265" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Panda Security 3.0 allows users to uninstall the Panda software via its Add/Remove Programs applet.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=38FB45F2.550EA000@teleline.es" source="BUGTRAQ" patch="1" adv="1">20000417 bugs in Panda Security 3.0</ref>
      <ref url="http://www.securityfocus.com/bid/1119" source="BID" patch="1" adv="1">1119</ref>
      <ref url="http://updates.pandasoftware.com/docs/us/Avoidvulnerability.zip" source="CONFIRM">http://updates.pandasoftware.com/docs/us/Avoidvulnerability.zip</ref>
    </refs>
    <vuln_soft>
      <prod vendor="panda" name="panda_security">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0266" published="2000-04-18" name="CVE-2000-0266" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Internet Explorer 5.01 allows remote attackers to bypass the cross frame security policy via a malicious applet that interacts with the Java JSObject to modify the DOM properties to set the IFRAME to an arbitrary Javascript URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1121" source="BID">1121</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=38FC6130.D6D178FD@nat.bg" source="BUGTRAQ">20000418 IE 5 security vulnerablity - circumventing Cross-frame security policy using Java/JavaScript (and disabling Active Scripting is not that easy)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0" />
        <vers num="5.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0267" published="2000-04-20" name="CVE-2000-0267" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Cisco Catalyst 5.4.x allows a user to gain access to the "enable" mode without a password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/catos-enable-bypass-pub.shtml" source="CISCO" adv="1">20000419 Cisco Catalyst Enable Password Bypass Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/1122" source="BID">1122</ref>
      <ref url="http://www.osvdb.org/1288" source="OSVDB">1288</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="catos">
        <vers num="5.4(1)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0268" published="2000-04-20" name="CVE-2000-0268" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco IOS 11.x and 12.x allows remote attackers to cause a denial of service by sending the ENVIRON option to the Telnet daemon before it is ready to accept it, which causes the system to reboot.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/iostelnetopt-pub.shtml" source="CISCO" patch="1" adv="1">20000420 Cisco IOS Software TELNET Option Handling Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/1123" source="BID">1123</ref>
      <ref url="http://www.osvdb.org/1289" source="OSVDB">1289</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="accesspath">
        <vers num="ls-3" />
        <vers num="ts-3" />
        <vers num="vs-3" />
      </prod>
      <prod vendor="cisco" name="as5200">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="as5300">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="as5800">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="system_controller_3640">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="3660_router">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="7100_router">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="7200_router">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="7500_router">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="ubr7200">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="voice_gateway_as5800">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="ios">
        <vers num="11.3aa" />
        <vers num="12.0(2)" />
        <vers num="12.0(2)xc" />
        <vers num="12.0(2)xd" />
        <vers num="12.0(2)xf" />
        <vers num="12.0(2)xg" />
        <vers num="12.0(3)t2" />
        <vers num="12.0(4)" />
        <vers num="12.0(4)s" />
        <vers num="12.0(4)t" />
        <vers num="12.0(5)" />
        <vers num="12.0(6)" />
        <vers num="12.0(7)t" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0269" published="2000-04-18" name="CVE-2000-0269" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Emacs 20 does not properly set permissions for a slave PTY device when starting a new subprocess, which allows local users to read or modify communications between Emacs and the subprocess.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1125" source="BID" patch="1" adv="1">1125</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-04-15&amp;msg=tg4s8zioxq.fsf@mercury.rus.uni-stuttgart.de" source="BUGTRAQ">20000418 RUS-CERT Advisory 200004-01: GNU Emacs 20</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="emacs">
        <vers num="20.0" />
        <vers num="20.1" />
        <vers num="20.2" />
        <vers num="20.3" />
        <vers num="20.4" />
        <vers num="20.5" />
        <vers num="20.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0270" published="2000-04-18" name="CVE-2000-0270" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">The make-temp-name Lisp function in Emacs 20 creates temporary files with predictable names, which allows attackers to conduct a symlink attack.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1126" source="BID" patch="1" adv="1">1125</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-04-15&amp;msg=tg4s8zioxq.fsf@mercury.rus.uni-stuttgart.de" source="BUGTRAQ">20000418 RUS-CERT Advisory 200004-01: GNU Emacs 20</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="emacs">
        <vers num="20.0" />
        <vers num="20.1" />
        <vers num="20.2" />
        <vers num="20.3" />
        <vers num="20.4" />
        <vers num="20.5" />
        <vers num="20.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0271" published="2000-04-18" name="CVE-2000-0271" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">read-passwd and other Lisp functions in Emacs 20 do not properly clear the history of recently typed keys, which allows an attacker to read unencrypted passwords.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1125" source="BID" patch="1" adv="1">1125</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-04-15&amp;msg=tg4s8zioxq.fsf@mercury.rus.uni-stuttgart.de" source="BUGTRAQ">20000418 RUS-CERT Advisory 200004-01: GNU Emacs 20</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="emacs">
        <vers num="20.0" />
        <vers num="20.1" />
        <vers num="20.2" />
        <vers num="20.3" />
        <vers num="20.4" />
        <vers num="20.5" />
        <vers num="20.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0272" published="2000-04-20" name="CVE-2000-0272" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">RealNetworks RealServer allows remote attackers to cause a denial of service by sending malformed input to the server at port 7070.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1128" source="BID" patch="1" adv="1">1128</ref>
      <ref url="http://service.real.com/help/faq/servg270.html" source="CONFIRM">http://service.real.com/help/faq/servg270.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95625288231045&amp;w=2" source="BUGTRAQ" adv="1">20000420 Remote DoS attack in Real Networks Real Server Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realserver">
        <vers num="7.0" />
        <vers num="basic" />
        <vers num="g2_1.0" />
        <vers num="intranet" />
        <vers num="plus" />
        <vers num="pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0273" published="2000-04-09" name="CVE-2000-0273" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PCAnywhere allows remote attackers to cause a denial of service by terminating the connection before PCAnywhere provides a login prompt.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1095" source="BID" adv="1">1095</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0031.html" source="BUGTRAQ" adv="1">20000409 A funny way to DOS pcANYWHERE8.0 and 9.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="pcanywhere">
        <vers num="8.0" />
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0274" published="2000-04-10" name="CVE-2000-0274" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The Linux trustees kernel patch allows attackers to cause a denial of service by accessing a file or directory with a long name.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.braysystems.com/linux/trustees.html" source="CONFIRM">http://www.braysystems.com/linux/trustees.html</ref>
      <ref url="http://www.securityfocus.com/bid/1096" source="BID">1096</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0035.html" source="BUGTRAQ">20000410 linux trustees 1.5 long path name vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bray_systems" name="linux_trustees">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0275" published="2000-04-10" name="CVE-2000-0275" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">CRYPTOCard CryptoAdmin for PalmOS uses weak encryption to store a user's PIN number, which allows an attacker with access to the .PDB file to generate valid PT-1 tokens after cracking the PIN.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1097" source="BID">1097</ref>
      <ref url="http://www.l0pht.com/advisories/cc-pinextract.txt" source="L0PHT" adv="1">20000410 CRYPTOCard PalmToken PIN Extraction</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0033.html" source="BUGTRAQ">20000410 CRYPTOAdmin 4.1 server with PalmPilot PT-1 token 1.04 PIN Extract ion</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cryptocard" name="cryptoadmin">
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0276" published="2000-04-10" name="CVE-2000-0276" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">BeOS 4.5 and 5.0 allow local users to cause a denial of service via malformed direct system calls using interrupt 37.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1098" source="BID" adv="1">1098</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000410131628.659.qmail@securityfocus.com" source="BUGTRAQ">20000410 BeOS syscall bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="be" name="beos">
        <vers num="4.5" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0277" published="2000-04-03" name="CVE-2000-0277" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Microsoft Excel 97 and 2000 does not warn the user when executing Excel Macro Language (XLM) macros in external text files, which could allow an attacker to execute a macro virus, aka the "XLM Text Macro" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS00-022.asp" source="MS">MS00-022</ref>
      <ref url="http://www.securityfocus.com/bid/1087" source="BID">1087</ref>
      <ref url="http://www.osvdb.org/1272" source="OSVDB">1272</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2000" />
        <vers num="97" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0278" published="2000-08-03" name="CVE-2000-0278" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The SalesLogix Eviewer allows remote attackers to cause a denial of service by accessing the URL for the slxweb.dll administration program, which does not authenticate the user.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1089" source="BID" adv="1">1089</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/current/0006.html" source="BUGTRAQ">20000331 SalesLogix Eviewer Web App Bug: URL request crashes eviewer web application</ref>
    </refs>
    <vuln_soft>
      <prod vendor="saleslogix" name="corporation_eviewer">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0279" published="2000-04-07" name="CVE-2000-0279" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BeOS allows remote attackers to cause a denial of service via malformed packets whose length field is less than the length of the headers.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1100" source="BID">1100</ref>
      <ref url="http://bebugs.be.com/devbugs/detail.php3?oid=2505312" source="MISC">http://bebugs.be.com/devbugs/detail.php3?oid=2505312</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0029.html" source="BUGTRAQ">20000407 BeOS Networking DOS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="be" name="beos">
        <vers num="4.0" />
        <vers num="4.5" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0280" published="2000-04-03" name="CVE-2000-0280" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Buffer overflow in the RealNetworks RealPlayer client versions 6 and 7 allows remote attackers to cause a denial of service via a long Location URL.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1088" source="BID" adv="1">1088</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0018.html" source="BUGTRAQ" adv="1">20000403 Win32 RealPlayer 6/7 Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realplayer">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":win" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":win" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0281" published="2000-03-26" name="CVE-2000-0281" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Buffer overflow in the Napster client beta 5 allows remote attackers to cause a denial of service via a long message.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0299.html" source="BUGTRAQ" adv="1">20000330 Napster, Inc. response to Colten Edwards</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0277.html" source="BUGTRAQ" adv="1">20000326 neat little napster bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="napster" name="napster_client">
        <vers num="beta_5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0282" published="2000-04-12" name="CVE-2000-0282" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">TalentSoft webpsvr daemon in the Web+ shopping cart application allows remote attackers to read arbitrary files via a .. (dot dot) attack on the webplus CGI program.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1102" source="BID" patch="1" adv="1">1102</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0050.html" source="BUGTRAQ" patch="1" adv="1">20000412 TalentSoft Web+ Input Validation Bug Vulnerability</ref>
      <ref url="ftp://ftp.talentsoft.com/Download/Webplus/Unix/Patches/Webplus46p%20Read%20me.html" source="CONFIRM">ftp://ftp.talentsoft.com/Download/Webplus/Unix/Patches/Webplus46p%20Read%20me.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="talentsoft" name="web+">
        <vers num="4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0283" published="2000-04-12" name="CVE-2000-0283" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The default installation of IRIX Performance Copilot allows remote attackers to access sensitive system information via the pmcd daemon.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1106" source="BID" patch="1" adv="1">1106</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0056.html" source="BUGTRAQ" patch="1" adv="1">20000412 Performance Copilot for IRIX 6.5</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
        <vers num="6.5.3" />
        <vers num="6.5.3f" />
        <vers num="6.5.3m" />
        <vers num="6.5.4" />
        <vers num="6.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0284" published="2000-04-16" name="CVE-2000-0284" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in University of Washington imapd version 4.7 allows users with a valid account to execute commands via LIST or other commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1110" source="BID" adv="1">1110</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0085.html" source="BUGTRAQ">20000416 imapd4r1 v12.264</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0074.html" source="BUGTRAQ" adv="1">20000416 imapd4r1 v12.264</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_washington" name="imap">
        <vers num="12.264" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0285" published="2000-04-16" name="CVE-2000-0285" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in XFree86 3.3.x allows local users to execute arbitrary commands via a long -xkbmap parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0076.html" source="BUGTRAQ" adv="1">20000416 XFree86 server overflow</ref>
      <ref url="http://www.securityfocus.com/bid/1306" source="BID">1306</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xfree86_project" name="x11r6">
        <vers num="3.3.6" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0286" published="2000-04-16" name="CVE-2000-0286" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">X fontserver xfs allows local users to cause a denial of service via malformed input to the server.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1111" source="BID" adv="1">1111</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0079.html" source="BUGTRAQ">20000416 xfs</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":sparc" />
        <vers num="6.0" edition=":i386" />
        <vers num="6.0" edition=":alpha" />
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":sparc" />
        <vers num="6.1" edition=":i386" />
        <vers num="6.1" edition=":alpha" />
        <vers num="6.2" edition="" />
        <vers num="6.2" edition=":alpha" />
        <vers num="6.2" edition=":sparc" />
        <vers num="6.2" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0287" published="2000-04-12" name="CVE-2000-0287" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The BizDB CGI script bizdb-search.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the dbname parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1104" source="BID" patch="1" adv="1">1104</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0058.html" source="BUGTRAQ">20000412 BizDB Search Script Enables Shell Command Execution at the Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cnc" name="technology_bizdb">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0288" published="2000-04-12" name="CVE-2000-0288" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Infonautics getdoc.cgi allows remote attackers to bypass the payment phase for accessing documents via a modified form variable.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0049.html" source="BUGTRAQ">20000412 Infonautic's getdoc.cgi may allow unauthorized access to documents</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0289" published="2000-03-27" name="CVE-2000-0289" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IP masquerading in Linux 2.2.x allows remote attackers to route UDP packets through the internal interface by modifying the external source IP address and port number to match those of an established connection.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1078" source="BID" patch="1" adv="1">1078</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0284.html" source="BUGTRAQ" adv="1">20000327 Security Problems with Linux 2.2.x IP Masquerading</ref>
      <ref url="http://www.novell.com/linux/security/advisories/suse_security_announce_48.html" source="SUSE">20000520 Security hole in kernel &lt; 2.2.15</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.1" />
        <vers num="2.2" edition="" />
        <vers num="2.2" edition=":pre_potato" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.2.10" />
        <vers num="2.2.12" />
        <vers num="2.2.14" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":i386" />
        <vers num="6.0" edition=":alpha" />
        <vers num="6.0" edition=":sparc" />
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":i386" />
        <vers num="6.1" edition=":alpha" />
        <vers num="6.1" edition=":sparc" />
        <vers num="6.2" edition="" />
        <vers num="6.2" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0290" published="2000-03-31" name="CVE-2000-0290" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Webstar HTTP server allows remote attackers to cause a denial of service via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0005.html" source="BUGTRAQ">20000331 Webstar 4.0 Buffer overflow vulnerability</ref>
      <ref url="http://xforce.iss.net/static/4792.php" source="XF">macos-webstar-get-bo(4792)</ref>
      <ref url="http://www.securityfocus.com/bid/1822" source="BID">1822</ref>
    </refs>
    <vuln_soft>
      <prod vendor="4d" name="webstar_http_server">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0291" published="2000-04-16" name="CVE-2000-0291" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in Star Office 5.1 allows attackers to cause a denial of service by embedding a long URL within a document.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1112" source="BID" adv="1">1112</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0077.html" source="BUGTRAQ" adv="1">20000416 StarOffice 5.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="staroffice">
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0292" published="2000-04-19" name="CVE-2000-0292" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Adtran MX2800 M13 Multiplexer allows remote attackers to cause a denial of service via a ping flood to the Ethernet interface, which causes the device to crash.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.10.10004190908140.32750-100000@localhost.localdomain" source="BUGTRAQ" adv="1">20000418 Adtran DoS</ref>
      <ref url="http://www.securityfocus.com/bid/1129" source="BID" adv="1">1129</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adtran" name="mx2800">
        <vers num="m13" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0293" published="2000-05-02" name="CVE-2000-0293" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">aaa_base in SuSE Linux 6.3, and cron.daily in earlier versions, allow local users to delete arbitrary files by creating files whose names include spaces, which are then incorrectly interpreted by aaa_base when it deletes expired files from the /tmp directory.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1130" source="BID">1130</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="suse_linux">
        <vers num="6.0" />
        <vers num="6.1" edition="alpha" />
        <vers num="6.2" />
        <vers num="6.3" edition="" />
        <vers num="6.3" edition=":ppc" />
        <vers num="6.3" edition="alpha" />
        <vers num="6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0294" published="2000-04-10" name="CVE-2000-0294" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in healthd for FreeBSD allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/advisory.html?id=2162" source="FREEBSD">FreeBSD-SA-00:12</ref>
      <ref url="http://www.securityfocus.com/bid/1107" source="BID">1107</ref>
      <ref url="http://www.osvdb.org/606" source="OSVDB">606</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jim_housley" name="healthd">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0295" published="2000-04-21" name="CVE-2000-0295" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in LCDproc allows remote attackers to gain root privileges via the screen_add command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.3.96.1000421010946.15318I-200000@schizo.strange.net" source="BUGTRAQ" patch="1" adv="1">20000420 Remote vulnerability in LCDproc 0.4</ref>
      <ref url="http://www.securityfocus.com/bid/1131" source="BID" patch="1" adv="1">1131</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/4315" source="XF">lcdproc-remote-overflow(4315)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/305589/30/26390/threaded" source="GENTOO">GLSA-200301-07</ref>
      <ref url="http://secunia.com/advisories/7829" source="SECUNIA">7829</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lcdproc" name="lcdproc">
        <vers num="0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0296" published="2000-03-31" name="CVE-2000-0296" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">fcheck allows local users to gain privileges by embedding shell metacharacters into file names that are processed by fcheck.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1086" source="BID" patch="1" adv="1">1086</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/current/0011.html" source="BUGTRAQ">20000331 fcheck v.2.7.45 and insecure use of Perl's system()</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michael_a._gumienny" name="fcheck">
        <vers num="2.7.45" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0297" published="2000-04-03" name="CVE-2000-0297" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Allaire Forums 2.0.5 allows remote attackers to bypass access restrictions to secure conferences via the rightAccessAllForums or rightModerateAllForums variables.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www2.allaire.com/handlers/index.cfm?ID=15099&amp;Method=Full" source="ALLAIRE">ASB00-06</ref>
      <ref url="http://www.securityfocus.com/bid/1085" source="BID">1085</ref>
      <ref url="http://www.osvdb.org/1270" source="OSVDB">1270</ref>
    </refs>
    <vuln_soft>
      <prod vendor="allaire" name="forums">
        <vers num="2.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0298" published="2000-04-07" name="CVE-2000-0298" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The unattended installation of Windows 2000 with the OEMPreinstall option sets insecure permissions for the All Users and Default Users directories.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4278.php" source="XF">win2k-unattended-install(4278)</ref>
      <ref url="http://www.securityfocus.com/bid/1758" source="BID">1758</ref>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0027.html" source="NTBUGTRAQ">20000407 All Users startup folder left open if unattended install and OEMP reinstall=1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0299" published="2000-04-04" name="CVE-2000-0299" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in WebObjects.exe in the WebObjects Developer 4.5 package allows remote attackers to cause a denial of service via an HTTP request with long headers such as Accept.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0020.html" source="BUGTRAQ">20000404 WebObjects DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="webobjects">
        <vers num="4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0300" published="2000-04-06" name="CVE-2000-0300" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The default encryption method of PcAnywhere 9.x uses weak encryption, which allows remote attackers to sniff and decrypt PcAnywhere or NT domain accounts.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1093" source="BID" patch="1" adv="1">1093</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000406030958.23902.qmail@securityfocus.com" source="BUGTRAQ" adv="1">20000405 PcAnywhere weak password encryption</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="pcanywhere">
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0301" published="2000-04-06" name="CVE-2000-0301" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Ipswitch IMAIL server 6.02 and earlier allows remote attackers to cause a denial of service via the AUTH CRAM-MD5 command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1094" source="BID" patch="1" adv="1">1094</ref>
      <ref url="http://support.ipswitch.com/kb/IM-20000208-DM02.htm" source="CONFIRM" patch="1" adv="1">http://support.ipswitch.com/kb/IM-20000208-DM02.htm</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95505800117143&amp;w=2" source="BUGTRAQ" adv="1">20000405 Re: IMAIL (Ipswitch) DoS with Eudora (Qualcomm)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="imail">
        <vers num="5.0" />
        <vers num="5.0.5" />
        <vers num="5.0.6" />
        <vers num="5.0.7" />
        <vers num="5.0.8" />
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0302" published="2000-03-31" name="CVE-2000-0302" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Index Server allows remote attackers to view the source code of ASP files by appending a %20 to the filename in the CiWebHitsFile argument to the null.htw URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-006.asp" source="MS" patch="1" adv="1">MS00-006</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95453598317340&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20000331 Alert: MS Index Server (CISADV000330)</ref>
      <ref url="http://www.securityfocus.com/bid/1084" source="BID">1084</ref>
      <ref url="http://www.osvdb.org/271" source="OSVDB">271</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="index_server">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0303" published="2000-05-03" name="CVE-2000-0303" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Quake3 Arena allows malicious server operators to read or modify files on a client via a dot dot (..) attack.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.quake3arena.com/news/index.html" source="CONFIRM" patch="1" adv="1">http://www.quake3arena.com/news/index.html</ref>
      <ref url="http://xforce.iss.net/alerts/advise50.php3" source="ISS">20000503 Vulnerability in Quake3Arena Auto-Download Feature</ref>
      <ref url="http://www.securityfocus.com/bid/1169" source="BID">1169</ref>
      <ref url="http://www.osvdb.org/7531" source="OSVDB">7531</ref>
    </refs>
    <vuln_soft>
      <prod vendor="id_software" name="quake_3_arena">
        <vers num="1.16n" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0304" published="2000-05-10" name="CVE-2000-0304" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft IIS 4.0 and 5.0 with the IISADMPWD virtual directory installed allows a remote attacker to cause a denial of service via a malformed request to the inetinfo.exe program, aka the "Undelimited .HTR Request" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/alerts/advise52.php3" source="ISS">20000511 Microsoft IIS Remote Denial of Service Attack</ref>
      <ref url="http://www.securityfocus.com/bid/1191" source="BID">1191</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-031.mspx" source="MS">MS00-031</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0305" published="2000-05-19" name="CVE-2000-0305" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Windows 95, Windows 98, Windows 2000, Windows NT 4.0, and Terminal Server systems allow a remote attacker to cause a denial of service by sending a large number of identical fragmented IP packets, aka jolt2 or the "IP Fragment Reassembly" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-029.asp" source="MS">MS00-029</ref>
      <ref url="http://www.securityfocus.com/templates/advisory.html?id=2240" source="BINDVIEW">20000519 jolt2 - Remote DoS against NT, W2K, 9x</ref>
      <ref url="http://www.securityfocus.com/bid/1236" source="BID">1236</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="terminal_server">
        <vers num="" />
      </prod>
      <prod vendor="be" name="beos">
        <vers num="5.0" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_95">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0306" published="2001-03-12" name="CVE-2000-0306" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in calserver in SCO OpenServer allows remote attackers to gain root access via a long message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1998-12-29&amp;msg=AAh6GYsGU1@leshka.chuvashia.su" source="BUGTRAQ">19981229 Local/remote exploit for SCO UNIX.</ref>
      <ref url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.02a" source="SCO" adv="1">SB-99.02</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="openserver">
        <vers prev="1" num="5.04" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0307" published="2001-03-12" name="CVE-2000-0307" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Vulnerability in xserver in SCO UnixWare 2.1.x and OpenServer 5.05 and earlier allows an attacker to cause a denial of service which prevents access to reserved port numbers below 1024.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.07b" source="SCO" patch="1" adv="1">SB-99.07</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="open_desktop">
        <vers num="" />
      </prod>
      <prod vendor="sco" name="openserver">
        <vers prev="1" num="5.05" />
      </prod>
      <prod vendor="sco" name="unixware">
        <vers prev="1" num="2.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0308" published="2001-03-12" name="CVE-2000-0308" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Insecure file permissions for Netscape FastTrack Server 2.x, Enterprise Server 2.0, and Proxy Server 2.5 in SCO UnixWare 7.0.x and 2.1.3 allow an attacker to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.08a" source="SCO" patch="1" adv="1">SB-99.08</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="enterprise_server">
        <vers num="2.0" />
      </prod>
      <prod vendor="netscape" name="fasttrack_server">
        <vers num="2.0" />
        <vers num="2.01" />
      </prod>
      <prod vendor="netscape" name="proxy_server">
        <vers num="2.5" />
      </prod>
      <prod vendor="sco" name="unixware">
        <vers prev="1" num="2.1.3" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0309" published="2001-03-12" name="CVE-2000-0309" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The i386 trace-trap handling in OpenBSD 2.4 with DDB enabled allows a local user to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/6126" source="OSVDB">6126</ref>
      <ref url="http://www.openbsd.org/errata24.html#trctrap" source="OPENBSD">19990212 i386 trace-trap handling when DDB was configured could cause a system crash.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0310" published="2001-03-12" name="CVE-2000-0310" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IP fragment assembly in OpenBSD 2.4 allows a remote attacker to cause a denial of service by sending a large number of fragmented packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/7539" source="OSVDB">7539</ref>
      <ref url="http://www.openbsd.org/errata24.html#maxqueue" source="OPENBSD">19990217 IP fragment assembly can bog the machine excessively and cause problems.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0311" published="2000-04-20" name="CVE-2000-0311" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The Windows 2000 domain controller allows a malicious user to modify Active Directory information by modifying an unprotected attribute, aka the "Mixed Object Access" vulnerability.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-026.asp" source="MS">MS00-026</ref>
      <ref url="http://www.securityfocus.com/bid/1145" source="BID">1145</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0312" published="2001-03-12" name="CVE-2000-0312" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">cron in OpenBSD 2.5 allows local users to gain root privileges via an argv[] that is not NULL terminated, which is passed to cron's fake popen function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.openbsd.org/errata25.html#cron" source="OPENBSD" patch="1">19990830 In cron(8), make sure argv[] is NULL terminated in the fake popen() and run sendmail as the user, not as root.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0313" published="2001-03-12" name="CVE-2000-0313" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Vulnerability in OpenBSD 2.6 allows a local user to change interface media configurations.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/7540" source="OSVDB">7540</ref>
      <ref url="http://www.openbsd.org/errata.html#ifmedia" source="OPENBSD">19991109 Any user can change interface media configurations.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0314" published="2001-03-12" name="CVE-2000-0314" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">traceroute in NetBSD 1.3.3 and Linux systems allows local users to flood other systems by providing traceroute with a large waittime (-w) option, which is not parsed properly and sets the time delay for sending packets to zero.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA1999-004.txt.asc" source="NETBSD" patch="1" adv="1">NetBSD-SA1999-004</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91893782027835&amp;w=2" source="BUGTRAQ" adv="1">19990213 traceroute as a flooder</ref>
      <ref url="http://www.osvdb.org/7574" source="OSVDB">7574</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.0.34" />
      </prod>
      <prod vendor="digital" name="unix">
        <vers num="4.0" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers prev="1" num="1.3.3" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="2.0.34" />
      </prod>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="2.0.34" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0315" published="2001-03-12" name="CVE-2000-0315" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">traceroute in NetBSD 1.3.3 and Linux systems allows local unprivileged users to modify the source address of the packets, which could be used in spoofing attacks.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA1999-004.txt.asc" source="NETBSD" patch="1" adv="1">NetBSD-SA1999-004</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91893782027835&amp;w=2" source="BUGTRAQ" adv="1">19990213 traceroute as a flooder</ref>
      <ref url="http://www.osvdb.org/7575" source="OSVDB">7575</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.0.34" />
      </prod>
      <prod vendor="digital" name="unix">
        <vers num="4.0" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers prev="1" num="1.3.3" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="2.0.34" />
      </prod>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="2.0.34" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0316" published="2000-04-24" name="CVE-2000-0316" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Solaris 7 lp allows local users to gain root privileges via a long -d option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1143" source="BID">1143</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0191.html" source="BUGTRAQ">20000424 Solaris 7 x86 lp exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0317" published="2000-04-24" name="CVE-2000-0317" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Solaris 7 lpset allows local users to gain root privileges via a long -r option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1138" source="BID" patch="1" adv="1">1138</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0236.html" source="BUGTRAQ" adv="1">20000424 Solaris 7 x86 lpset exploit.</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0192.html" source="BUGTRAQ" adv="1">20000424 Solaris 7 x86 lpset exploit.</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95729763119559&amp;w=2" source="BUGTRAQ">20000427 Re: Solaris/SPARC 2.7 lpset exploit (well not likely !)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0318" published="2000-04-21" name="CVE-2000-0318" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Atrium Mercur Mail Server 3.2 allows local attackers to read other user's email and create arbitrary files via a dot dot (..) attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1144" source="BID" adv="1">1144</ref>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0057.html" source="NTBUGTRAQ">20000413 Security problems with Atrium Mercur Mailserver 3.20</ref>
    </refs>
    <vuln_soft>
      <prod vendor="atrium_software" name="mercur_mailserver">
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0319" published="2000-04-23" name="CVE-2000-0319" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">mail.local in Sendmail 8.10.x does not properly identify the .\n string which identifies the end of message text, which allows a remote attacker to cause a denial of service or corrupt mailboxes via a message line that is 2047 characters long and ends in .\n.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1146" source="BID" patch="1" adv="1">1146</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=2694.000424@SECURITY.NNOV.RU" source="BUGTRAQ">20000424 unsafe fgets() in sendmail's mail.local</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eric_allman" name="sendmail">
        <vers num="5.58" />
        <vers num="5.59" />
        <vers num="8.6.x" />
        <vers num="8.7.1" />
        <vers num="8.7.2" />
        <vers num="8.7.3" />
        <vers num="8.7.4" />
        <vers num="8.7.5" />
        <vers num="8.7.6" />
        <vers num="8.7.x" />
        <vers num="8.8" />
        <vers num="8.8.1" />
        <vers num="8.8.2" />
        <vers num="8.8.3" />
        <vers num="8.8.4" />
        <vers num="8.8.5" />
        <vers num="8.8.x" />
        <vers num="8.9.1" />
        <vers num="8.9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0320" published="2000-04-21" name="CVE-2000-0320" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Qpopper 2.53 and 3.0 does not properly identify the \n string which identifies the end of message text, which allows a remote attacker to cause a denial of service or corrupt mailboxes via a message line that is 1023 characters long and ends in \n.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=9763.000421@SECURITY.NNOV.RU" source="BUGTRAQ" patch="1" adv="1">20000421 unsafe fgets() in qpopper</ref>
      <ref url="http://www.securityfocus.com/bid/1133" source="BID" patch="1" adv="1">1133</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qualcomm" name="qpopper">
        <vers num="2.53" />
        <vers num="3.0" />
      </prod>
      <prod vendor="sun" name="cobalt_raq_2">
        <vers num="" />
      </prod>
      <prod vendor="sun" name="cobalt_raq_3i">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0321" published="2000-04-24" name="CVE-2000-0321" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in IC Radius package allows a remote attacker to cause a denial of service via a long user name.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1147" source="BID" adv="1">1147</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0190.html" source="BUGTRAQ" adv="1">20000424 Buffer Overflow in version .14</ref>
    </refs>
    <vuln_soft>
      <prod vendor="icradius" name="icradius">
        <vers num="0.14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0322" published="2000-04-24" name="CVE-2000-0322" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The passwd.php3 CGI script in the Red Hat Piranha Virtual Server Package allows local users to execure arbitrary commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1149" source="BID" patch="1" adv="1">1149</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Enip.BSO.23.0004241601140.28851-100000@www.whitehats.com" source="BUGTRAQ">20000424 piranha default password/exploit</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-014.html" source="REDHAT">RHSA-2000:014</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="6.2" edition="" />
        <vers num="6.2" edition=":alpha" />
        <vers num="6.2" edition=":sparc" />
        <vers num="6.2" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0323" published="1999-07-28" name="CVE-2000-0323" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">The Microsoft Jet database engine allows an attacker to modify text files via a database query, aka the "Text I-ISAM" vulnerability. </descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-08-22&amp;msg=19990729195531.25108.qmail@underground.org" source="BUGTRAQ">19990728 Alert : MS Office 97 Vulnerability</ref>
      <ref url="http://www.securityfocus.com/level2/?go=vulnerabilities&amp;id=595" source="BID">595</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-030.asp" source="MS">MS99-030</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="jet">
        <vers num="3.5" />
        <vers num="3.51" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0324" published="2000-04-25" name="CVE-2000-0324" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">pcAnywhere 8.x and 9.0 allows remote attackers to cause a denial of service via a TCP SYN scan, e.g. by nmap.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.3.96.1000425150157.13567A-100000@sword.damocles.com" source="BUGTRAQ" adv="1">20000425 Denial of Service Against pcAnywhere.</ref>
      <ref url="http://www.securityfocus.com/bid/1150" source="BID" adv="1">1150</ref>
      <ref url="http://www.osvdb.org/1301" source="OSVDB">1301</ref>
      <ref url="http://www.iss.net/security_center/static/4347.php" source="XF">pcanywhere-tcpsyn-dos(4347)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0258.html" source="BUGTRAQ">20010212 Re: Symantec pcAnywhere 9.0 DoS / Buffer Overflow </ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0201.html" source="BUGTRAQ">20010211 Symantec pcAnywhere 9.0 DoS / Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="pcanywhere">
        <vers num="8.0.1" />
        <vers num="8.0.2" />
        <vers num="9.0" />
        <vers num="9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0325" published="1999-08-20" name="CVE-2000-0325" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The Microsoft Jet database engine allows an attacker to execute commands via a database query, aka the "VBA Shell" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3155.php" source="XF">jet-vba-shell(3155)</ref>
      <ref url="http://www.securityfocus.com/bid/548" source="BID">548</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-030.asp" source="MS">MS99-030</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="jet">
        <vers num="3.5" />
        <vers num="3.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0326" published="2000-04-25" name="CVE-2000-0326" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Meeting Maker uses weak encryption (a polyalphabetic substitution cipher) for passwords, which allows remote attackers to sniff and decrypt passwords for Meeting Maker accounts.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1151" source="BID" adv="1">1151</ref>
      <ref url="http://support.on.com/support/mmxp.nsf/31af51e08bcc93eb852565a90056138b/11af70407a16b165852568c50056a952?OpenDocument" source="CONFIRM" adv="1">http://support.on.com/support/mmxp.nsf/31af51e08bcc93eb852565a90056138b/11af70407a16b165852568c50056a952?OpenDocument</ref>
    </refs>
    <vuln_soft>
      <prod vendor="on_technology" name="meeting_maker">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0327" published="1999-10-21" name="CVE-2000-0327" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Microsoft Virtual Machine (VM) allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, aka the "Virtual Machine Verifier" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-045.asp" source="MS" patch="1" adv="1">MS99-045</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93993545118416&amp;w=2" source="BUGTRAQ">19991014 Another Microsoft Java Flaw Disovered</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="virtual_machine">
        <vers num="2000" />
        <vers num="3000" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0328" published="1999-08-24" name="CVE-2000-0328" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Windows NT 4.0 generates predictable random TCP initial sequence numbers (ISN), which allows remote attackers to perform spoofing and session hijacking.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-046.asp" source="MS">MS99-046</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=4.1.19990824165629.00abcb40@192.168.124.1" source="BUGTRAQ">19990824 NT Predictable Initial TCP Sequence numbers - changes observed with SP4</ref>
      <ref url="http://www.securityfocus.com/bid/604" source="BID">604</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0329" published="1999-11-11" name="CVE-2000-0329" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">A Microsoft ActiveX control allows a remote attacker to execute a malicious cabinet file via an attachment and an embedded script in an HTML mail, aka the "Active Setup Control" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
      <config />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-048.asp" source="MS" patch="1" adv="1">MS99-048</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":windows_nt" />
        <vers num="4.0" edition=":windows_98" />
        <vers num="4.0.1" edition="" />
        <vers num="4.0.1" edition=":windows_95" />
        <vers num="4.0.1" edition=":windows_98" />
        <vers num="4.0.1" edition=":windows_nt" />
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":windows_95" />
        <vers num="4.1" edition=":windows_nt_4.0" />
        <vers num="4.1" edition=":windows_98" />
        <vers num="5" edition="" />
        <vers num="5" edition=":windows_nt_4.0" />
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":windows_95" />
        <vers num="5.0" edition=":windows_98" />
        <vers num="5.0" edition=":windows_2000" />
      </prod>
      <prod vendor="microsoft" name="outlook">
        <vers num="2000" />
        <vers num="98" />
      </prod>
      <prod vendor="microsoft" name="outlook_express">
        <vers num="4.27.3110.1" />
        <vers num="4.72.2106.4" />
        <vers num="4.72.3120.0" />
        <vers num="4.72.3612.1700" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0330" published="1999-11-12" name="CVE-2000-0330" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">The networking software in Windows 95 and Windows 98 allows remote attackers to execute commands via a long file name string, aka the "File Access URL" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms99-049.asp" source="MS" patch="1" adv="1">MS99-049</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_95">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0331" published="2000-04-20" name="CVE-2000-0331" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft command processor (CMD.EXE) for Windows NT and Windows 2000 allows a local user to cause a denial of service via a long environment variable, aka the "Malformed Environment Variable" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1135" source="BID" patch="1" adv="1">1135</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-027.asp" source="MS">MS00-027</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0147.html" source="BUGTRAQ">20000421 CMD.EXE overflow (CISADV000420)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="terminal_server">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0332" published="2000-05-03" name="CVE-2000-0332" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">UltraBoard.pl or UltraBoard.cgi CGI scripts in UltraBoard 1.6 allows remote attackers to read arbitrary files via a pathname string that includes a dot dot (..) and ends with a null byte.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1164" source="BID" adv="1">1164</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000503091316.99073.qmail@hotmail.com" source="BUGTRAQ">20000502 Fun with UltraBoard V1.6X</ref>
      <ref url="http://www.osvdb.org/4065" source="OSVDB">4065</ref>
      <ref url="http://www.osvdb.org/1309" source="OSVDB">1309</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ultrascripts" name="ultraboard">
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0333" published="1999-05-31" name="CVE-2000-0333" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">tcpdump, Ethereal, and other sniffer packages allow remote attackers to cause a denial of service via malformed DNS packets in which a jump offset refers to itself, which causes tcpdump to enter an infinite loop while decompressing the packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1165" source="BID" patch="1" adv="1">1165</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.SOL.4.10.10005021942380.2077-100000@paranoia.pgci.ca" source="BUGTRAQ" adv="1">20000502 Denial of service attack against tcpdump</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.8.4" />
        <vers num="0.8.5" />
        <vers num="0.8.6" />
      </prod>
      <prod vendor="lbl" name="tcpdump">
        <vers num="3.4" />
        <vers num="3.5a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0334" published="2000-04-24" name="CVE-2000-0334" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The Allaire Spectra container editor preview tool does not properly enforce object security, which allows an attacker to conduct unauthorized activities via an object-method that is added to the container object with a publishing rule.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.allaire.com/handlers/index.cfm?ID=15411&amp;Method=Full" source="ALLAIRE" patch="1" adv="1">ASB00-10</ref>
      <ref url="http://www.securityfocus.com/bid/1181" source="BID">1181</ref>
    </refs>
    <vuln_soft>
      <prod vendor="allaire" name="spectra">
        <vers num="1.0" />
        <vers num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0335" published="2000-05-03" name="CVE-2000-0335" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The resolver in glibc 2.1.3 uses predictable IDs, which allows a local attacker to spoof DNS query results.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1166" source="BID" adv="1">1166</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="glibc">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
      </prod>
      <prod vendor="isc" name="bind">
        <vers num="8.2" />
        <vers num="8.2.1" />
        <vers num="8.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0336" published="2000-04-21" name="CVE-2000-0336" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Linux OpenLDAP server allows local users to modify arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-2000-009.0.txt" source="CALDERA" patch="1" adv="1">CSSA-2000-009.0</ref>
      <ref url="http://www.turbolinux.com/pipermail/tl-security-announce/2000-May/000009.html" source="TURBO">TLSA2000010-1</ref>
      <ref url="http://www.securityfocus.com/bid/1232" source="BID">1232</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-012.html" source="REDHAT">RHSA-2000:012</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openldap" name="openldap">
        <vers num="1.2.10" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="6.1" />
        <vers num="7.0" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":i386" />
        <vers num="6.1" edition=":alpha" />
        <vers num="6.1" edition=":sparc" />
        <vers num="6.2" edition="" />
        <vers num="6.2" edition=":alpha" />
        <vers num="6.2" edition=":sparc" />
        <vers num="6.2" edition=":i386" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux">
        <vers num="4.2" />
        <vers num="4.4" />
        <vers num="6.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0337" published="2000-04-24" name="CVE-2000-0337" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Xsun X server in Solaris 7 allows local users to gain root privileges via a long -dev parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1140" source="BID">1140</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0188.html" source="BUGTRAQ">20000424 Solaris x86 Xsun overflow.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0338" published="2000-04-23" name="CVE-2000-0338" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Concurrent Versions Software (CVS) uses predictable temporary file names for locking, which allows local users to cause a denial of service by creating the lock directory before it is created for use by a legitimate CVS user.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1136" source="BID" patch="1" adv="1">1136</ref>
      <ref url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D20000423174038.A520%40clico.pl" source="BUGTRAQ">20000423 CVS DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cvs" name="cvs">
        <vers num="1.10.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0339" published="2000-04-24" name="CVE-2000-0339" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">ZoneAlarm 2.1.10 and earlier does not filter UDP packets with a source port of 67, which allows remote attackers to bypass the firewall rules.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000421044123.2353.qmail@securityfocus.com" source="BUGTRAQ">20000420 ZoneAlarm</ref>
      <ref url="http://www.securityfocus.com/bid/1137" source="BID">1137</ref>
      <ref url="http://www.osvdb.org/1294" source="OSVDB">1294</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zonelabs" name="zonealarm">
        <vers prev="1" num="2.2.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0340" published="2000-04-29" name="CVE-2000-0340" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Gnomelib in SuSE Linux 6.3 allows local users to execute arbitrary commands via the DISPLAY environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1155" source="BID" patch="1" adv="1">1155</ref>
      <ref url="http://www.suse.com/us/support/download/updates/axp_63.html" source="CONFIRM">http://www.suse.com/us/support/download/updates/axp_63.html</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=00042902575201.09597@wintermute-pub" source="BUGTRAQ">20000428 SuSE 6.3 Gnomelib buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="suse_linux">
        <vers num="6.3" />
        <vers num="6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0341" published="2000-05-01" name="CVE-2000-0341" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ATRIUM Cassandra NNTP Server 1.10 allows remote attackers to cause a denial of service via a long login name.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1156" source="BID" adv="1">1156</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=95736106504870&amp;w=2" source="NTBUGTRAQ">20000501 Remote DoS attack in CASSANDRA NNTPServer v1.10 from ATRIUM</ref>
    </refs>
    <vuln_soft>
      <prod vendor="atrium_software" name="cassandra_nntp_server">
        <vers num="1.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0342" published="2000-04-28" name="CVE-2000-0342" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Eudora 4.x allows remote attackers to bypass the user warning for executable attachments such as .exe, .com, and .bat by using a .lnk file that refers to the attachment, aka "Stealth Attachment."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.peacefire.org/security/stealthattach/explanation.html" source="MISC">http://www.peacefire.org/security/stealthattach/explanation.html</ref>
      <ref url="http://news.cnet.com/news/0-1005-200-1773077.html?tag=st.ne.fd.lthd.1005-200-1773077" source="CONFIRM" adv="1">http://news.cnet.com/news/0-1005-200-1773077.html?tag=st.ne.fd.lthd.1005-200-1773077</ref>
      <ref url="http://www.securityfocus.com/bid/1157" source="BID">1157</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qualcomm" name="eudora">
        <vers num="4.2" />
        <vers num="4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0343" published="2000-05-02" name="CVE-2000-0343" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Sniffit 0.3.x with the -L logging option enabled allows remote attackers to execute arbitrary commands via a long MAIL FROM mail header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1158" source="BID" adv="1">1158</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200005021736.TAA01991@ALuSSi" source="BUGTRAQ">20000502 spj-003-000 - S0ftPj Advisory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="brecht_claerhout" name="sniffit">
        <vers num="0.3.6hip" />
        <vers num="0.3.7beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0344" published="2000-05-01" name="CVE-2000-0344" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The knfsd NFS server in Linux kernel 2.2.x allows remote attackers to cause a denial of service via a negative size value.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.21.0005012042550.6419-100000@ferret.lmh.ox.ac.uk" source="BUGTRAQ" patch="1" adv="1">20000501 Linux knfsd DoS issue</ref>
      <ref url="http://www.securityfocus.com/bid/1160" source="BID" adv="1">1160</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.1" />
        <vers num="2.2.0" />
        <vers num="2.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0345" published="2000-05-03" name="CVE-2000-0345" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The on-line help system options in Cisco routers allows non-privileged users without "enabled" access to obtain sensitive information via the show command.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1161" source="BID" patch="1" adv="1">1161</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000502222246.28423.qmail@securityfocus.com" source="BUGTRAQ">20000502 Possible issue with Cisco on-line help?</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="router_2500">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="router_2600">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="router_3600">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="router_4000">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="router_7200">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="router_7500">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="ios">
        <vers num="11.1" />
        <vers num="11.1(13)" />
        <vers num="11.1(13)aa" />
        <vers num="11.1(13)ca" />
        <vers num="11.1(13)ia" />
        <vers num="11.1(15)ca" />
        <vers num="11.1(16)" />
        <vers num="11.1(16)aa" />
        <vers num="11.1(16)ia" />
        <vers num="11.1(17)cc" />
        <vers num="11.1(17)ct" />
        <vers num="11.2" />
        <vers num="11.2(10)" />
        <vers num="11.2(10)bc" />
        <vers num="11.2(17)" />
        <vers num="11.2(4)f1" />
        <vers num="11.2(8)" />
        <vers num="11.2(8)p" />
        <vers num="11.2(8)sa1" />
        <vers num="11.2(8)sa3" />
        <vers num="11.2(8)sa5" />
        <vers num="11.2(9)p" />
        <vers num="11.2(9)xa" />
        <vers num="11.2p" />
        <vers num="12.0" />
        <vers num="12.0(1)w" />
        <vers num="12.0(1)xa3" />
        <vers num="12.0(1)xb" />
        <vers num="12.0(1)xe" />
        <vers num="12.0(2)" />
        <vers num="12.0(2)xc" />
        <vers num="12.0(2)xd" />
        <vers num="12.0(2)xf" />
        <vers num="12.0(2)xg" />
        <vers num="12.0(3)t2" />
        <vers num="12.0(4)" />
        <vers num="12.0(4)s" />
        <vers num="12.0(4)t" />
        <vers num="12.0(5)" />
        <vers num="12.0(5)t1" />
        <vers num="12.0(6)" />
        <vers num="12.0(7)t" />
        <vers num="12.0(8)" />
        <vers num="12.0(9)s" />
        <vers num="12.0db" />
        <vers num="12.0s" />
        <vers num="12.0t" />
        <vers num="9.14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0346" published="2000-05-02" name="CVE-2000-0346" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">AppleShare IP 6.1 and later allows a remote attacker to read potentially sensitive information via an invalid range request to the web server.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://asu.info.apple.com/swupdates.nsf/artnum/n11670" source="CONFIRM">http://asu.info.apple.com/swupdates.nsf/artnum/n11670</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000502133240.21807.qmail@securityfocus.com" source="BUGTRAQ">20000502 INFO:AppleShare IP 6.3.2 squashes security bug</ref>
      <ref url="http://www.securityfocus.com/bid/1162" source="BID">1162</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="appleshare">
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":" />
        <vers num="6.1" edition="::jp" />
        <vers num="6.2" edition="" />
        <vers num="6.2" edition=":" />
        <vers num="6.2" edition="::jp" />
        <vers num="6.3" edition="" />
        <vers num="6.3" edition=":" />
        <vers num="6.3" edition="::jp" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0347" published="2000-05-02" name="CVE-2000-0347" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Windows 95 and Windows 98 allow a remote attacker to cause a denial of service via a NetBIOS session request packet with a NULL source name.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1163" source="BID">1163</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=95737580922397&amp;w=2" source="NTBUGTRAQ">20000501 el8.org advisory - Win 95/98 DoS (RFParalyze.c)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_95">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0348" published="2001-03-12" name="CVE-2000-0348" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A vulnerability in the Sendmail configuration file sendmail.cf as installed in SCO UnixWare 7.1.0 and earlier allows an attacker to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.10a" source="SCO" patch="1" adv="1">SB-99.10</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="unixware">
        <vers prev="1" num="7.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0349" published="2001-03-12" name="CVE-2000-0349" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Vulnerability in the passthru driver in SCO UnixWare 7.1.0 allows an attacker to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.13a" source="SCO" patch="1" adv="1">SB-99.13</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="unixware">
        <vers prev="1" num="7.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0350" published="2000-05-17" name="CVE-2000-0350" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">A debugging feature in NetworkICE ICEcap 2.0.23 and earlier is enabled, which allows a remote attacker to bypass the weak authentication and post unencrypted events.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/advisory.html?id=2220" source="MISC">http://www.securityfocus.com/templates/advisory.html?id=2220</ref>
      <ref url="http://advice.networkice.com/advice/Support/KB/q000166/" source="CONFIRM">http://advice.networkice.com/advice/Support/KB/q000166/</ref>
      <ref url="http://www.securityfocus.com/bid/1216" source="BID">1216</ref>
      <ref url="http://www.osvdb.org/312" source="OSVDB">312</ref>
    </refs>
    <vuln_soft>
      <prod vendor="networkice" name="icecap_manager">
        <vers prev="1" num="2.0.23" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0351" published="2001-03-12" name="CVE-2000-0351" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Some packaging commands in SCO UnixWare 7.1.0 have insecure privileges, which allows local users to add or remove software packages.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.09b" source="SCO" patch="1" adv="1">SB-99.09</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="unixware">
        <vers prev="1" num="7.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0352" published="1999-11-18" name="CVE-2000-0352" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Pine before version 4.21 does not properly filter shell metacharacters from URLs, which allows remote attackers to execute arbitrary commands via a malformed URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.10.9911171818220.12375-100000@ray.compu-aid.com" source="BUGTRAQ">19991117 Pine: expanding env vars in URLs (seems to be fixed as of 4.21)</ref>
      <ref url="http://www.securityfocus.com/bid/810" source="BID">810</ref>
      <ref url="http://www.novell.com/linux/security/advisories/suse_security_announce_36.html" source="SUSE">19991227 Security hole in Pine &lt; 4.21</ref>
      <ref url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-036.0.txt" source="CALDERA">CSSA-1999-036.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_washington" name="pine">
        <vers num="4.20" />
        <vers num="4.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0353" published="1999-06-28" name="CVE-2000-0353" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Pine 4.x allows a remote attacker to execute arbitrary commands via an index.html file which executes lynx and obtains a uudecoded file from a malicious web server, which is then executed by Pine.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securiteam.com/unixfocus/HHP-Pine_remote_exploit.html" source="MISC" patch="1" adv="1">http://www.securiteam.com/unixfocus/HHP-Pine_remote_exploit.html</ref>
      <ref url="http://www.securityfocus.com/bid/1247" source="BID">1247</ref>
      <ref url="http://www.novell.com/linux/security/advisories/suse_security_announce_6.html" source="SUSE">19990628 Execution of commands in Pine 4.x</ref>
      <ref url="http://www.novell.com/linux/security/advisories/pine_update_announcement.html" source="SUSE">19990911 Update for Pine (fixed IMAP support)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_washington" name="pine">
        <vers num="3.98" />
        <vers num="4.0" />
        <vers num="4.10" />
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0354" published="2000-09-28" name="CVE-2000-0354" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">mirror 2.8.x in Linux systems allows remote attackers to create files one level above the local target directory.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=15769.990928@tomcat.ru" source="BUGTRAQ">19990928 mirror 2.9 hole</ref>
      <ref url="http://www.securityfocus.com/bid/681" source="BID">681</ref>
      <ref url="http://www.novell.com/linux/security/advisories/suse_security_announce_22.html" source="SUSE">19991001 Security hole in mirror</ref>
      <ref url="http://www.debian.org/security/1999/19991018" source="DEBIAN">19991018 Incorrect directory name handling in mirror</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lee_mcloughlin" name="mirror">
        <vers num="2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0355" published="1999-08-21" name="CVE-2000-0355" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">pg and pb in SuSE pbpg 1.x package allows an attacker to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.novell.com/linux/security/advisories/suse_security_announce_21.html" source="SUSE">19990920 Security hole in pbpg</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bent_bagger" name="pbpg">
        <vers num="1.1" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="6.0" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0356" published="1999-10-13" name="CVE-2000-0356" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Pluggable Authentication Modules (PAM) in Red Hat Linux 6.1 does not properly lock access to disabled NIS accounts.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/advisory.html?id=1789" source="REDHAT">RHSA-1999:040</ref>
      <ref url="http://www.securityfocus.com/bid/697" source="BID">697</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0357" published="1999-12-03" name="CVE-2000-0357" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">ORBit and esound in Red Hat Linux 6.1 do not use sufficiently random numbers, which allows local users to guess the authentication keys.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/corp/support/errata/RHSA1999058-01.html" source="REDHAT">RHSA-1999:058-01</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0358" published="1999-12-03" name="CVE-2000-0358" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ORBit and gnome-session in Red Hat Linux 6.1 allows remote attackers to crash a program.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/corp/support/errata/RHSA1999058-01.html" source="REDHAT">RHSA-1999:058-01</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0359" published="2000-10-20" name="CVE-2000-0359" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Trivial HTTP (THTTPd) allows remote attackers to cause a denial of service or execute arbitrary commands via a long If-Modified-Since header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1248" source="BID">1248</ref>
      <ref url="http://www.novell.com/linux/security/advisories/suse_security_announce_30.html" source="SUSE">19991116 Security hole in thttpd 1.90a - 2.04</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/1626.html" source="BUGTRAQ">19991113 thttpd 2.04 stack overflow (VD#6)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="acme_labs" name="thttpd">
        <vers num="1.90a" />
        <vers num="1.95" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0360" published="2000-10-20" name="CVE-2000-0360" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in INN 2.2.1 and earlier allows remote attackers to cause a denial of service via a maliciously formatted article.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-038.0.txt" source="CALDERA" patch="1" adv="1">CSSA-1999-038.0</ref>
      <ref url="http://www.securityfocus.com/bid/1249" source="BID">1249</ref>
      <ref url="http://www.novell.com/linux/security/advisories/suse_security_announce_34.html" source="SUSE">19991124 Security hole in inn &lt;= 2.2.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="inn">
        <vers num="1.4sec" />
        <vers num="1.4sec2" />
        <vers num="1.4unoff3" />
        <vers num="1.4unoff4" />
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.7" />
        <vers num="1.7.2" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0361" published="1999-12-14" name="CVE-2000-0361" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The PPP wvdial.lxdialog script in wvdial 1.4 and earlier creates a .config file with world readable permissions, which allows a local attacker in the dialout group to access login and password information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.novell.com/linux/security/advisories/suse_security_announce_35.html" source="SUSE">19991214 Security hole in wvdial &lt;= 1.4</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="suse_linux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0362" published="1999-10-22" name="CVE-2000-0362" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflows in Linux cdwtools 093 and earlier allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/738" source="BID">738</ref>
      <ref url="http://www.novell.com/linux/security/advisories/suse_security_announce_25.html" source="SUSE">19991019 Security hole in cdwtools &lt; 093</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="suse_linux">
        <vers num="6.1" />
        <vers num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0363" published="1999-10-22" name="CVE-2000-0363" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">Linux cdwtools 093 and earlier allows local users to gain root privileges via the /tmp directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/738" source="BID">738</ref>
      <ref url="http://www.novell.com/linux/security/advisories/suse_security_announce_25.html" source="SUSE">19991019 Security hole in cdwtools &lt; 093</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="suse_linux">
        <vers num="6.1" />
        <vers num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0364" published="1999-06-01" name="CVE-2000-0364" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">screen and rxvt in Red Hat Linux 6.0 do not properly set the modes of tty devices, which allows local users to write to other ttys.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/309" source="BID">309</ref>
      <ref url="http://www.redhat.com/corp/support/errata/RHSA1999014_01.html" source="REDHAT">RHSA1999014_01</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92886009012161&amp;w=2" source="BUGTRAQ">19990606 RedHat 6.0, /dev/pts permissions bug when using xterm</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92877527701347&amp;w=2" source="BUGTRAQ">19990606 RedHat 6.0, /dev/pts permissions bug when using xterm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0365" published="1999-06-01" name="CVE-2000-0365" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Red Hat Linux 6.0 installs the /dev/pts file system with insecure modes, which allows local users to write to other tty devices.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/308" source="BID">308</ref>
      <ref url="http://www.redhat.com/corp/support/errata/RHSA1999014_01.html" source="REDHAT">RHSA1999014_01</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92886009012161&amp;w=2" source="BUGTRAQ">19990606 RedHat 6.0, /dev/pts permissions bug when using xterm</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92877527701347&amp;w=2" source="BUGTRAQ">19990606 RedHat 6.0, /dev/pts permissions bug when using xterm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0366" published="1999-12-02" name="CVE-2000-0366" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">dump in Debian GNU/Linux 2.1 does not properly restore symlinks, which allows a local user to modify the ownership of arbitrary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1442" source="BID">1442</ref>
      <ref url="http://www.debian.org/security/1999/19991202" source="DEBIAN">19991202 problem restoring symlinks</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0367" published="1999-02-18" name="CVE-2000-0367" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in eterm 0.8.8 in Debian GNU/Linux allows an attacker to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/1999/19990218" source="DEBIAN" adv="1">19990218 Root exploit in eterm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michael_jennings" name="eterm">
        <vers num="0.8.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0368" published="2001-03-12" name="CVE-2000-0368" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Classic Cisco IOS 9.1 and later allows attackers with access to the loging prompt to obtain portions of the command history of previous users, which may allow the attacker to access sensitive data.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/770/ioshist-pub.shtml" source="CISCO" patch="1" adv="1">19981014 Cisco IOS Command History Release at Login Prompt</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/j-009.shtml" source="CIAC" patch="1" adv="1">J-009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers prev="1" num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0369" published="1999-10-08" name="CVE-2000-0369" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The IDENT server in Caldera Linux 2.3 creates multiple threads for each IDENT request, which allows remote attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1266" source="BID">1266</ref>
      <ref url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-029.1.txt" source="CALDERA">CSSA-1999-029.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="caldera" name="openlinux">
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0370" published="1999-01-29" name="CVE-2000-0370" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The debug option in Caldera Linux smail allows remote attackers to execute commands via shell metacharacters in the -D option for the rmail command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-001.0.txt" source="CALDERA" patch="1" adv="1">CSSA-1999-001.0</ref>
      <ref url="http://www.securityfocus.com/bid/1268" source="BID">1268</ref>
    </refs>
    <vuln_soft>
      <prod vendor="caldera" name="openlinux">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0371" published="1999-03-01" name="CVE-2000-0371" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">The libmediatool library used for the KDE mediatool allows local users to create arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-005.0.txt" source="CALDERA" patch="1" adv="1">CSSA-1999-005.0</ref>
      <ref url="http://www.securityfocus.com/bid/1269" source="BID">1269</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="kde">
        <vers num="1.1" />
        <vers num="1.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0372" published="2000-07-12" name="CVE-2000-0372" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in Caldera rmt command in the dump package 0.4b4 allows a local user to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2268.php" source="XF" patch="1" adv="1">linux-rmt</ref>
      <ref url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-014.0.txt" source="CALDERA" patch="1" adv="1">CSSA-1999-014.0</ref>
      <ref url="http://www.osvdb.org/7940" source="OSVDB">7940</ref>
    </refs>
    <vuln_soft>
      <prod vendor="caldera" name="openlinux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0373" published="1999-06-01" name="CVE-2000-0373" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerabilities in the KDE kvt terminal program allow local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/2266.php" source="XF" patch="1" adv="1">kde-kvt</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA1999015_01.html" source="REDHAT" patch="1" adv="1">RHSA-1999:015-01</ref>
      <ref url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-015.0.txt" source="CALDERA">CSSA-1999-015.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="kvt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0374" published="1999-08-22" name="CVE-2000-0374" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The default configuration of kdm in Caldera and Mandrake Linux, and possibly other distributions, allows XDMCP connections from any host, which allows remote attackers to obtain sensitive information or bypass additional access restrictions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/4856" source="XF">xdmcp-kdm-default-configuration(4856)</ref>
      <ref url="http://www.securityfocus.com/bid/1446" source="BID">1446</ref>
      <ref url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2002:025" source="MANDRAKE">MDKSA-2002:025</ref>
      <ref url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-021.0.txt" source="CALDERA">CSSA-1999-021.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="caldera" name="openlinux">
        <vers num="2.2" />
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0375" published="2001-03-12" name="CVE-2000-0375" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The kernel in FreeBSD 3.2 follows symbolic links when it creates core dump files, which allows local attackers to modify arbitrary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/6084" source="OSVDB">6084</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0376" published="2000-06-07" name="CVE-2000-0376" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the HTTP proxy server for the i-drive Filo software allows remote attackers to execute arbitrary commands via a long HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1324" source="BID">1324</ref>
    </refs>
    <vuln_soft>
      <prod vendor="i-drive" name="filo">
        <vers num="1.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0377" published="2000-06-08" name="CVE-2000-0377" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Remote Registry server in Windows NT 4.0 allows local authenticated users to cause a denial of service via a malformed request, which causes the winlogon process to fail, aka the "Remote Registry Access Authentication" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-040.asp" source="MS">MS00-040</ref>
      <ref url="http://www.securityfocus.com/bid/1331" source="BID">1331</ref>
      <ref url="http://www.microsoft.com/technet/support/kb.asp?ID=264684" source="MSKB">Q264684</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1021" source="OVAL" sig="1">oval:org.mitre.oval:def:1021</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0378" published="2000-05-03" name="CVE-2000-0378" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The pam_console PAM module in Linux systems performs a chown on various devices upon a user login, but an open file descriptor for those devices can be maintained after the user logs out, which allows that user to sniff activity on these devices when subsequent users log in.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1176" source="BID">1176</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0023.html" source="BUGTRAQ">20000502 pam_console bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0379" published="2000-05-16" name="CVE-2000-0379" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">The Netopia R9100 router does not prevent authenticated users from modifying SNMP tables, even if the administrator has configured it to do so.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200005082054.NAA32590@linux.mtndew.com" source="BUGTRAQ" patch="1" adv="1">20000507 Advisory: Netopia R9100 router vulnerability</ref>
      <ref url="http://www.netopia.com/equipment/purchase/fmw_update.html" source="CONFIRM">http://www.netopia.com/equipment/purchase/fmw_update.html</ref>
      <ref url="http://www.securityfocus.com/bid/1177" source="BID">1177</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netopia" name="r-series_routers">
        <vers num="4.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0380" published="2000-04-26" name="CVE-2000-0380" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The IOS HTTP service in Cisco routers and switches running IOS 11.1 through 12.1 allows remote attackers to cause a denial of service by requesting a URL that contains a %% string.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1154" source="BID">1154</ref>
      <ref url="http://www.osvdb.org/1302" source="OSVDB">1302</ref>
      <ref url="http://www.cisco.com/warp/public/707/ioshttpserver-pub.shtml" source="CISCO">20000514 Cisco IOS HTTP Server Vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0261.html" source="BUGTRAQ">20000426 Cisco HTTP possible bug:</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="11.1" />
        <vers num="11.2" />
        <vers num="11.2(10)" />
        <vers num="11.2(10)bc" />
        <vers num="11.2(17)" />
        <vers num="11.2(4)f1" />
        <vers num="11.2(8)" />
        <vers num="11.2(8)p" />
        <vers num="11.2(9)p" />
        <vers num="11.2(9)xa" />
        <vers num="11.2p" />
        <vers num="11.3" />
        <vers num="11.3(1)" />
        <vers num="11.3(1)ed" />
        <vers num="11.3(1)t" />
        <vers num="11.3t" />
        <vers num="12.0" />
        <vers num="12.0(1)w" />
        <vers num="12.0(1)xa3" />
        <vers num="12.0(1)xb" />
        <vers num="12.0(1)xe" />
        <vers num="12.0(2)" />
        <vers num="12.0(2)xc" />
        <vers num="12.0(2)xd" />
        <vers num="12.0(2)xf" />
        <vers num="12.0(2)xg" />
        <vers num="12.0(3)t2" />
        <vers num="12.0(4)" />
        <vers num="12.0(4)s" />
        <vers num="12.0(4)t" />
        <vers num="12.0(5)" />
        <vers num="12.0(5)t1" />
        <vers num="12.0(6)" />
        <vers num="12.0(7)t" />
        <vers num="12.0(8)" />
        <vers num="12.0(9)s" />
        <vers num="12.0db" />
        <vers num="12.0s" />
        <vers num="12.0t" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0381" published="2000-05-05" name="CVE-2000-0381" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The Gossamer Threads DBMan db.cgi CGI script allows remote attackers to view environmental variables and setup information by referencing a non-existing database in the db parameter.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.perfectotech.com/blackwatchlabs/vul5_05.html" source="MISC">http://www.perfectotech.com/blackwatchlabs/vul5_05.html</ref>
      <ref url="http://www.securityfocus.com/bid/1178" source="BID">1178</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0067.html" source="BUGTRAQ">20000505 Black Watch Labs Vulnerability Alert</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gossamer_threads" name="dbman">
        <vers num="2.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0382" published="2000-05-08" name="CVE-2000-0382" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">ColdFusion ClusterCATS appends stale query string arguments to a URL during HTML redirection, which may provide sensitive information to the redirected site.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.allaire.com/handlers/index.cfm?ID=15697&amp;Method=Full" source="ALLAIRE" patch="1" adv="1">ASB00-12</ref>
      <ref url="http://www.securityfocus.com/bid/1179" source="BID">1179</ref>
    </refs>
    <vuln_soft>
      <prod vendor="allaire" name="clustercats">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0383" published="2000-05-08" name="CVE-2000-0383" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The file transfer component of AOL Instant Messenger (AIM) reveals the physical path of the transferred file to the remote recipient.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1180" source="BID">1180</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=002401bfb918$7310d5a0$1ef084ce@karemor.com" source="BUGTRAQ">20000507 AOL Instant Messenger</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aol" name="instant_messenger">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0384" published="2000-05-08" name="CVE-2000-0384" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">NetStructure 7110 and 7180 have undocumented accounts (servnow, root, and wizard) whose passwords are easily guessable from the NetStructure's MAC address, which could allow remote attackers to gain root access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1183" source="BID" patch="1" adv="1">1183</ref>
      <ref url="http://www.securityfocus.com/bid/1182" source="BID" patch="1" adv="1">1182</ref>
      <ref url="http://www.lopht.com/advisories/ipivot7110.html" source="L0PHT" patch="1" adv="1">20000508 NetStructure 7180 remote backdoor vulnerability</ref>
      <ref url="http://www.l0pht.com/advisories/ipivot7180.html" source="L0PHT" patch="1" adv="1">20000508 NetStructure 7110 console backdoor</ref>
      <ref url="http://216.188.41.136/" source="CONFIRM">http://216.188.41.136/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intel" name="netstructure_7110">
        <vers num="" />
      </prod>
      <prod vendor="intel" name="netstructure_7180">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0385" published="2000-05-02" name="CVE-2000-0385" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">FileMaker Pro 5 Web Companion allows remote attackers to bypass Field-Level database security restrictions via the XML publishing or email capabilities.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.filemaker.com/support/webcompanion.html" source="CONFIRM">http://www.filemaker.com/support/webcompanion.html</ref>
      <ref url="http://www.blueworld.com/blueworld/news/05.01.00-FM5_Security.html" source="MISC">http://www.blueworld.com/blueworld/news/05.01.00-FM5_Security.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="filemaker" name="filemaker">
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0386" published="2000-05-02" name="CVE-2000-0386" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">FileMaker Pro 5 Web Companion allows remote attackers to send anonymous or forged email.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.filemaker.com/support/webcompanion.html" source="CONFIRM">http://www.filemaker.com/support/webcompanion.html</ref>
      <ref url="http://www.blueworld.com/blueworld/news/05.01.00-FM5_Security.html" source="MISC">http://www.blueworld.com/blueworld/news/05.01.00-FM5_Security.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="filemaker" name="filemaker">
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0387" published="2000-05-09" name="CVE-2000-0387" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The makelev program in the golddig game from the FreeBSD ports collection allows local users to overwrite arbitrary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1184" source="BID">1184</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:16.golddig.asc" source="FREEBSD">FreeBSD-SA-00:16</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alexander_siegel" name="golddig">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0388" published="1990-05-09" name="CVE-2000-0388" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in FreeBSD libmytinfo library allows local users to execute commands via a long TERMCAP environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1185" source="BID">1185</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00%3A17.libmytinfo.asc" source="FREEBSD">FreeBSD-SA-00:17</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0389" published="2000-05-16" name="CVE-2000-0389" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in krb_rd_req function in Kerberos 4 and 5 allows remote attackers to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2000-06.html" source="CERT" adv="1">CA-2000-06</ref>
      <ref url="http://www.securityfocus.com/bid/1220" source="BID">1220</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-025.html" source="REDHAT">RHSA-2000:025</ref>
      <ref url="http://archives.neohapsis.com/archives/freebsd/2000-05/0295.html" source="FREEBSD">FreeBSD-SA-00:20</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0184.html" source="BUGTRAQ">20000516 BUFFER OVERRUN VULNERABILITIES IN KERBEROS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cygnus" name="cygnus_network_security">
        <vers num="4.0" />
      </prod>
      <prod vendor="cygnus" name="kerbnet">
        <vers num="5.0" />
      </prod>
      <prod vendor="mit" name="kerberos">
        <vers num="4.0" />
        <vers num="5_1.0" />
        <vers num="5_1.1.1" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="6.2" edition="" />
        <vers num="6.2" edition=":alpha" />
        <vers num="6.2" edition=":sparc" />
        <vers num="6.2" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0390" published="2000-05-16" name="CVE-2000-0390" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in krb425_conv_principal function in Kerberos 5 allows remote attackers to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2000-06.html" source="CERT" adv="1">CA-2000-06</ref>
      <ref url="http://www.securityfocus.com/bid/1220" source="BID">1220</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-025.html" source="REDHAT">RHSA-2000:025</ref>
      <ref url="http://www.osvdb.org/4884" source="OSVDB">4884</ref>
      <ref url="http://archives.neohapsis.com/archives/freebsd/2000-05/0295.html" source="FREEBSD">FreeBSD-SA-00:20</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0184.html" source="BUGTRAQ">20000516 BUFFER OVERRUN VULNERABILITIES IN KERBEROS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cygnus" name="cygnus_network_security">
        <vers num="4.0" />
      </prod>
      <prod vendor="cygnus" name="kerbnet">
        <vers num="5.0" />
      </prod>
      <prod vendor="mit" name="kerberos">
        <vers num="4.0" />
        <vers num="5_1.0" />
        <vers num="5_1.1.1" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="6.2" edition="" />
        <vers num="6.2" edition=":alpha" />
        <vers num="6.2" edition=":sparc" />
        <vers num="6.2" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0391" published="2000-05-16" name="CVE-2000-0391" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in krshd in Kerberos 5 allows remote attackers to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2000-06.html" source="CERT" adv="1">CA-2000-06</ref>
      <ref url="http://www.securityfocus.com/bid/1220" source="BID">1220</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-025.html" source="REDHAT">RHSA-2000:025</ref>
      <ref url="http://www.osvdb.org/4876" source="OSVDB">4876</ref>
      <ref url="http://archives.neohapsis.com/archives/freebsd/2000-05/0295.html" source="FREEBSD">FreeBSD-SA-00:20</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0184.html" source="BUGTRAQ">20000516 BUFFER OVERRUN VULNERABILITIES IN KERBEROS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cygnus" name="cygnus_network_security">
        <vers num="4.0" />
      </prod>
      <prod vendor="cygnus" name="kerbnet">
        <vers num="5.0" />
      </prod>
      <prod vendor="mit" name="kerberos">
        <vers num="4.0" />
        <vers num="5_1.0" />
        <vers num="5_1.1.1" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="6.2" edition="" />
        <vers num="6.2" edition=":alpha" />
        <vers num="6.2" edition=":sparc" />
        <vers num="6.2" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0392" published="2000-05-16" name="CVE-2000-0392" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in ksu in Kerberos 5 allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2000-06.html" source="CERT" adv="1">CA-2000-06</ref>
      <ref url="http://www.securityfocus.com/bid/1220" source="BID">1220</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-025.html" source="REDHAT">RHSA-2000:025</ref>
      <ref url="http://archives.neohapsis.com/archives/freebsd/2000-05/0295.html" source="FREEBSD">FreeBSD-SA-00:20</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0184.html" source="BUGTRAQ">20000516 BUFFER OVERRUN VULNERABILITIES IN KERBEROS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cygnus" name="cygnus_network_security">
        <vers num="4.0" />
      </prod>
      <prod vendor="cygnus" name="kerbnet">
        <vers num="5.0" />
      </prod>
      <prod vendor="mit" name="kerberos">
        <vers num="4.0" />
        <vers num="5_1.0" />
        <vers num="5_1.1.1" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="6.2" edition="" />
        <vers num="6.2" edition=":alpha" />
        <vers num="6.2" edition=":sparc" />
        <vers num="6.2" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0393" published="2000-05-16" name="CVE-2000-0393" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The KDE kscd program does not drop privileges when executing a program specified in a user's SHELL environmental variable, which allows the user to gain privileges by specifying an alternate program to execute.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1206" source="BID">1206</ref>
      <ref url="http://www.novell.com/linux/security/advisories/suse_security_announce_50.html" source="SUSE">20000529 kmulti &lt;= 1.1.2</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0172.html" source="BUGTRAQ">20000516 kscd vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="kde">
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.2" />
        <vers num="2.0_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0394" published="2000-05-18" name="CVE-2000-0394" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">NetProwler 3.0 allows remote attackers to cause a denial of service by sending malformed IP packets that trigger NetProwler's Man-in-the-Middle signature.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=392AD3B3.3E9BE3EA@axent.com" source="BUGTRAQ">20000522 RFP2K05 - NetProwler "Fragmentation" Issue </ref>
      <ref url="http://www.securityfocus.com/bid/1225" source="BID">1225</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95878603510835&amp;w=2" source="BUGTRAQ">20000519 RFP2K05: NetProwler vs. RFProwler</ref>
    </refs>
    <vuln_soft>
      <prod vendor="axent" name="netprowler">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0395" published="2000-05-16" name="CVE-2000-0395" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in CProxy 3.3 allows remote users to cause a denial of service via a long HTTP request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=007d01bfbf48$e44f0e40$01dc11ac@peopletel.org" source="BUGTRAQ">20000516 CProxy v3.3 SP 2 DoS</ref>
      <ref url="http://www.securityfocus.com/bid/1213" source="BID">1213</ref>
    </refs>
    <vuln_soft>
      <prod vendor="computalynx" name="cproxy_server">
        <vers num="3.3sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0396" published="2000-05-24" name="CVE-2000-0396" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The add.exe program in the Carello shopping cart software allows remote attackers to duplicate files on the server, which could allow the attacker to read source code for web scripts such as .ASP files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1245" source="BID">1245</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0285.html" source="BUGTRAQ">20000524 Alert: Carello File Creation flaw</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pacific_software" name="carello">
        <vers num="1.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0397" published="2000-05-15" name="CVE-2000-0397" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The EMURL web-based email account software encodes predictable identifiers in user session URLs, which allows a remote attacker to access a user's email account.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1203" source="BID">1203</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0160.html" source="BUGTRAQ">20000515 Vulnerability in EMURL-based e-mail providers</ref>
    </refs>
    <vuln_soft>
      <prod vendor="seattle_lab_software" name="emurl">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0398" published="2000-05-24" name="CVE-2000-0398" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in wconsole.dll in Rockliffe MailSite Management Agent allows remote attackers to execute arbitrary commands via a long query_string parameter in the HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1244" source="BID">1244</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0286.html" source="BUGTRAQ">20000524 Alert: Buffer overflow in Rockliffe's MailSite</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rockliffe" name="mailsite">
        <vers num="4.2.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0399" published="2000-05-24" name="CVE-2000-0399" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in MDaemon POP server allows remote attackers to cause a denial of service via a long user name.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1250" source="BID">1250</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0301.html" source="BUGTRAQ">20000524 Deerfield Communications MDaemon Mail Server DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alt-n" name="mdaemon">
        <vers num="3.0.3" />
        <vers num="3.1_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0400" published="2000-05-13" name="CVE-2000-0400" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Microsoft Active Movie ActiveX Control in Internet Explorer 5 does not restrict which file types can be downloaded, which allows an attacker to download any type of file to a user's system by encoding it within an email message or news post.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1221" source="BID">1221</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95868514521257&amp;w=2" source="BUGTRAQ">20000516 MICROSOFT SECURITY FLAW?</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="active_movie_control">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0401" published="2000-05-01" name="CVE-2000-0401" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflows in redirect.exe and changepw.exe in PDGSoft shopping cart allow remote attackers to execute arbitrary commands via a long query string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1256" source="BID">1256</ref>
      <ref url="http://www.pdgsoft.com/Security/security2.html" source="CONFIRM">http://www.pdgsoft.com/Security/security2.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=95928667119963&amp;w=2" source="NTBUGTRAQ">20000525 Alert: PDG Cart Overflows</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95928319715983&amp;w=2" source="BUGTRAQ">20000525 Alert: PDG Cart Overflows</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pdgsoft" name="pdg_shopping_cart">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0402" published="2000-05-30" name="CVE-2000-0402" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in plaintext in a log file which is readable by any user, aka the "SQL Server 7.0 Service Pack Password" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-035.asp" source="MS">MS00-035</ref>
      <ref url="http://www.securityfocus.com/bid/1281" source="BID">1281</ref>
      <ref url="http://www.microsoft.com/technet/support/kb.asp?ID=263968" source="MSKB">Q263968</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="sql_server">
        <vers num="7.0" edition="sp1" />
        <vers num="7.0" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0403" published="2000-05-25" name="CVE-2000-0403" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The CIFS Computer Browser service on Windows NT 4.0 allows a remote attacker to cause a denial of service by sending a large number of host announcement requests to the master browse tables, aka the "HostAnnouncement Flooding" or "HostAnnouncement Frame" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-036.asp" source="MS" patch="1" adv="1">MS00-036</ref>
      <ref url="http://www.securityfocus.com/bid/1261" source="BID">1261</ref>
      <ref url="http://www.microsoft.com/technet/support/kb.asp?ID=263307" source="MSKB">Q263307</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0404" published="2000-05-25" name="CVE-2000-0404" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The CIFS Computer Browser service allows remote attackers to cause a denial of service by sending a ResetBrowser frame to the Master Browser, aka the "ResetBrowser Frame" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-036.asp" source="MS" patch="1" adv="1">MS00-036</ref>
      <ref url="http://www.securityfocus.com/bid/1262" source="BID">1262</ref>
      <ref url="http://www.microsoft.com/technet/support/kb.asp?ID=262694" source="MSKB">Q262694</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="terminal_server">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_95">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0405" published="2000-05-16" name="CVE-2000-0405" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in L0pht AntiSniff allows remote attackers to execute arbitrary commands via a malformed DNS response packet.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.l0pht.com/advisories/asniff_advisory.txt" source="L0PHT" patch="1" adv="1">20000515 AntiSniff version 1.01 and Researchers version 1 DNS overflow</ref>
      <ref url="http://www.securityfocus.com/bid/1207" source="BID">1207</ref>
      <ref url="http://www.osvdb.org/3179" source="OSVDB">3179</ref>
    </refs>
    <vuln_soft>
      <prod vendor="atstake" name="antisniff">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":researchers" />
        <vers num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0406" published="2000-05-10" name="CVE-2000-0406" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Netscape Communicator before version 4.73 and Navigator 4.07 do not properly validate SSL certificates, which allows remote attackers to steal information by redirecting traffic from a legitimate web server to their own malicious server, aka the "Acros-Suencksen SSL" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2000-05.html" source="CERT" adv="1">CA-2000-05</ref>
      <ref url="http://www.securityfocus.com/bid/1188" source="BID">1188</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-028.html" source="REDHAT">RHSA-2000:028</ref>
      <ref url="http://www.acrossecurity.com/aspr/ASPR-2000-04-06-1-PUB.txt" source="MISC">http://www.acrossecurity.com/aspr/ASPR-2000-04-06-1-PUB.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="communicator">
        <vers num="4.0" />
        <vers num="4.05" />
        <vers num="4.06" />
        <vers num="4.07" />
        <vers num="4.5" />
        <vers num="4.51" />
        <vers num="4.5_beta" />
        <vers num="4.6" />
        <vers num="4.61" />
        <vers num="4.7" />
        <vers num="4.72" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0407" published="2000-05-12" name="CVE-2000-0407" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Solaris netpr program allows local users to execute arbitrary commands via a long -p option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1200" source="BID">1200</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0141.html" source="BUGTRAQ">20000512 New Solaris root exploit for /usr/lib/lp/bin/netpr</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0408" published="2000-05-11" name="CVE-2000-0408" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IIS 4.05 and 5.0 allow remote attackers to cause a denial of service via a long, complex URL that appears to contain a large number of file extensions, aka the "Malformed Extension Data in URL" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-030.asp" source="MS" patch="1" adv="1">MS00-030</ref>
      <ref url="http://www.ussrback.com/labs40.html" source="MISC">http://www.ussrback.com/labs40.html</ref>
      <ref url="http://www.securityfocus.com/bid/1190" source="BID">1190</ref>
      <ref url="http://www.microsoft.com/technet/support/kb.asp?ID=260205" source="MSKB">Q260205</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0409" published="2000-05-10" name="CVE-2000-0409" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">Netscape 4.73 and earlier follows symlinks when it imports a new certificate, which allows local users to overwrite files of the user importing the certificate.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1201" source="BID">1201</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0126.html" source="BUGTRAQ">20000510 Possible symlink problems with Netscape 4.73</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="communicator">
        <vers num="4.5" />
        <vers num="4.51" />
        <vers num="4.6" />
        <vers num="4.61" />
        <vers num="4.7" />
        <vers num="4.72" />
        <vers num="4.73" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0410" published="2000-05-10" name="CVE-2000-0410" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ColdFusion Server 4.5.1 allows remote attackers to cause a denial of service by making repeated requests to a CFCACHE tagged cache file that is not stored in memory.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0005&amp;L=ntbugtraq&amp;F=&amp;S=&amp;P=4843" source="NTBUGTRAQ" patch="1" adv="1">20000510 Cold Fusion Server 4.5.1 DoS Vulnerability.</ref>
      <ref url="http://www.securityfocus.com/bid/1192" source="BID">1192</ref>
    </refs>
    <vuln_soft>
      <prod vendor="allaire" name="coldfusion_server">
        <vers num="4.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0411" published="2000-05-10" name="CVE-2000-0411" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Matt Wright's FormMail CGI script allows remote attackers to obtain environmental variables via the env_report parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.perfectotech.com/blackwatchlabs/vul5_10.html" source="MISC">http://www.perfectotech.com/blackwatchlabs/vul5_10.html</ref>
      <ref url="http://www.securityfocus.com/bid/1187" source="BID">1187</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0125.html" source="BUGTRAQ">20000510 Black Watch Labs Vulnerability Alert</ref>
    </refs>
    <vuln_soft>
      <prod vendor="matt_wright" name="formmail">
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0412" published="1999-05-01" name="CVE-2000-0412" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The gnapster and knapster clients for Napster do not properly restrict access only to MP3 files, which allows remote attackers to read arbitrary files from the client by specifying the full pathname for the file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1186" source="BID">1186</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0127.html" source="BUGTRAQ">20000510 Gnapster Vulnerability Compromises User-readable Files</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0124.html" source="BUGTRAQ">20000510 KNapster Vulnerability Compromises User-readable Files</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:18-gnapster.adv" source="FREEBSD">FreeBSD-SA-00:18</ref>
    </refs>
    <vuln_soft>
      <prod vendor="napster" name="knapster">
        <vers num="napster" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0413" published="2000-05-06" name="CVE-2000-0413" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers to determine the physical path of HTML, HTM, ASP, and SHTML files by requesting a file that does not exist, which generates an error message that reveals the path.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1174" source="BID">1174</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0084.html" source="BUGTRAQ">20000506 shtml.exe reveal local path of IIS web directory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="frontpage">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0414" published="2000-05-04" name="CVE-2000-0414" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Vulnerability in shutdown command for HP-UX 11.X and 10.X allows allows local users to gain privileges via malformed input variables.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1214" source="BID">1214</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0047.html" source="HP">HPSBUX0005-113</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.10" />
        <vers num="10.20" />
        <vers num="11.00" />
      </prod>
      <prod vendor="hp" name="vvos">
        <vers num="10.24" />
        <vers num="11.04" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0415" published="2000-05-12" name="CVE-2000-0415" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Outlook Express 4.x allows attackers to cause a denial of service via a mail or news message that has a .jpg or .bmp attachment with a long file name.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1195" source="BID" patch="1" adv="1">1195</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0140.html" source="BUGTRAQ">20000512 Overflow in Outlook Express 4.* - too long filenames with graphic format extension</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="outlook">
        <vers num="98" />
      </prod>
      <prod vendor="microsoft" name="outlook_express">
        <vers num="4.0" />
        <vers num="4.01" />
        <vers num="4.27.3110.1" />
        <vers num="4.72.2106.4" />
        <vers num="4.72.3120.0" />
        <vers num="4.72.3612.1700" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0416" published="2000-05-11" name="CVE-2000-0416" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">NTMail 5.x allows network users to bypass the NTMail proxy restrictions by redirecting their requests to NTMail's web configuration server.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gordano.com/support/archives/ntmail/2000-05/00001114.htm" source="CONFIRM">http://www.gordano.com/support/archives/ntmail/2000-05/00001114.htm</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=NABBJLKKPKIHDIMKFKGCMEFANMAB.georger@nls.net" source="BUGTRAQ">20000511 NTMail Proxy Exploit</ref>
      <ref url="http://www.securityfocus.com/bid/1196" source="BID">1196</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0417" published="2000-05-17" name="CVE-2000-0417" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The HTTP administration interface to the Cayman 3220-H DSL router allows remote attackers to cause a denial of service via a long username or password.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1219" source="BID">1219</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0280.html" source="BUGTRAQ">20000523 Cayman 3220H DSL Router Software Update and New Bonus Attack</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0075.html" source="BUGTRAQ">20000505 Cayman 3220-H DSL Router DOS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cayman" name="3220-h_dsl_router">
        <vers num="1.0" />
      </prod>
      <prod vendor="cayman" name="gatorsurf">
        <vers num="5.3build_r1" />
        <vers num="5.3build_r2" />
        <vers num="5.5build_r0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0418" published="2000-05-23" name="CVE-2000-0418" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Cayman 3220-H DSL router allows remote attackers to cause a denial of service via oversized ICMP echo (ping) requests.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1240" source="BID">1240</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0280.html" source="BUGTRAQ">20000523 Cayman 3220H DSL Router Software Update and New Bonus Attack</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cayman" name="3220-h_dsl_router">
        <vers num="1.0" />
      </prod>
      <prod vendor="cayman" name="gatorsurf">
        <vers num="5.3" />
        <vers num="5.3build_r1" />
        <vers num="5.3build_r2" />
        <vers num="5.5build_r0" />
        <vers num="5.5build_r1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0419" published="2000-05-11" name="CVE-2000-0419" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Office 2000 UA ActiveX Control is marked as "safe for scripting," which allows remote attackers to conduct unauthorized activities via the "Show Me" function in Office Help, aka the "Office 2000 UA Control" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2000-07.html" source="CERT">CA-2000-07</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-034.asp" source="MS" patch="1" adv="1">MS00-034</ref>
      <ref url="http://www.securityfocus.com/bid/1197" source="BID">1197</ref>
      <ref url="http://www.microsoft.com/technet/support/kb.asp?ID=262767" source="MSKB">Q262767</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="access">
        <vers num="2000" />
      </prod>
      <prod vendor="microsoft" name="excel">
        <vers num="2000" />
      </prod>
      <prod vendor="microsoft" name="frontpage">
        <vers num="2000" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2000" />
      </prod>
      <prod vendor="microsoft" name="outlook">
        <vers num="2000" />
      </prod>
      <prod vendor="microsoft" name="photodraw_2000">
        <vers num="1.0" />
      </prod>
      <prod vendor="microsoft" name="powerpoint">
        <vers num="2000" />
      </prod>
      <prod vendor="microsoft" name="project">
        <vers num="2000" />
      </prod>
      <prod vendor="microsoft" name="word">
        <vers num="2000" />
      </prod>
      <prod vendor="microsoft" name="works">
        <vers num="2000" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0420" published="2000-05-11" name="CVE-2000-0420" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The default configuration of SYSKEY in Windows 2000 stores the startup key in the registry, which could allow an attacker tor ecover it and use it to decrypt Encrypted File System (EFS) data.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1198" source="BID">1198</ref>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0112.html" source="NTBUGTRAQ">20000511 ISS SAVANT Advisory 00/26</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0421" published="2000-05-11" name="CVE-2000-0421" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The process_bug.cgi script in Bugzilla allows remote attackers to execute arbitrary commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1199" source="BID">1199</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0128.html" source="BUGTRAQ">20000510 Advisory: Unchecked system(blaat $var blaat) call in Bugzilla 2.8</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0422" published="2000-05-04" name="CVE-2000-0422" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Netwin DMailWeb CGI program allows remote attackers to execute arbitrary commands via a long utoken parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1171" source="BID">1171</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95749276827558&amp;w=2" source="BUGTRAQ">20000504 Alert: DMailWeb buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netwin" name="dmail">
        <vers num="2.5d" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0423" published="2000-05-05" name="CVE-2000-0423" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Netwin DNEWSWEB CGI program allows remote attackers to execute arbitrary commands via long parameters such as group, cmd, and utag.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1172" source="BID">1172</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95764950403250&amp;w=2" source="BUGTRAQ">20000505 Alert: DNewsWeb buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netwin" name="dnews">
        <vers num="5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0424" published="2000-05-15" name="CVE-2000-0424" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The CGI counter 4.0.7 by George Burgyan allows remote attackers to execute arbitrary commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200005151024.aa01811@blaze.arl.mil" source="BUGTRAQ">20000514 Vulnerability in CGI counter 4.0.7 by George Burgyan</ref>
      <ref url="http://www.securityfocus.com/bid/1202" source="BID">1202</ref>
    </refs>
    <vuln_soft>
      <prod vendor="george_burgyan" name="cgi_counter">
        <vers num="4.0.2" />
        <vers num="4.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0425" published="2000-05-03" name="CVE-2000-0425" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the Web Archives component of L-Soft LISTSERV 1.8 allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.lsoft.com/news/default.asp?item=Advisory0" source="CONFIRM">http://www.lsoft.com/news/default.asp?item=Advisory0</ref>
      <ref url="http://www.securityfocus.com/bid/1167" source="BID">1167</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0048.html" source="BUGTRAQ">20000505 Alert: Listserv Web Archives (wa) buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lsoft" name="listserv">
        <vers num="1.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0426" published="2000-05-05" name="CVE-2000-0426" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">UltraBoard 1.6 and other versions allow remote attackers to cause a denial of service by referencing UltraBoard in the Session parameter, which causes UltraBoard to fork copies of itself.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1175" source="BID">1175</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0059.html" source="BUGTRAQ">20000505 Re: Fun with UltraBoard V1.6X</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ultrascripts" name="ultraboard">
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0427" published="2000-05-04" name="CVE-2000-0427" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The Aladdin Knowledge Systems eToken device allows attackers with physical access to the device to obtain sensitive information without knowing the PIN of the owner by resetting the PIN in the EEPROM.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1170" source="BID">1170</ref>
      <ref url="http://www.osvdb.org/3266" source="OSVDB">3266</ref>
      <ref url="http://www.l0pht.com/advisories/etoken-piepa.txt" source="L0PHT">20000504 eToken Private Information Extraction and Physical Attack</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aladdin_knowledge_systems" name="etoken">
        <vers num="3.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0428" published="2000-05-04" name="CVE-2000-0428" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the SMTP gateway for InterScan Virus Wall 3.32 and earlier allows a remote attacker to execute arbitrary commands via a long filename for a uuencoded attachment.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1168" source="BID">1168</ref>
      <ref url="http://www.nai.com/nai_labs/asp_set/advisory/39_Trend.asp" source="NAI">20000503 Trend Micro InterScan VirusWall Remote Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="interscan_viruswall">
        <vers num="3.0.1" />
        <vers num="3.2.3" />
        <vers num="3.3" />
        <vers num="3.32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0429" published="2000-04-27" name="CVE-2000-0429" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">A backdoor password in Cart32 3.0 and earlier allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cart32.com/kbshow.asp?article=c048" source="CONFIRM">http://www.cart32.com/kbshow.asp?article=c048</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95686068203138&amp;w=2" source="BUGTRAQ">20000427 Alert: Cart32 secret password backdoor (CISADV000427)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcmurtrey_whitaker_and_associates" name="cart32">
        <vers num="2.6" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0430" published="2000-05-03" name="CVE-2000-0430" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cart32 allows remote attackers to access sensitive debugging information by appending /expdate to the URL request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1358" source="BID">1358</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95738697301956&amp;w=2" source="BUGTRAQ">20000503 Another interesting Cart32 command</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcmurtrey_whitaker_and_associates" name="cart32">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0431" published="2000-05-22" name="CVE-2000-0431" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cobalt RaQ2 and RaQ3 does not properly set the access permissions and ownership for files that are uploaded via FrontPage, which allows attackers to bypass cgiwrap and modify files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1238" source="BID" patch="1" adv="1">1238</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0305.html" source="CONFIRM">http://archives.neohapsis.com/archives/bugtraq/2000-05/0305.html</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000523100045.B11049@HiWAAY.net" source="BUGTRAQ">20000522  Problem with FrontPage on Cobalt RaQ2/RaQ3</ref>
      <ref url="http://www.osvdb.org/1346" source="OSVDB">1346</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="cobalt_raq_2">
        <vers num="" />
      </prod>
      <prod vendor="sun" name="cobalt_raq_3i">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0432" published="2000-05-16" name="CVE-2000-0432" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The calender.pl and the calendar_admin.pl calendar scripts by Matt Kruse allow remote attackers to execute arbitrary commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1215" source="BID">1215</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0173.html" source="BUGTRAQ">20000516 Vuln in calender.pl (Matt Kruse calender script)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="matt_kruse" name="calendar_script">
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0433" published="2000-05-02" name="CVE-2000-0433" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The SuSE aaa_base package installs some system accounts with home directories set to /tmp, which allows local users to gain privileges to those accounts by creating standard user startup scripts such as profiles.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.novell.com/linux/security/advisories/suse_security_announce_47.html" source="SUSE">20000502 aaabase &lt; 2000.5.2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="suse_linux">
        <vers num="6.1" edition="alpha" />
        <vers num="6.2" />
        <vers num="6.3" edition="" />
        <vers num="6.3" edition=":ppc" />
        <vers num="6.3" edition="alpha" />
        <vers num="6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0434" published="2000-05-13" name="CVE-2000-0434" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The administrative password for the Allmanage web site administration software is stored in plaintext in a file which could be accessed by remote attackers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1217" source="BID">1217</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0167.html" source="BUGTRAQ">20000516 Allmanage.pl Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="matthew_redman" name="allmanage">
        <vers num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0435" published="2000-05-13" name="CVE-2000-0435" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The allmanageup.pl file upload CGI script in the Allmanage Website administration software 2.6 can be called directly by remote attackers, which allows them to modify user accounts or web pages.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1217" source="BID">1217</ref>
      <ref url="http://www.osvdb.org/1337" source="OSVDB">1337</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0167.html" source="BUGTRAQ">20000516 Allmanage.pl Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="matthew_redman" name="allmanage">
        <vers num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0436" published="2000-05-19" name="CVE-2000-0436" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">MetaProducts Offline Explorer 1.2 and earlier allows remote attackers to access arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.metaproducts.com/mpOE-HY.html" source="CONFIRM" patch="1">http://www.metaproducts.com/mpOE-HY.html</ref>
      <ref url="http://www.securityfocus.com/bid/1231" source="BID">1231</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0254.html" source="BUGTRAQ">20000522 MetaProducts Offline Explorer Directory Traversal Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="metaproducts" name="offline_explorer">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0437" published="2000-05-18" name="CVE-2000-0437" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the CyberPatrol daemon "cyberdaemon" used in gauntlet and WebShield allows remote attackers to cause a denial of service or execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.tis.com/support/cyberadvisory.html" source="CONFIRM">http://www.tis.com/support/cyberadvisory.html</ref>
      <ref url="http://www.pgp.com/jump/gauntlet_advisory.asp" source="CONFIRM">http://www.pgp.com/jump/gauntlet_advisory.asp</ref>
      <ref url="http://www.securityfocus.com/bid/1234" source="BID">1234</ref>
      <ref url="http://www.osvdb.org/322" source="OSVDB">322</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0249.html" source="BUGTRAQ">20000522 Gauntlet CyberPatrol Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="network_associates" name="gauntlet_firewall">
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.5" />
      </prod>
      <prod vendor="network_associates" name="webshield">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":solaris" />
      </prod>
      <prod vendor="network_associates" name="webshield_e-ppliance">
        <vers num="100.0" />
        <vers num="300.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0438" published="2000-05-22" name="CVE-2000-0438" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in fdmount on Linux systems allows local users in the "floppy" group to execute arbitrary commands via a long mountpoint parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1239" source="BID">1239</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0245.html" source="BUGTRAQ">20000522 fdmount buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="caldera" name="openlinux">
        <vers num="7.0" />
      </prod>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="3.5" />
        <vers num="3.6" />
        <vers num="3.9" />
        <vers num="4.0" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="4.2" />
        <vers num="4.3" />
        <vers num="4.4" />
        <vers num="4.4.1" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="5.3" />
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
        <vers num="7.0" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux">
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0439" published="2000-05-11" name="CVE-2000-0439" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Internet Explorer 4.0 and 5.0 allows a malicious web site to obtain client cookies from another domain by including that domain name and escaped characters in a URL, aka the "Unauthorized Cookie Access" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-033.asp" source="MS" patch="1" adv="1">MS00-033</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/4447" source="XF">ie-cookie-disclosure(4447)</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=NDBBKGHPMKBKDDGLDEEHAEHMDIAA.rms2000@bellatlantic.net" source="BUGTRAQ">20000511 IE Domain Confusion Vulnerability is an Email problem also</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000511135609.D7774@securityfocus.com" source="BUGTRAQ">20000510 IE Domain Confusion Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/1194" source="BID">1194</ref>
      <ref url="http://www.osvdb.org/1326" source="OSVDB">1326</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="3.0" />
        <vers num="3.2" />
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="4.1" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0440" published="2000-05-01" name="CVE-2000-0440" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">NetBSD 1.4.2 and earlier allows remote attackers to cause a denial of service by sending a packet with an unaligned IP timestamp option.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1173" source="BID">1173</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0088.html" source="BUGTRAQ">20000506 [NHC20000504a.0: NetBSD Panics when sent unaligned IP options]</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-002.txt.asc" source="NETBSD">NetBSD-SA2000-002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.4" />
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.4.1" />
        <vers num="1.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0441" published="2000-05-24" name="CVE-2000-0441" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Vulnerability in AIX 3.2.x and 4.x allows local users to gain write access to files on locally or remotely mounted AIX filesystems.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1241" source="BID">1241</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0275.html" source="IBM">ERS-OAR-E01-2000:087.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="3.2" />
        <vers num="3.2.4" />
        <vers num="3.2.5" />
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
        <vers num="4.2" />
        <vers num="4.2.1" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0442" published="2000-05-24" name="CVE-2000-0442" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Qpopper 2.53 and earlier allows local users to gain privileges via a formatting string in the From: header, which is processed by the euidl command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1242" source="BID">1242</ref>
      <ref url="http://www.novell.com/linux/security/advisories/suse_security_announce_51.html" source="SUSE">20000608 pop &lt;= 2000.3.4</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0267.html" source="BUGTRAQ">20000523 Qpopper 2.53 remote problem, user can gain gid=mail</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qualcomm" name="qpopper">
        <vers num="2.52" />
        <vers num="2.53" />
      </prod>
      <prod vendor="sun" name="cobalt_raq_2">
        <vers num="" />
      </prod>
      <prod vendor="sun" name="cobalt_raq_3i">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0443" published="2000-05-24" name="CVE-2000-0443" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The web interface server in HP Web JetAdmin 5.6 allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1243" source="BID">1243</ref>
      <ref url="http://www.osvdb.org/1350" source="OSVDB">1350</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0281.html" source="BUGTRAQ">20000524 HP Web JetAdmin Version 5.6 Web interface Server Directory Traversal Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="jetadmin">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0444" published="2000-05-24" name="CVE-2000-0444" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">HP Web JetAdmin 6.0 allows remote attackers to cause a denial of service via a malformed URL to port 8000.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1246" source="BID">1246</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0277.html" source="BUGTRAQ">20000524 HP Web JetAdmin Version 6.0 Remote DoS attack Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="jetadmin">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0445" published="2000-05-24" name="CVE-2000-0445" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The pgpk command in PGP 5.x on Unix systems uses an insufficiently random data source for non-interactive key pair generation, which may produce predictable keys.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2000-09.html" source="CERT">CA-2000-09</ref>
      <ref url="http://www.securityfocus.com/bid/1251" source="BID">1251</ref>
      <ref url="http://www.osvdb.org/1355" source="OSVDB">1355</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0273.html" source="BUGTRAQ">20000523 Key Generation Security Flaw in PGP 5.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pgp" name="pgp">
        <vers num="5.0_linux" />
        <vers num="5.0i" />
        <vers num="6.5_linux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0446" published="2000-05-24" name="CVE-2000-0446" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in MDBMS database server allows remote attackers to execute arbitrary commands via a long string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1252" source="BID">1252</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0274.html" source="BUGTRAQ">20000524 Remote xploit for MDBMS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="marty_bochane" name="mdbms">
        <vers num="0.9_xbx" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0447" published="2000-05-01" name="CVE-2000-0447" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in WebShield SMTP 4.5.44 allows remote attackers to execute arbitrary commands via a long configuration parameter to the WebShield remote management service.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=6C740781F92BD411831F0090273A8AB806FD4A@exchange.servers.delphis.net" source="BUGTRAQ">20000525 DST2K0003 : Buffer Overrun in NAI WebShield SMTP v4.5.44 Managem ent Tool </ref>
      <ref url="http://www.securityfocus.com/bid/1254" source="BID">1254</ref>
      <ref url="http://www.osvdb.org/327" source="OSVDB">327</ref>
    </refs>
    <vuln_soft>
      <prod vendor="network_associates" name="webshield">
        <vers num="4.5.44" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0448" published="2000-05-01" name="CVE-2000-0448" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The WebShield SMTP Management Tool version 4.5.44 does not properly restrict access to the management port when an IP address does not resolve to a hostname, which allows remote attackers to access the configuration via the GET_CONFIG command.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=6C740781F92BD411831F0090273A8AB806FD4A@exchange.servers.delphis.net" source="BUGTRAQ">20000525 DST2K0003 : Buffer Overrun in NAI WebShield SMTP v4.5.44 Managem ent Tool </ref>
      <ref url="http://www.securityfocus.com/bid/1253" source="BID">1253</ref>
      <ref url="http://www.osvdb.org/326" source="OSVDB">326</ref>
    </refs>
    <vuln_soft>
      <prod vendor="network_associates" name="webshield">
        <vers num="4.5.44" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0449" published="2000-05-01" name="CVE-2000-0449" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Omnis Studio 2.4 uses weak encryption (trivial encoding) for encrypting database fields.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1255" source="BID">1255</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0311.html" source="BUGTRAQ">20000525 Omnis Weak Encryption - Many products affected</ref>
    </refs>
    <vuln_soft>
      <prod vendor="omnis" name="studio">
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0450" published="2000-05-18" name="CVE-2000-0450" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Vulnerability in bbd server in Big Brother System and Network Monitor allows an attacker to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1257" source="BID">1257</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0216.html" source="BUGTRAQ">20000518 FW: Security Notice: Big Brother System and Network Monitor</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sean_macguire" name="big_brother">
        <vers num="1.3b" />
        <vers num="1.4" />
        <vers num="1.4g" />
        <vers num="1.4h1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0451" published="2000-05-19" name="CVE-2000-0451" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Intel express 8100 ISDN router allows remote attackers to cause a denial of service via oversized or fragmented ICMP packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1228" source="BID">1228</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0229.html" source="BUGTRAQ">20000518 Remote Dos attack against Intel express 8100 router</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intel" name="express_8100">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0452" published="2000-05-18" name="CVE-2000-0452" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in the ESMTP service of Lotus Domino Server 5.0.1 allows remote attackers to cause a denial of service via a long MAIL FROM command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1229" source="BID">1229</ref>
      <ref url="http://www.osvdb.org/321" source="OSVDB">321</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0219.html" source="BUGTRAQ">20000518 Lotus ESMTP Service (Lotus Domino Release 5.0.1 (Intl))</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lotus" name="domino_enterprise_server">
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
      </prod>
      <prod vendor="lotus" name="domino_mail_server">
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0453" published="2000-05-18" name="CVE-2000-0453" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">XFree86 3.3.x and 4.0 allows a user to cause a denial of service via a negative counter value in a malformed TCP packet that is sent to port 6000.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1235" source="BID">1235</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0223.html" source="BUGTRAQ">20000518 Nasty XFree Xserver DoS</ref>
      <ref url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2000-012.0.txt" source="CALDERA">CSSA-2000-012.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xfree86_project" name="x11r6">
        <vers num="3.3.5" />
        <vers num="3.3.6" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0454" published="2000-05-29" name="CVE-2000-0454" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Linux cdrecord allows local users to gain privileges via the dev parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1265" source="BID">1265</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0019.html" source="BUGTRAQ">20000607 Conectiva Linux Security Announcement - cdrecord</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0434.html" source="BUGTRAQ">20000603 [Gael Duval ] [Security Announce] cdrecord</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0367.html" source="BUGTRAQ">20000527 Mandrake 7.0: /usr/bin/cdrecord gid=80 (strike #2)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0455" published="2000-05-29" name="CVE-2000-0455" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Buffer overflow in xlockmore xlock program version 4.16 and earlier allows local users to read sensitive data from memory via a long -mode option.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1267" source="BID">1267</ref>
      <ref url="http://www.nai.com/nai_labs/asp_set/advisory/41initialized.asp" source="NAI">20000529 Initialized Data Overflow in Xlock</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0375.html" source="TURBO">TLSA2000012-1</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-003.txt.asc" source="NETBSD">NetBSD-SA2000-003</ref>
    </refs>
    <vuln_soft>
      <prod vendor="david_bagley" name="xlock">
        <vers num="4.16" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0456" published="2000-05-28" name="CVE-2000-0456" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">NetBSD 1.4.2 and earlier allows local users to cause a denial of service by repeatedly running certain system calls in the kernel which do not yield the CPU, aka "cpu-hog".</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1272" source="BID">1272</ref>
      <ref url="http://www.osvdb.org/1365" source="OSVDB">1365</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-005.txt.asc" source="NETBSD">NetBSD-SA2000-005</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.4.1" edition="" />
        <vers num="1.4.1" edition=":sparc" />
        <vers num="1.4.1" edition=":arm32" />
        <vers num="1.4.1" edition=":alpha" />
        <vers num="1.4.1" edition=":x86" />
        <vers num="1.4.2" edition="" />
        <vers num="1.4.2" edition=":arm32" />
        <vers num="1.4.2" edition=":sparc" />
        <vers num="1.4.2" edition=":alpha" />
        <vers num="1.4.2" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0457" published="2000-05-11" name="CVE-2000-0457" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">ISM.DLL in IIS 4.0 and 5.0 allows remote attackers to read file contents by requesting the file and appending a large number of encoded spaces (%20) and terminated with a .htr extension, aka the ".HTR File Fragment Reading" or "File Fragment Reading via .HTR" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4448.php" source="XF" patch="1" adv="1">iis-ism-file-access(4448)</ref>
      <ref url="http://www.securityfocus.com/bid/1193" source="BID">1193</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-031.mspx" source="MS">MS00-031</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95810120719608&amp;w=2" source="BUGTRAQ">20000511 Alert: IIS ism.dll exposes file contents</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0458" published="2000-04-22" name="CVE-2000-0458" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The MSWordView application in IMP creates world-readable files in the /tmp directory, which allows other local users to read potentially sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1360" source="BID">1360</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95672120116627&amp;w=2" source="BUGTRAQ">20000424 Two Problems in IMP 2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="imp" name="imp">
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.9" />
        <vers num="2.2_pre10" />
        <vers num="2.2_pre9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0459" published="2000-04-22" name="CVE-2000-0459" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IMP does not remove files properly if the MSWordView application quits, which allows local users to cause a denial of service by filling up the disk space by requesting a large number of documents and prematurely stopping the request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1361" source="BID">1361</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95672120116627&amp;w=2" source="BUGTRAQ">20000424 Two Problems in IMP 2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="imp" name="imp">
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.9" />
        <vers num="2.2_pre10" />
        <vers num="2.2_pre11" />
        <vers num="2.2_pre12" />
        <vers num="2.2_pre9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0460" published="2000-05-27" name="CVE-2000-0460" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in KDE kdesud on Linux allows local uses to gain privileges via a long DISPLAY environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0353.html" source="BUGTRAQ" adv="1">20000526 KDE: /usr/bin/kdesud, gid = 0 exploit</ref>
      <ref url="http://www.securityfocus.com/bid/1274" source="BID">1274</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="kde">
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0461" published="2000-05-29" name="CVE-2000-0461" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The undocumented semconfig system call in BSD freezes the state of semaphores, which allows local users to cause a denial of service of the semaphore system by using the semconfig call.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1270" source="BID">1270</ref>
      <ref url="http://www.openbsd.org/errata26.html#semconfig" source="OPENBSD">20000526</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-004.txt.asc" source="NETBSD">NetBSD-SA2000-004</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:19.semconfig.asc" source="FREEBSD">FreeBSD-SA-00:19</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="1.1.5.1" />
        <vers num="2.0" />
        <vers num="2.0.5" />
        <vers num="2.1.0" />
        <vers num="2.1.5" />
        <vers num="2.1.6" />
        <vers num="2.1.6.1" />
        <vers num="2.1.7.1" />
        <vers num="2.2" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.8" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="4.0" edition="alpha" />
        <vers num="5.0" edition="alpha" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.4.1" edition="" />
        <vers num="1.4.1" edition=":arm32" />
        <vers num="1.4.1" edition=":alpha" />
        <vers num="1.4.1" edition=":sparc" />
        <vers num="1.4.2" edition="" />
        <vers num="1.4.2" edition=":sparc" />
        <vers num="1.4.2" edition=":alpha" />
        <vers num="1.4.2" edition=":arm32" />
        <vers num="1.4.2" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0462" published="2000-05-28" name="CVE-2000-0462" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">ftpd in NetBSD 1.4.2 does not properly parse entries in /etc/ftpchroot and does not chroot the specified users, which allows those users to access other files outside of their home directory.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1273" source="BID">1273</ref>
      <ref url="http://www.osvdb.org/1366" source="OSVDB">1366</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-006.txt.asc" source="NETBSD">NetBSD-SA2000-006</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.4.2" edition="" />
        <vers num="1.4.2" edition=":arm32" />
        <vers num="1.4.2" edition=":sparc" />
        <vers num="1.4.2" edition=":alpha" />
        <vers num="1.4.2" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0463" published="2000-05-18" name="CVE-2000-0463" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BeOS 5.0 allows remote attackers to cause a denial of service via fragmented TCP packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1222" source="BID">1222</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0197.html" source="BUGTRAQ">20000517 AUX Security Advisory on Be/OS 5.0 (DoS)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="be" name="beos">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0464" published="2000-05-17" name="CVE-2000-0464" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Internet Explorer 4.x and 5.x allows remote attackers to execute arbitrary commands via a buffer overflow in the ActiveX parameter parsing capability, aka the "Malformed Component Attribute" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-033.asp" source="MS" patch="1" adv="1">MS00-033</ref>
      <ref url="http://www.securityfocus.com/bid/1223" source="BID">1223</ref>
      <ref url="http://www.microsoft.com/technet/support/kb.asp?ID=261257" source="MSKB">Q261257</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="5.0" />
        <vers num="5.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0465" published="2000-05-17" name="CVE-2000-0465" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Internet Explorer 4.x and 5.x does properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files via the frame, aka the "Frame Domain Verification" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-033.asp" source="MS">MS00-033</ref>
      <ref url="http://www.securityfocus.com/bid/1224" source="BID">1224</ref>
      <ref url="http://www.microsoft.com/technet/support/kb.asp?ID=255676" source="MSKB">Q255676</ref>
      <ref url="http://www.microsoft.com/technet/support/kb.asp?ID=251108" source="MSKB">Q251108</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="5.01" />
        <vers num="5.5" edition="preview" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0466" published="2000-06-20" name="CVE-2000-0466" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">AIX cdmount allows local users to gain root privileges via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1384" source="BID" patch="1" adv="1">1384</ref>
      <ref url="http://xforce.iss.net/alerts/advise55.php" source="ISS" adv="1">20000620 Insecure call of external program in AIX cdmount</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0467" published="2000-06-01" name="CVE-2000-0467" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Linux splitvt 1.6.3 and earlier allows local users to gain root privileges via a long password in the screen locking function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0125.html" source="BUGTRAQ" patch="1" adv="1">20000614 Splitvt exploit</ref>
      <ref url="http://www.securityfocus.com/bid/1346" source="BID">1346</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sam_lantinga" name="splitvt">
        <vers num="1.6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0468" published="2000-06-02" name="CVE-2000-0468" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">man in HP-UX 10.20 and 11 allows local attackers to overwrite files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1302" source="BID" patch="1" adv="1">1302</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.SOL.4.02.10006021014400.4779-100000@nofud.nwest.attws.com" source="BUGTRAQ">20000601 HP Security vulnerability in the man command</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.20" />
        <vers num="11.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0469" published="2000-02-02" name="CVE-2000-0469" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Selena Sol WebBanner 4.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-06-22&amp;msg=ILENKALMCAFBLHBGEOFKGEJCCAAA.jwesterink@jwesterink.daxis.nl" source="BUGTRAQ" patch="1" adv="1">20000613 CGI: Selena Sol's WebBanner ( Random Banner Generator ) Vulnerability</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=4.2.0.58.20000620193604.00979950@mail.clark.net" source="BUGTRAQ">20000620 Re: CGI: Selena Sol's WebBanner ( Random Banner Generator ) Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/1347" source="BID">1347</ref>
    </refs>
    <vuln_soft>
      <prod vendor="selena_sol" name="webbanner">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0470" published="2000-06-01" name="CVE-2000-0470" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Allegro RomPager HTTP server allows remote attackers to cause a denial of service via a malformed authentication request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4588.php" source="XF" adv="1">rompager-malformed-dos</ref>
      <ref url="http://www.securityfocus.com/bid/1290" source="BID">1290</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0398.html" source="BUGTRAQ">20000601 Hardware Exploit - Gets network Down</ref>
    </refs>
    <vuln_soft>
      <prod vendor="allegro" name="rom_pager">
        <vers num="2.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0471" published="2000-06-14" name="CVE-2000-0471" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in ufsrestore in Solaris 8 and earlier allows local users to gain root privileges via a long pathname.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/36866" source="CERT-VN">VU#36866</ref>
      <ref url="http://www.securityfocus.com/bid/1348" source="BID" patch="1" adv="1">1348</ref>
      <ref url="http://xforce.iss.net/static/4711.php" source="XF" adv="1">sol-ufsrestore-bo</ref>
      <ref url="http://www.osvdb.org/1398" source="OSVDB">1398</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/210" source="SUN">00210</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0114.html" source="BUGTRAQ">20000614 Vulnerability in Solaris ufsrestore</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="" edition=":x86" />
        <vers num="1.1" />
        <vers num="1.1.1a" />
        <vers num="1.1.2" />
        <vers num="1.1.3" edition="u1" />
        <vers num="1.1.4" edition="" />
        <vers num="1.1.4" edition=":jl" />
        <vers num="1.2" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":ppc" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" edition="hw3" />
        <vers num="2.6" edition="hw5" />
        <vers num="5.3" />
        <vers num="5.4" edition="" />
        <vers num="5.4" edition=":x86" />
        <vers num="5.5" edition="" />
        <vers num="5.5" edition=":x86" />
        <vers num="5.5.1" edition="" />
        <vers num="5.5.1" edition=":x86" />
        <vers num="5.6" edition="" />
        <vers num="5.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0472" published="2000-02-06" name="CVE-2000-0472" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Buffer overflow in innd 2.2.2 allows remote attackers to execute arbitrary commands via a cancel request containing a long message ID.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4615.php" source="XF" patch="1" adv="1">innd-cancel-overflow</ref>
      <ref url="http://www.securityfocus.com/bid/1316" source="BID">1316</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0330.html" source="BUGTRAQ">20000722 MDKSA-2000:023 inn update</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0298.html" source="BUGTRAQ">20000721 [ANNOUNCE] INN 2.2.3 available</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0097.html" source="BUGTRAQ">20000707 inn update</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0003.html" source="BUGTRAQ">20000106 innd 2.2.2 remote buffer overflow</ref>
      <ref url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-2000-016.0.txt" source="CALDERA">CSSA-2000-016.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="inn">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0473" published="2000-06-15" name="CVE-2000-0473" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in AnalogX SimpleServer 1.05 allows a remote attacker to cause a denial of service via a long GET request for a program in the cgi-bin directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1349" source="BID" patch="1" adv="1">1349</ref>
      <ref url="http://www.analogx.com/contents/download/network/sswww.htm" source="MISC" patch="1">http://www.analogx.com/contents/download/network/sswww.htm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="analogx" name="simpleserver_www">
        <vers num="1.01" />
        <vers num="1.03" />
        <vers num="1.04" />
        <vers num="1.05" />
        <vers num="1.06" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0474" published="2000-06-01" name="CVE-2000-0474" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Real Networks RealServer 7.x allows remote attackers to cause a denial of service via a malformed request for a page in the viewsource directory.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1288" source="BID" patch="1" adv="1">1288</ref>
      <ref url="http://xforce.iss.net/static/4587.php" source="XF" adv="1">realserver-malformed-remote-dos</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0427.html" source="BUGTRAQ">20000601 Remote DoS attack in RealServer: USSR-2000043</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0410.html" source="BUGTRAQ">20000601 Remote DoS attack in Real Networks Real Server (Strike #2) Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realserver">
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="8.0_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0475" published="2000-06-15" name="CVE-2000-0475" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Windows 2000 allows a local user process to access another user's desktop within the same windows station, aka the "Desktop Separation" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4714.php" source="XF" patch="1" adv="1">win2k-desktop-separation</ref>
      <ref url="http://www.securityfocus.com/bid/1350" source="BID" patch="1" adv="1">1350</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-020.asp" source="MS" patch="1" adv="1">MS00-020</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0476" published="2000-06-01" name="CVE-2000-0476" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">xterm, Eterm, and rxvt allow an attacker to cause a denial of service by embedding certain escape characters which force the window to be resized.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1298" source="BID" patch="1" adv="1">1298</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0409.html" source="BUGTRAQ" patch="1" adv="1">20000601 [rootshell.com] Xterm DoS Attack</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0420.html" source="BUGTRAQ">20000601 [rootshell.com] Xterm DoS Attack</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michael_jennings" name="eterm">
        <vers num="0.8.10" />
      </prod>
      <prod vendor="putty" name="putty">
        <vers num="0.48" />
      </prod>
      <prod vendor="rxvt" name="rxvt">
        <vers num="2.6.1" />
      </prod>
      <prod vendor="xfree86_project" name="x11r6">
        <vers num="3.3.3" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0477" published="2000-06-14" name="CVE-2000-0477" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Norton Antivirus for Exchange (NavExchange) allows remote attackers to cause a denial of service via a .zip file that contains long file names.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1351" source="BID" patch="1" adv="1">1351</ref>
      <ref url="http://xforce.iss.net/static/4710.php" source="XF">antivirus-nav-zip-bo</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0136.html" source="BUGTRAQ">20000614 Vulnerabilities in Norton Antivirus for Exchange</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="norton_antivirus">
        <vers num="1.5" edition="" />
        <vers num="1.5" edition=":ms_exchange" />
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":ms_exchange" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0478" published="2000-06-14" name="CVE-2000-0478" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">In some cases, Norton Antivirus for Exchange (NavExchange) enters a "fail-open" state which allows viruses to pass through the server.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1351" source="BID" adv="1">1351</ref>
      <ref url="http://xforce.iss.net/static/4709.php" source="XF">antivirus-nav-fail-open</ref>
      <ref url="http://www.osvdb.org/6266" source="OSVDB">6266</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0136.html" source="BUGTRAQ">20000614 Vulnerabilities in Norton Antivirus for Exchange</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="norton_antivirus">
        <vers num="1.5" edition="" />
        <vers num="1.5" edition=":ms_exchange" />
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":ms_exchange" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0479" published="2000-06-16" name="CVE-2000-0479" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Dragon FTP server allows remote attackers to cause a denial of service via a long USER command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1352" source="BID" adv="1">1352</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96113734714517&amp;w=2" source="BUGTRAQ">20000616 Multiples Remotes DoS Attacks in Dragon Server v1.00 and v2.00</ref>
    </refs>
    <vuln_soft>
      <prod vendor="shadow_op_software" name="dragon_server">
        <vers num="1.0" />
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0480" published="2000-06-16" name="CVE-2000-0480" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Dragon telnet server allows remote attackers to cause a denial of service via a long username.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1352" source="BID" adv="1">1352</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96113734714517&amp;w=2" source="BUGTRAQ">20000616 Multiples Remotes DoS Attacks in Dragon Server v1.00 and v2.00</ref>
    </refs>
    <vuln_soft>
      <prod vendor="shadow_op_software" name="dragon_server">
        <vers num="1.0" />
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0481" published="1999-06-01" name="CVE-2000-0481" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in KDE Kmail allows a remote attacker to cause a denial of service via an attachment with a long file name.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1380" source="BID" patch="1" adv="1">1380</ref>
      <ref url="http://securityfocus.com/templates/archive.pike?list=82&amp;date=2000-06-22&amp;msg=00060200422401.01667@lez" source="VULN-DEV" adv="1">20000601 Kmail heap overflow</ref>
      <ref url="http://xforce.iss.net/static/4993.php" source="XF">kde-kmail-attachment-dos</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="k-mail">
        <vers num="1.0.23" />
        <vers num="1.0.24" />
        <vers num="1.0.25" />
        <vers num="1.0.26" />
        <vers num="1.0.27" />
        <vers num="1.0.28" />
        <vers num="1.0.29" />
        <vers num="1.0.29.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0482" published="2000-06-06" name="CVE-2000-0482" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Check Point Firewall-1 allows remote attackers to cause a denial of service by sending a large number of malformed fragmented IP packets.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1312" source="BID" patch="1" adv="1">1312</ref>
      <ref url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#IP_Fragmentation" source="CONFIRM">http://www.checkpoint.com/techsupport/alerts/list_vun.html#IP_Fragmentation</ref>
      <ref url="http://xforce.iss.net/static/4609.php" source="XF">fw1-packet-fragment-dos</ref>
      <ref url="http://www.osvdb.org/1379" source="OSVDB">1379</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0473.html" source="BUGTRAQ">20000605 FW-1 IP Fragmentation Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="checkpoint" name="firewall-1">
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0483" published="2000-06-15" name="CVE-2000-0483" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The DocumentTemplate package in Zope 2.2 and earlier allows a remote attacker to modify DTMLDocuments or DTMLMethods without authorization.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.zope.org/Products/Zope/Hotfix_06_16_2000/security_alert" source="CONFIRM" patch="1">http://www.zope.org/Products/Zope/Hotfix_06_16_2000/security_alert</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0144.html" source="BUGTRAQ" patch="1" adv="1">20000615 [Brian@digicool.com: [Zope] Zope security alert and 2.1.7 update [*important*]]</ref>
      <ref url="http://xforce.iss.net/static/4716.php" source="XF" adv="1">zope-dtml-remote-modify</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000616103807.A3768@conectiva.com.br" source="BUGTRAQ">2000615 Conectiva Linux Security Announcement - ZOPE</ref>
      <ref url="http://www.securityfocus.com/bid/1354" source="BID">1354</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-038.html" source="REDHAT">RHSA-2000:038</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0412.html" source="BUGTRAQ">20000728 MDKSA-2000:026 Zope update</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00%3A38.zope.asc" source="FREEBSD">FreeBSD-SA-00:38</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux_powertools">
        <vers num="6.1" />
        <vers num="6.2" />
      </prod>
      <prod vendor="zope" name="zope">
        <vers num="1.10.3" />
        <vers num="2.1.1" />
        <vers num="2.1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0484" published="2000-06-15" name="CVE-2000-0484" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Small HTTP Server allows remote attackers to cause a denial of service via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4692.php" source="XF" adv="1">small-http-get-overflow-dos</ref>
      <ref url="http://www.securityfocus.com/bid/1355" source="BID">1355</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=96151775004229&amp;w=2" source="NTBUGTRAQ">20000616 Remote DoS Attack in Small HTTP Server ver. 1.212 Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96113651713414&amp;w=2" source="BUGTRAQ">20000616 Remote DoS Attack in Small HTTP Server ver. 1.212 Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="max_feoktistov" name="small_http_server">
        <vers num="1.212" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0485" published="2000-05-30" name="CVE-2000-0485" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Microsoft SQL Server allows local users to obtain database passwords via the Data Transformation Service (DTS) package Properties dialog, aka the "DTS Password" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-041.asp" source="MS" patch="1" adv="1">MS00-041</ref>
      <ref url="http://xforce.iss.net/static/4582.php" source="XF" adv="1">mssql-dts-reveal-passwords</ref>
      <ref url="http://www.securityfocus.com/bid/1292" source="BID">1292</ref>
      <ref url="http://www.securityfocus.com/archive/1/62771" source="BUGTRAQ">20000530 Fw: Steal Passwords Using SQL Server EM</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="sql_server">
        <vers num="6.5" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0486" published="2000-05-30" name="CVE-2000-0486" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Cisco TACACS+ tac_plus server allows remote attackers to cause a denial of service via a malformed packet with a long length field.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0369.html" source="BUGTRAQ" patch="1" adv="1">20000530 An Analysis of the TACACS+ Protocol and its Implementations</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0370.html" source="CONFIRM">http://archives.neohapsis.com/archives/bugtraq/2000-05/0370.html</ref>
      <ref url="http://xforce.iss.net/static/4985.php" source="XF">tacacsplus-packet-length-dos</ref>
      <ref url="http://www.securityfocus.com/bid/1293" source="BID">1293</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="tacacs+">
        <vers num="f4.0.2alpha" />
        <vers num="f4.0.3alpha" />
      </prod>
      <prod vendor="cisco" name="ios">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0487" published="2000-06-01" name="CVE-2000-0487" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">The Protected Store in Windows 2000 does not properly select the strongest encryption when available, which causes it to use a default of 40-bit encryption instead of 56-bit DES encryption, aka the "Protected Store Key Length" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1295" source="BID" patch="1" adv="1">1295</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-032.asp" source="MS" patch="1" adv="1">MS00-032</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0488" published="2000-05-30" name="CVE-2000-0488" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in ITHouse mail server 1.04 allows remote attackers to execute arbitrary commands via a long RCPT TO mail command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4580.php" source="XF" adv="1">ithouse-rcpt-overflow(4580)</ref>
      <ref url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q2/0148.html" source="BUGTRAQ" adv="1">20000601 DST2K0007: Buffer Overrun in ITHouse Mail Server v1.04</ref>
      <ref url="http://www.securityfocus.com/bid/1285" source="BID">1285</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ithouse" name="ithouse_mail_server">
        <vers num="1.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0489" published="1999-09-05" name="CVE-2000-0489" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">FreeBSD, NetBSD, and OpenBSD allow an attacker to cause a denial of service by creating a large number of socket pairs using the socketpair function, setting a large buffer size via setsockopt, then writing large buffers.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3298.php" source="XF" adv="1">bsd-setsockopt-dos</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.10.9908270039010.16315-100000@thetis.deor.org" source="BUGTRAQ">19990826 Local DoS in FreeBSD</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=NCBBKFKDOLAGKIAPMILPCEJLCEAA.labs@ussrback.com" source="BUGTRAQ">20000601 Local FreeBSD, Openbsd, NetBSD, DoS Vulnerability - Mac OS X affected</ref>
      <ref url="http://www.securityfocus.com/bid/622" source="BID">622</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="3.5" />
        <vers num="4.0" />
        <vers num="5.0" edition="alpha" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.4" edition="" />
        <vers num="1.4" edition=":x86" />
        <vers num="1.4.1" edition="" />
        <vers num="1.4.1" edition=":arm32" />
        <vers num="1.4.1" edition=":alpha" />
        <vers num="1.4.1" edition=":x86" />
        <vers num="1.4.1" edition=":sparc" />
        <vers num="1.4.2" edition="" />
        <vers num="1.4.2" edition=":sparc" />
        <vers num="1.4.2" edition=":alpha" />
        <vers num="1.4.2" edition=":arm32" />
        <vers num="1.4.2" edition=":x86" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.5" />
        <vers num="2.6" />
        <vers num="2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0490" published="2000-06-01" name="CVE-2000-0490" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the NetWin DSMTP 2.7q in the NetWin dmail package allows remote attackers to execute arbitrary commands via a long ETRN request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1297" source="BID" patch="1" adv="1">1297</ref>
      <ref url="http://xforce.iss.net/static/4579.php" source="XF" adv="1">dmail-etrn-dos</ref>
      <ref url="http://netwinsite.com/dmail/security.htm" source="CONFIRM">http://netwinsite.com/dmail/security.htm</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0407.html" source="BUGTRAQ">20000601 Netwin's Dmail package</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netwin" name="dmail">
        <vers num="2.7" />
        <vers num="2.7q" />
        <vers num="2.8e" />
        <vers num="2.8f" />
        <vers num="2.8g" />
        <vers num="2.8h" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0491" published="2000-05-24" name="CVE-2000-0491" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the XDMCP parsing code of GNOME gdm, KDE kdm, and wdm allows remote attackers to execute arbitrary commands or cause a denial of service via a long FORWARD_QUERY request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-2000-013.0.txt" source="CALDERA" patch="1" adv="1">CSSA-2000-013.0</ref>
      <ref url="http://www.securityfocus.com/bid/1370" source="BID">1370</ref>
      <ref url="http://www.securityfocus.com/bid/1279" source="BID">1279</ref>
      <ref url="http://www.securityfocus.com/bid/1233" source="BID">1233</ref>
      <ref url="http://www.novell.com/linux/security/advisories/suse_security_announce_49.html" source="SUSE">20000524 Security hole in gdm &lt;= 2.0beta4-25</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0025.html" source="BUGTRAQ">20000607 Conectiva Linux Security Announcement - gdm</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0241.html" source="BUGTRAQ">20000521 "gdm" remote hole</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="gdm">
        <vers num="1.0" />
      </prod>
      <prod vendor="caldera" name="openlinux">
        <vers num="" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="6.2" />
        <vers num="6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0492" published="2000-06-04" name="CVE-2000-0492" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PassWD 1.2 uses weak encryption (trivial encoding) to store passwords, which allows an attacker who can read the password file to easliy decrypt the passwords.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0450.html" source="BUGTRAQ" patch="1" adv="1">20000609 Insecure encryption in PassWD v1.2</ref>
      <ref url="http://www.securityfocus.com/bid/1300" source="BID">1300</ref>
    </refs>
    <vuln_soft>
      <prod vendor="passwd" name="passwd">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0493" published="2000-06-01" name="CVE-2000-0493" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Simple Network Time Sync (SMTS) daemon allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4602.php" source="XF" adv="1">timesync-bo-execute</ref>
      <ref url="http://archives.neohapsis.com/archives/vuln-dev/2000-q2/0843.html" source="VULN-DEV" adv="1">20000601 Vulnerability in SNTS</ref>
      <ref url="http://www.securityfocus.com/bid/1289" source="BID">1289</ref>
    </refs>
    <vuln_soft>
      <prod vendor="atrius_trivalie_sn" name="time_sync">
        <vers num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0494" published="2000-06-16" name="CVE-2000-0494" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Veritas Volume Manager creates a world writable .server_pids file, which allows local users to add arbitrary commands into the file, which is then executed by the vmsa_server script.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1356" source="BID" patch="1" adv="1">1356</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0151.html" source="BUGTRAQ" patch="1" adv="1">20000616 Veritas Volume Manager 3.0.x hole</ref>
      <ref url="http://seer.support.veritas.com/tnotes/volumeman/230053.htm" source="CONFIRM">http://seer.support.veritas.com/tnotes/volumeman/230053.htm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec_veritas" name="volume_manager">
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0495" published="2000-05-30" name="CVE-2000-0495" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Windows Media Encoder allows remote attackers to cause a denial of service via a malformed request, aka the "Malformed Windows Media Encoder Request" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4585.php" source="XF" patch="1" adv="1">ms-malformed-media-dos</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-038.asp" source="MS" patch="1" adv="1">MS00-038</ref>
      <ref url="http://www.securityfocus.com/bid/1282" source="BID">1282</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_media_services">
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0497" published="2000-06-08" name="CVE-2000-0497" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IBM WebSphere server 3.0.2 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0263.html" source="NTBUGTRAQ" patch="1" adv="1">20000612 IBM WebSphere JSP showcode vulnerability</ref>
      <ref url="http://www-4.ibm.com/software/webservers/appserv/efix.html" source="CONFIRM">http://www-4.ibm.com/software/webservers/appserv/efix.html</ref>
      <ref url="http://www.securityfocus.com/bid/1328" source="BID">1328</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="3.0.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0498" published="2000-06-08" name="CVE-2000-0498" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unify eWave ServletExec allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4649.php" source="XF" adv="1">ewave-servletexec-jsp-source-read(4649)</ref>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0250.html" source="NTBUGTRAQ" adv="1">20000608 Potential vulnerability in Unify eWave ServletExec</ref>
      <ref url="http://www.securityfocus.com/bid/1328" source="BID">1328</ref>
    </refs>
    <vuln_soft>
      <prod vendor="unify" name="ewave_servletexec">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0499" published="2000-06-08" name="CVE-2000-0499" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The default configuration of BEA WebLogic 3.1.8 through 4.5.1 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1328" source="BID" patch="1" adv="1">1328</ref>
      <ref url="http://developer.bea.com/alerts/security_000612.html" source="CONFIRM">http://developer.bea.com/alerts/security_000612.html</ref>
      <ref url="http://xforce.iss.net/static/4694.php" source="XF">weblogic-jsp-source-read</ref>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0262.htm" source="NTBUGTRAQ">20000612 BEA WebLogic JSP showcode vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="" edition=":express" />
        <vers num="3.1.8" />
        <vers num="4.0.4" />
        <vers num="4.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0500" published="2000-06-21" name="CVE-2000-0500" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The default configuration of BEA WebLogic 5.1.0 allows a remote attacker to view source code of programs by requesting a URL beginning with /file/, which causes the default servlet to display the file without further processing.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1378" source="BID" patch="1" adv="1">1378</ref>
      <ref url="http://xforce.iss.net/static/4775.php" source="XF" adv="1">weblogic-file-source-read</ref>
      <ref url="http://www.weblogic.com/docs51/admindocs/http.html#file" source="CONFIRM">http://www.weblogic.com/docs51/admindocs/http.html#file</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96161462915381&amp;w=2" source="BUGTRAQ">20000621 BEA WebLogic /file/ showcode vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="3.1.8" edition="" />
        <vers num="3.1.8" edition=":express" />
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":express" />
        <vers num="4.5" edition="" />
        <vers num="4.5" edition=":express" />
        <vers num="5.1" edition="" />
        <vers num="5.1" edition=":express" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0501" published="2000-06-16" name="CVE-2000-0501" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Race condition in MDaemon 2.8.5.0 POP server allows local users to cause a denial of service by entering a UIDL command and quickly exiting the server.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4745.php" source="XF" patch="1" adv="1">mdaemon-pass-dos</ref>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0277.html" source="NTBUGTRAQ" patch="1" adv="1">20000616 mdaemon 2.8.5.0 WinNT and Win9x remote DoS</ref>
      <ref url="http://www.securityfocus.com/bid/1366" source="BID">1366</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alt-n" name="mdaemon">
        <vers num="2.8.5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0502" published="2000-06-08" name="CVE-2000-0502" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Mcafee VirusScan 4.03 does not properly restrict access to the alert text file before it is sent to the Central Alert Server, which allows local users to modify alerts in an arbitrary fashion.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1326" source="BID" adv="1">1326</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0038.html" source="BUGTRAQ" adv="1">20000607 Mcafee Alerting DOS vulnerability</ref>
      <ref url="http://xforce.iss.net/static/4641.php" source="XF">mcafee-alerting-dos(4641)</ref>
      <ref url="http://www.osvdb.org/6287" source="OSVDB">6287</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcafee" name="virusscan">
        <vers num="4.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0503" published="2000-06-06" name="CVE-2000-0503" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">The IFRAME of the WebBrowser control in Internet Explorer 5.01 allows a remote attacker to violate the cross frame security policy via the NavigateComplete2 event.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q2/0154.html" source="BUGTRAQ" patch="1" adv="1">20000606 IE 5 Cross-frame security vulnerability using IFRAME and WebBrowser control</ref>
      <ref url="http://www.securityfocus.com/bid/1311" source="BID">1311</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="5.01" />
        <vers num="5.5" edition="preview" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0504" published="2000-06-19" name="CVE-2000-0504" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">libICE in XFree86 allows remote attackers to cause a denial of service by specifying a large value which is not properly checked by the SKIP_STRING macro.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1369" source="BID" patch="1" adv="1">1369</ref>
      <ref url="http://www.xfree86.org/security/" source="CONFIRM">http://www.xfree86.org/security/</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0170.html" source="BUGTRAQ" adv="1">20000619 XFree86: libICE DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="gdm">
        <vers num="1.0" />
        <vers num="1.1" />
      </prod>
      <prod vendor="open_group" name="x">
        <vers num="11.0r5" />
        <vers num="11.0r6" />
        <vers num="11.0r6.1" />
        <vers num="11.0r6.2" />
        <vers num="11.0r6.3" />
        <vers num="11.0r6.4" />
      </prod>
      <prod vendor="xfree86_project" name="x11r6">
        <vers num="3.3.3" />
        <vers num="3.3.4" />
        <vers num="3.3.5" />
        <vers num="3.3.6" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0505" published="2000-05-31" name="CVE-2000-0505" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Apache 1.3.x HTTP server for Windows platforms allows remote attackers to list directory contents by requesting a URL containing a large number of / characters.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.BSF.4.20.0006031912360.45740-100000@alive.znep.com" source="BUGTRAQ" patch="1" adv="1">20000603 Re: IBM HTTP SERVER / APACHE</ref>
      <ref url="http://www.securityfocus.com/bid/1284" source="BID" patch="1" adv="1">1284</ref>
      <ref url="http://xforce.iss.net/static/4575.php" source="XF">ibm-http-file-retrieve</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="1.3.11" edition="" />
        <vers num="1.3.11" edition=":win32" />
        <vers num="1.3.12" edition="" />
        <vers num="1.3.12" edition=":win32" />
        <vers num="1.3.6" edition="" />
        <vers num="1.3.6" edition=":win32" />
        <vers num="1.3.9" edition="" />
        <vers num="1.3.9" edition=":win32" />
      </prod>
      <prod vendor="ibm" name="http_server">
        <vers num="1.3.3" edition="" />
        <vers num="1.3.3" edition=":win32" />
        <vers num="1.3.6.2" edition="" />
        <vers num="1.3.6.2" edition=":win32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0506" published="2000-06-09" name="CVE-2000-0506" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The "capabilities" feature in Linux before 2.2.16 allows local users to cause a denial of service or gain privileges by setting the capabilities to prevent a setuid program from dropping privileges, aka the "Linux kernel setuid/setcap vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.21.0006090852340.3475-300000@alfa.elzabsoft.pl" source="BUGTRAQ" adv="1">20000609 Sendmail &amp; procmail local root exploits on Linux kernel up to 2.2.16pre5</ref>
      <ref url="http://www.securityfocus.com/bid/1322" source="BID">1322</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-037.html" source="REDHAT">RHSA-2000:037</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0063.html" source="BUGTRAQ">20000608 CONECTIVA LINUX SECURITY ANNOUNCEMENT - kernel</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0062.html" source="BUGTRAQ">20000609 Trustix Security Advisory</ref>
      <ref url="ftp://sgigate.sgi.com/security/20000802-01-P" source="SGI">20000802-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.0" />
        <vers num="2.0.30" />
        <vers num="2.0.33" />
        <vers num="2.0.34" />
        <vers num="2.0.35" />
        <vers num="2.0.36" />
        <vers num="2.0.37" />
        <vers num="2.0.38" />
        <vers num="2.1" />
        <vers num="2.2.0" />
        <vers num="2.2.10" />
        <vers num="2.2.12" />
        <vers num="2.2.13" />
        <vers num="2.2.14" />
        <vers num="2.2.15" edition="pre16" />
        <vers num="2.2.15_pre20" />
        <vers num="2.2.16" edition="pre5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0507" published="2000-06-01" name="CVE-2000-0507" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Imate Webmail Server 2.5 allows remote attackers to cause a denial of service via a long HELO command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4586.php" source="XF" patch="1" adv="1">nt-webmail-dos</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95990195708509&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20000601 DST2K0006: Denial of Service Possibility in Imate WebMail Server</ref>
      <ref url="http://www.securityfocus.com/bid/1286" source="BID" adv="1">1286</ref>
    </refs>
    <vuln_soft>
      <prod vendor="concatus" name="imate_webmail_server">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0508" published="1994-12-19" name="CVE-2000-0508" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">rpc.lockd in Red Hat Linux 6.1 and 6.2 allows remote attackers to cause a denial of service via a malformed request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1372" source="BID" patch="1" adv="1">1372</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0073.html" source="BUGTRAQ" patch="1" adv="1">20000608 Remote DOS in linux rpc.lockd</ref>
      <ref url="http://xforce.iss.net/static/5050.php" source="XF">linux-lockd-remote-dos</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="7.0" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0509" published="2000-06-01" name="CVE-2000-0509" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflows in the finger and whois demonstration scripts in Sambar Server 4.3 allow remote attackers to execute arbitrary commands via a long hostname.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1287" source="BID" patch="1" adv="1">1287</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95990103207665&amp;w=2" source="BUGTRAQ">20000601 DST2K0008: Buffer Overrun in Sambar Server 4.3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sambar" name="sambar_server">
        <vers prev="1" num="4.3" edition="beta9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0510" published="2000-06-21" name="CVE-2000-0510" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CUPS (Common Unix Printing System) 1.04 and earlier allows remote attackers to cause a denial of service via a malformed IPP request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="ftp://ftp.easysw.com/pub/cups/1.0.5/cups-DoS.patch" source="CONFIRM" patch="1" adv="1">ftp://ftp.easysw.com/pub/cups/1.0.5/cups-DoS.patch</ref>
      <ref url="http://www.securityfocus.com/bid/1373" source="BID" adv="1">1373</ref>
      <ref url="http://xforce.iss.net/static/4846.php" source="XF">debian-cups-malformed-ipp</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0188.html" source="BUGTRAQ">20000620 CUPS DoS Bugs</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.2" />
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0511" published="2000-06-21" name="CVE-2000-0511" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CUPS (Common Unix Printing System) 1.04 and earlier allows remote attackers to cause a denial of service via a CGI POST request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="ftp://ftp.easysw.com/pub/cups/1.0.5/cups-DoS.patch" source="CONFIRM" patch="1" adv="1">ftp://ftp.easysw.com/pub/cups/1.0.5/cups-DoS.patch</ref>
      <ref url="http://www.securityfocus.com/bid/1373" source="BID" adv="1">1373</ref>
      <ref url="http://xforce.iss.net/static/4846.php" source="XF">debian-cups-posts</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0188.html" source="BUGTRAQ">20000620 CUPS DoS Bugs</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.2" />
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0512" published="2000-06-16" name="CVE-2000-0512" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CUPS (Common Unix Printing System) 1.04 and earlier does not properly delete request files, which allows a remote attacker to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="ftp://ftp.easysw.com/pub/cups/1.0.5/cups-DoS.patch" source="CONFIRM" patch="1" adv="1">ftp://ftp.easysw.com/pub/cups/1.0.5/cups-DoS.patch</ref>
      <ref url="http://www.securityfocus.com/bid/1373" source="BID" adv="1">1373</ref>
      <ref url="http://xforce.iss.net/static/4846.php" source="XF">debian-cups-posts</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0188.html" source="BUGTRAQ">20000620 CUPS DoS Bugs</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.2" />
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0513" published="2000-06-21" name="CVE-2000-0513" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CUPS (Common Unix Printing System) 1.04 and earlier allows remote attackers to cause a denial of service by authenticating with a user name that does not exist or does not have a shadow password.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="ftp://ftp.easysw.com/pub/cups/1.0.5/cups-DoS.patch" source="CONFIRM" patch="1" adv="1">ftp://ftp.easysw.com/pub/cups/1.0.5/cups-DoS.patch</ref>
      <ref url="http://xforce.iss.net/static/4846.php" source="XF">debian-cups-posts</ref>
      <ref url="http://www.securityfocus.com/bid/1373" source="BID">1373</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0188.html" source="BUGTRAQ">20000620 CUPS DoS Bugs</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.2" />
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0514" published="2000-06-14" name="CVE-2000-0514" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">GSSFTP FTP daemon in Kerberos 5 1.1.x does not properly restrict access to some FTP commands, which allows remote attackers to cause a denial of service, and local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4734.php" source="XF" patch="1" adv="1">kerberos-gssftpd-dos</ref>
      <ref url="http://web.mit.edu/kerberos/www/advisories/ftp.txt" source="CONFIRM" patch="1" adv="1">http://web.mit.edu/kerberos/www/advisories/ftp.txt</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=ldvsnufao18.fsf@saint-elmos-fire.mit.edu" source="BUGTRAQ">20000614 Security Advisory: REMOTE ROOT VULNERABILITY IN GSSFTP DAEMON</ref>
      <ref url="http://www.securityfocus.com/bid/1374" source="BID">1374</ref>
      <ref url="http://www.osvdb.org/4885" source="OSVDB">4885</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="5_1.1" />
        <vers num="5_1.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0515" published="2000-06-07" name="CVE-2000-0515" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The snmpd.conf configuration file for the SNMP daemon (snmpd) in HP-UX 11.0 is world writable, which allows local users to modify SNMP configuration or gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4643.php" source="XF" patch="1" adv="1">hpux-snmp-daemon</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200006090640.XAA00779@hpchs.cup.hp.com" source="BUGTRAQ">20000608 Re: HP-UX SNMP daemon vulnerability</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200006070511.OAA05492@dogfoot.hackerslab.org" source="BUGTRAQ">20000607 [ Hackerslab bug_paper ] HP-UX SNMP daemon vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/1327" source="BID">1327</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.20" />
        <vers num="11.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0516" published="2000-06-06" name="CVE-2000-0516" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">When configured to store configuration information in an LDAP directory, Shiva Access Manager 5.0.0 stores the root DN (Distinguished Name) name and password in cleartext in a file that is world readable, which allows local users to compromise the LDAP server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0008.html" source="BUGTRAQ" patch="1" adv="1">20000606 Shiva Access Manager 5.0.0 Plaintext LDAP root password.</ref>
      <ref url="http://xforce.iss.net/static/4612.php" source="XF" adv="1">shiva-plaintext-ldap-password</ref>
      <ref url="http://www.securityfocus.com/bid/1329" source="BID">1329</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intel" name="shiva_access_manager">
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":solaris" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0517" published="2000-05-26" name="CVE-2000-0517" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Netscape 4.73 and earlier does not properly warn users about a potentially invalid certificate if the user has previously accepted the certificate for a different web site, which could allow remote attackers to spoof a legitimate web site by compromising that site's DNS information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2000-08.html" source="CERT" patch="1" adv="1">CA-2000-08</ref>
      <ref url="http://xforce.iss.net/static/4550.php" source="XF" patch="1" adv="1">netscape-ssl-certificate</ref>
      <ref url="http://www.securityfocus.com/bid/1260" source="BID" patch="1" adv="1">1260</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="communicator">
        <vers num="4.0" />
        <vers num="4.5" />
        <vers num="4.51" />
        <vers num="4.6" />
        <vers num="4.61" />
        <vers num="4.7" />
        <vers num="4.72" />
        <vers num="4.73" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0518" published="2000-06-05" name="CVE-2000-0518" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Internet Explorer 4.x and 5.x does not properly verify all contents of an SSL certificate if a connection is made to the server via an image or a frame, aka one of two different "SSL Certificate Validation" vulnerabilities.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2000-10.html" source="CERT" patch="1" adv="1">CA-2000-10</ref>
      <ref url="http://xforce.iss.net/static/4624.php" source="XF" patch="1" adv="1">ie-invalid-frame-image-certificate</ref>
      <ref url="http://www.securityfocus.com/bid/1309" source="BID" patch="1" adv="1">1309</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-039.asp" source="MS" patch="1" adv="1">MS00-039</ref>
      <ref url="http://www.acrossecurity.com/aspr/ASPR-1999-12-15-1-PUB.txt" source="MISC">http://www.acrossecurity.com/aspr/ASPR-1999-12-15-1-PUB.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":windows_nt" />
        <vers num="4.0" edition=":windows_98" />
        <vers num="4.0.1" edition="" />
        <vers num="4.0.1" edition=":windows_95" />
        <vers num="4.0.1" edition=":windows_98" />
        <vers num="4.0.1" edition=":windows_nt" />
        <vers num="5" edition="" />
        <vers num="5" edition=":windows_nt_4.0" />
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":windows_95" />
        <vers num="5.0" edition=":windows_98" />
        <vers num="5.0" edition=":windows_2000" />
        <vers num="5.0.1" edition="" />
        <vers num="5.0.1" edition=":windows_95" />
        <vers num="5.0.1" edition=":windows_nt_4.0" />
        <vers num="5.0.1" edition=":windows_2000" />
        <vers num="5.0.1" edition=":windows_98" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0519" published="2000-06-05" name="CVE-2000-0519" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Internet Explorer 4.x and 5.x does not properly re-validate an SSL certificate if the user establishes a new SSL session with the same server during the same Internet Explorer session, aka one of two different "SSL Certificate Validation" vulnerabilities.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2000-10.html" source="CERT" patch="1" adv="1">CA-2000-10</ref>
      <ref url="http://xforce.iss.net/static/4627.php" source="XF" patch="1" adv="1">ie-revalidate-certificate</ref>
      <ref url="http://www.securityfocus.com/bid/1309" source="BID" patch="1" adv="1">1309</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-039.asp" source="MS" patch="1" adv="1">MS00-039</ref>
      <ref url="http://www.acrossecurity.com/aspr/ASPR-1999-12-15-1-PUB.txt" source="MISC">http://www.acrossecurity.com/aspr/ASPR-1999-12-15-1-PUB.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":windows_nt" />
        <vers num="4.0" edition=":windows_98" />
        <vers num="4.0.1" edition="" />
        <vers num="4.0.1" edition=":windows_95" />
        <vers num="4.0.1" edition=":windows_98" />
        <vers num="4.0.1" edition=":windows_nt" />
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":windows_nt_4.0" />
        <vers num="5.0" edition=":windows_95" />
        <vers num="5.0" edition=":windows_98" />
        <vers num="5.0" edition=":windows_2000" />
        <vers num="5.0.1" edition="" />
        <vers num="5.0.1" edition=":windows_95" />
        <vers num="5.0.1" edition=":windows_nt_4.0" />
        <vers num="5.0.1" edition=":windows_2000" />
        <vers num="5.0.1" edition=":windows_98" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0520" published="2000-06-07" name="CVE-2000-0520" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in restore program 0.4b17 and earlier in dump package allows local users to execute arbitrary commands via a long tape name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1330" source="BID" patch="1" adv="1">1330</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=11880" source="MISC" patch="1" adv="1">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=11880</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96240393814071&amp;w=2" source="BUGTRAQ">20000630 CONECTIVA LINUX SECURITY ANNOUNCEMENT - dump</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stelian" name="pop_dump">
        <vers num="0.4b15.1" />
        <vers num="0.4b15.30" />
        <vers num="0.4b16.0" />
        <vers num="0.4b17.0" />
        <vers num="0.4b9.0" />
        <vers num="0.4b9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0521" published="2000-06-05" name="CVE-2000-0521" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Savant web server allows remote attackers to read source code of CGI scripts via a GET request that does not include the HTTP version number.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1313" source="BID" patch="1" adv="1">1313</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0469.html" source="BUGTRAQ" patch="1" adv="1">20000605 MDMA Advisory #5: Reading of CGI Scripts under Savant Webserver</ref>
      <ref url="http://xforce.iss.net/static/4616.php" source="XF" adv="1">savant-source-read</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michael_lamont" name="savant_webserver">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0522" published="2000-06-08" name="CVE-2000-0522" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">RSA ACE/Server allows remote attackers to cause a denial of service by flooding the server's authentication request port with UDP packets, which causes the server to crash.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5053.php" source="XF" patch="1" adv="1">aceserver-udp-packet-dos</ref>
      <ref url="http://www.securityfocus.com/bid/1332" source="BID" patch="1" adv="1">1332</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0197.html" source="BUGTRAQ" patch="1" adv="1">20000714 Re: RSA Aceserver UDP Flood Vulnerability</ref>
      <ref url="ftp://ftp.securid.com/support/outgoing/dos/readme.txt" source="CONFIRM" patch="1" adv="1">ftp://ftp.securid.com/support/outgoing/dos/readme.txt</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=011a01bfd14c$3c206960$050010ac@xtranet.co.uk" source="BUGTRAQ">20000608 Potential DoS Attack on RSA's ACE/Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rsa" name="ace_server">
        <vers num="3.1" />
        <vers num="3.3" />
        <vers num="3.3.1" />
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0523" published="2000-06-06" name="CVE-2000-0523" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the logging feature of EServ 2.9.2 and earlier allows an attacker to execute arbitrary commands via a long MKD command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4614.php" source="XF" adv="1">eserv-logging-overflow</ref>
      <ref url="http://www.securityfocus.com/bid/1315" source="BID" adv="1">1315</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0009.html" source="BUGTRAQ" adv="1">20000606 MDMA Advisory #6: EServ Logging Heap Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="etype" name="eserv">
        <vers num="2.9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0524" published="2000-06-05" name="CVE-2000-0524" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Outlook and Outlook Express allow remote attackers to cause a denial of service by sending email messages with blank fields such as BCC, Reply-To, Return-Path, or From.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1333" source="BID" adv="1">1333</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0045.html" source="BUGTRAQ" adv="1">20000604 Microsoft Outlook (Express) bug..</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
      <prod vendor="microsoft" name="outlook">
        <vers num="97" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0525" published="2000-06-08" name="CVE-2000-0525" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">OpenSSH does not properly drop privileges when the UseLogin option is enabled, which allows local users to execute arbitrary commands by providing the command to the ssh daemon.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4646.php" source="XF" patch="1" adv="1">openssh-uselogin-remote-exec</ref>
      <ref url="http://www.securityfocus.com/bid/1334" source="BID">1334</ref>
      <ref url="http://www.osvdb.org/341" source="OSVDB">341</ref>
      <ref url="http://www.openbsd.org/errata.html#uselogin" source="OPENBSD">20000606 The non-default UseLogin feature in /etc/sshd_config is broken and should not be used.</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0065.html" source="BUGTRAQ">20000609 OpenSSH's UseLogin option allows remote access with root privilege.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openssh">
        <vers num="1.2" />
        <vers num="1.2.3" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0526" published="2000-06-09" name="CVE-2000-0526" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">mailview.cgi CGI program in MailStudio 2000 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1335" source="BID" adv="1">1335</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0081.html" source="BUGTRAQ" adv="1">20000609 Mailstudio2000 CGI Vulnerabilities [S0ftPj.4]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="3r_soft" name="mailstudio_2000">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0527" published="2000-06-09" name="CVE-2000-0527" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">userreg.cgi CGI program in MailStudio 2000 2.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1335" source="BID" adv="1">1335</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0081.html" source="BUGTRAQ">20000609 Mailstudio2000 CGI Vulnerabilities [S0ftPj.4]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="3r_soft" name="mailstudio_2000">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0528" published="2000-06-19" name="CVE-2000-0528" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Net Tools PKI Server does not properly restrict access to remote attackers when the XUDA template files do not contain absolute pathnames for other files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4743.php" source="XF" patch="1" adv="1">nettools-pki-unauthenticated-access</ref>
      <ref url="http://www.securityfocus.com/bid/1364" source="BID" patch="1" adv="1">1364</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0166.html" source="BUGTRAQ" patch="1" adv="1">20000619 Net Tools PKI server exploits</ref>
      <ref url="ftp://ftp.tis.com/gauntlet/hide/pki/hotfix.txt" source="CONFIRM">ftp://ftp.tis.com/gauntlet/hide/pki/hotfix.txt</ref>
      <ref url="http://www.osvdb.org/4353" source="OSVDB">4353</ref>
    </refs>
    <vuln_soft>
      <prod vendor="network_associates" name="net_tools_pki_server">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0529" published="2000-06-19" name="CVE-2000-0529" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Net Tools PKI Server allows remote attackers to cause a denial of service via a long HTTP request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4744.php" source="XF" patch="1" adv="1">nettools-pki-http-bo</ref>
      <ref url="http://www.securityfocus.com/bid/1363" source="BID" patch="1" adv="1">1363</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0166.html" source="BUGTRAQ" patch="1" adv="1">20000619 Net Tools PKI server exploits</ref>
      <ref url="ftp://ftp.tis.com/gauntlet/hide/pki/hotfix.txt" source="CONFIRM">ftp://ftp.tis.com/gauntlet/hide/pki/hotfix.txt</ref>
      <ref url="http://www.osvdb.org/4352" source="OSVDB">4352</ref>
    </refs>
    <vuln_soft>
      <prod vendor="network_associates" name="net_tools_pki_server">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0530" published="2000-05-31" name="CVE-2000-0530" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The KApplication class in the KDE 1.1.2 configuration file management capability allows local users to overwrite arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4583.php" source="XF" patch="1" adv="1">kde-configuration-file-creation</ref>
      <ref url="http://www.securityfocus.com/bid/1291" source="BID" patch="1" adv="1">1291</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0387.html" source="BUGTRAQ" patch="1" adv="1">20000531 KDE::KApplication feature?</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-032.html" source="REDHAT">RHSA-2000:032</ref>
      <ref url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-2000-015.0.txt" source="CALDERA">CSSA-2000-015.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="caldera" name="openlinux">
        <vers num="2.4" />
      </prod>
      <prod vendor="kde" name="kde">
        <vers num="1.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0531" published="1999-11-23" name="CVE-2000-0531" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Linux gpm program allows local users to cause a denial of service by flooding the /dev/gpmctl device with STREAM sockets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5010.php" source="XF" patch="1" adv="1">linux-gpm-gpmctl-dos</ref>
      <ref url="http://www.securityfocus.com/bid/1377" source="BID" patch="1" adv="1">1377</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.10.10006201453090.1812-200000@apollo.aci.com.pl" source="BUGTRAQ" adv="1">20000620 Bug in gpm</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-045.html" source="REDHAT">RHSA-2000:045</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0409.html" source="BUGTRAQ">20000728 MDKSA:2000-025 gpm update</ref>
    </refs>
    <vuln_soft>
      <prod vendor="caldera" name="openlinux">
        <vers num="2.3" />
        <vers num="2.4" />
      </prod>
      <prod vendor="caldera" name="openlinux_eserver">
        <vers num="2.3" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":i386" />
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0532" published="2000-06-07" name="CVE-2000-0532" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">A FreeBSD patch for SSH on 2000-01-14 configures ssh to listen on port 722 as well as port 22, which might allow remote attackers to access SSH through port 722 even if port 22 is otherwise filtered.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4638.php" source="XF" patch="1" adv="1">freebsd-ssh-ports</ref>
      <ref url="http://www.securityfocus.com/bid/1323" source="BID" patch="1" adv="1">1323</ref>
      <ref url="http://archives.neohapsis.com/archives/freebsd/2000-06/0031.html" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-00:21</ref>
      <ref url="http://www.osvdb.org/1387" source="OSVDB">1387</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0533" published="2000-06-20" name="CVE-2000-0533" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in cvconnect in SGI IRIX WorkShop allows local users to overwrite arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4725.php" source="XF" patch="1" adv="1">irix-workshop-cvconnect-overwrite</ref>
      <ref url="http://www.securityfocus.com/bid/1379" source="BID" patch="1" adv="1">1379</ref>
      <ref url="ftp://sgigate.sgi.com/security/20000601-01-P" source="SGI">20000601-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="workshop_debugger_and_performance_tools">
        <vers num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0534" published="2000-06-07" name="CVE-2000-0534" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The apsfilter software in the FreeBSD ports package does not properly read user filter configurations, which allows local users to execute commands as the lpd user.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1325" source="BID" patch="1" adv="1">1325</ref>
      <ref url="http://xforce.iss.net/static/4617.php" source="XF">apsfilter-elevate-privileges</ref>
      <ref url="http://www.osvdb.org/1389" source="OSVDB">1389</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aps_filter_development_team" name="apsfilter">
        <vers num="5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0535" published="2000-06-12" name="CVE-2000-0535" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">OpenSSL 0.9.4 and OpenSSH for FreeBSD do not properly check for the existence of the /dev/random or /dev/urandom devices, which are absent on FreeBSD Alpha systems, which causes them to produce weak keys which may be more easily broken.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1340" source="BID" patch="1" adv="1">1340</ref>
      <ref url="http://archives.neohapsis.com/archives/freebsd/2000-06/0083.html" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-00:25</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openssl" name="openssl">
        <vers num="0.9.4" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.0" edition="alpha" />
        <vers num="5.0" edition="alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0536" published="2000-06-04" name="CVE-2000-0536" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">xinetd 2.1.8.x does not properly restrict connections if hostnames are used for access control and the connecting host does not have a reverse DNS entry.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4986.php" source="XF" patch="1" adv="1">xinetd-improper-restrictions</ref>
      <ref url="http://www.synack.net/xinetd/" source="CONFIRM" patch="1" adv="1">http://www.synack.net/xinetd/</ref>
      <ref url="http://www.securityfocus.com/bid/1381" source="BID" patch="1" adv="1">1381</ref>
      <ref url="http://www.debian.org/security/2000/20000619" source="DEBIAN">20000619 xinetd: bug in access control mechanism</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xinetd" name="xinetd">
        <vers num="2.1.87" />
        <vers num="2.1.88" />
        <vers num="2.1.88_pre1" />
        <vers num="2.1.88_pre2" />
        <vers num="2.1.89_pre1" />
        <vers num="2.1.89_pre2" />
        <vers num="2.1.89_pre3" />
        <vers num="2.1.89_pre4" />
        <vers num="2.1.89_pre5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0537" published="2000-06-05" name="CVE-2000-0537" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">BRU backup software allows local users to append data to arbitrary files by specifying an alternate configuration file with the BRUEXECLOG environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4644.php" source="XF" patch="1" adv="1">bru-execlog-env-variable</ref>
      <ref url="http://www.securityfocus.com/bid/1321" source="BID" patch="1" adv="1">1321</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0013.html" source="BUGTRAQ" adv="1">20000606 BRU Vulnerability</ref>
      <ref url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-018.0.txt" source="CALDERA">CSSA-2000-018.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tolis_group" name="bru">
        <vers num="15.1" />
        <vers num="16.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0538" published="2000-06-07" name="CVE-2000-0538" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ColdFusion Administrator for ColdFusion 4.5.1 and earlier allows remote attackers to cause a denial of service via a long login password.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4611.php" source="XF" patch="1" adv="1">coldfusion-parse-dos</ref>
      <ref url="http://www.securityfocus.com/bid/1314" source="BID" patch="1" adv="1">1314</ref>
      <ref url="http://www.allaire.com/handlers/index.cfm?ID=16122&amp;Method=Full" source="ALLAIRE" patch="1" adv="1">ASB00-14</ref>
      <ref url="http://www.osvdb.org/3399" source="OSVDB">3399</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96045469627806&amp;w=2" source="BUGTRAQ">20000607 New Allaire ColdFusion DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="allaire" name="coldfusion_server">
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="3.01" />
        <vers num="3.1" />
        <vers num="3.11" />
        <vers num="3.12" />
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="4.5" />
        <vers num="4.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0539" published="2000-06-22" name="CVE-2000-0539" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Servlet examples in Allaire JRun 2.3.x allow remote attackers to obtain sensitive information, e.g. listing HttpSession ID's via the SessionServlet servlet.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4774.php" source="XF" patch="1" adv="1">jrun-read-sample-files</ref>
      <ref url="http://www.securityfocus.com/bid/1386" source="BID" patch="1" adv="1">1386</ref>
      <ref url="http://www.allaire.com/handlers/index.cfm?ID=16290&amp;Method=Full" source="ALLAIRE" patch="1" adv="1">ASB00-015</ref>
      <ref url="http://www.osvdb.org/818" source="OSVDB">818</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macromedia" name="jrun">
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0540" published="2000-06-22" name="CVE-2000-0540" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">JSP sample files in Allaire JRun 2.3.x allow remote attackers to access arbitrary files (e.g. via viewsource.jsp) or obtain configuration information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4774.php" source="XF" patch="1" adv="1">jrun-read-sample-files</ref>
      <ref url="http://www.securityfocus.com/bid/1386" source="BID" patch="1" adv="1">1386</ref>
      <ref url="http://www.allaire.com/handlers/index.cfm?ID=16290&amp;Method=Full" source="ALLAIRE" patch="1" adv="1">ASB00-015</ref>
      <ref url="http://www.osvdb.org/2713" source="OSVDB">2713</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macromedia" name="jrun">
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0541" published="2000-06-17" name="CVE-2000-0541" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The Panda Antivirus console on port 2001 allows local users to execute arbitrary commands without authentication via the CMD command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1359" source="BID" patch="1" adv="1">1359</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0164.html" source="BUGTRAQ" patch="1" adv="1">20000617 Infosec.20000617.panda.a</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/4707" source="XF">panda-antivirus-remote-admin(4707)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="panda" name="panda_antivirus">
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":netware" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0542" published="2000-06-13" name="CVE-2000-0542" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Tigris remote access server before 11.5.4.22 does not properly record Radius accounting information when a user fails the initial login authentication but subsequently succeeds.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4705.php" source="XF" patch="1" adv="1">tigris-radius-login-failure</ref>
      <ref url="http://www.securityfocus.com/bid/1345" source="BID" patch="1" adv="1">1345</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0104.html" source="BUGTRAQ" adv="1">20000612 ACC/Ericsson Tigris Accounting Failure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ericsson" name="axc_tigris_multiservice_access_platform">
        <vers num="623.0" />
        <vers num="627.0" />
        <vers num="711.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0543" published="2000-06-14" name="CVE-2000-0543" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The command port for PGP Certificate Server 2.5.0 and 2.5.1 allows remote attackers to cause a denial of service if their hostname does not have a reverse DNS entry and they connect to port 4000.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4695.php" source="XF" patch="1" adv="1">pgp-cert-server-dos</ref>
      <ref url="http://www.securityfocus.com/bid/1343" source="BID" patch="1" adv="1">1343</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0107.html" source="BUGTRAQ" patch="1" adv="1">20000614 Remote DoS attack in Networks Associates PGP Certificate Server Version 2.5 Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pgp" name="certificate_server">
        <vers num="2.5" />
        <vers num="2.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0544" published="2000-06-05" name="CVE-2000-0544" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Windows NT and Windows 2000 hosts allow a remote attacker to cause a denial of service via malformed DCE/RPC SMBwriteX requests that contain an invalid data length.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1304" source="BID" adv="1">1304</ref>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0231.html" source="NTBUGTRAQ" adv="1">20000604 anonymous SMBwriteX DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0545" published="2000-08-08" name="CVE-2000-0545" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in mailx mail command (aka Mail) on Linux systems allows local users to gain privileges via a long -c (carbon copy) parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1305" source="BID">1305</ref>
      <ref url="http://www.debian.org/security/2000/20000605" source="DEBIAN">20000605 mailx: mail group exploit in mailx</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0435.html" source="BUGTRAQ" adv="1">20000602 /usr/bin/Mail exploit for Slackware 7.0 (mail-slack.c)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="mailx">
        <vers num="3" />
        <vers num="4" />
        <vers num="5" />
        <vers num="6.0.1" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
        <vers num="6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0546" published="2000-06-09" name="CVE-2000-0546" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the lastrealm variable in the set_tgtkey function.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2000-11.html" source="CERT" patch="1" adv="1">CA-2000-11</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0064.html" source="BUGTRAQ" patch="1" adv="1">20000609 Security Advisory: MULTIPLE DENIAL OF SERVICE VULNERABILITIES IN KRB4 KDC</ref>
      <ref url="http://www.securityfocus.com/bid/1338" source="BID">1338</ref>
      <ref url="http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt" source="CONFIRM">http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/k-051.shtml" source="CIAC">K-051</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cygnus" name="cygnus_network_security">
        <vers num="" />
      </prod>
      <prod vendor="cygnus" name="kerbnet">
        <vers num="" />
      </prod>
      <prod vendor="mit" name="kerberos">
        <vers prev="1" num="4.0" />
        <vers num="5_1.0" />
        <vers num="5_1.1" />
        <vers num="5_1.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0547" published="2000-06-09" name="CVE-2000-0547" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the localrealm variable in the process_v4 function.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2000-11.html" source="CERT" patch="1" adv="1">CA-2000-11</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0064.html" source="BUGTRAQ" patch="1" adv="1">20000609 Security Advisory: MULTIPLE DENIAL OF SERVICE VULNERABILITIES IN KRB4 KDC</ref>
      <ref url="http://www.securityfocus.com/bid/1338" source="BID">1338</ref>
      <ref url="http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt" source="CONFIRM">http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/k-051.shtml" source="CIAC">K-051</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cygnus" name="cygnus_network_security">
        <vers num="" />
      </prod>
      <prod vendor="cygnus" name="kerbnet">
        <vers num="" />
      </prod>
      <prod vendor="mit" name="kerberos">
        <vers prev="1" num="4.0" />
        <vers num="5_1.0" />
        <vers num="5_1.1" />
        <vers num="5_1.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0548" published="2000-06-09" name="CVE-2000-0548" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the e_msg variable in the kerb_err_reply function.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2000-11.html" source="CERT" patch="1" adv="1">CA-2000-11</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0064.html" source="BUGTRAQ" patch="1" adv="1">20000609 Security Advisory: MULTIPLE DENIAL OF SERVICE VULNERABILITIES IN KRB4 KDC</ref>
      <ref url="http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt" source="CONFIRM">http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-031.html" source="REDHAT">RHSA-2000:031</ref>
      <ref url="http://www.osvdb.org/4875" source="OSVDB">4875</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/k-051.shtml" source="CIAC">K-051</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cygnus" name="cygnus_network_security">
        <vers num="" />
      </prod>
      <prod vendor="cygnus" name="kerbnet">
        <vers num="" />
      </prod>
      <prod vendor="mit" name="kerberos">
        <vers prev="1" num="4.0" />
        <vers num="5_1.0" />
        <vers num="5_1.1" />
        <vers num="5_1.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0549" published="2000-06-09" name="CVE-2000-0549" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Kerberos 4 KDC program does not properly check for null termination of AUTH_MSG_KDC_REQUEST requests, which allows remote attackers to cause a denial of service via a malformed request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2000-11.html" source="CERT" patch="1" adv="1">CA-2000-11</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0064.html" source="BUGTRAQ" patch="1" adv="1">20000609 Security Advisory: MULTIPLE DENIAL OF SERVICE VULNERABILITIES IN KRB4 KDC</ref>
      <ref url="http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt" source="CONFIRM">http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-031.html" source="REDHAT">RHSA-2000:031</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/k-051.shtml" source="CIAC">K-051</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cygnus" name="cygnus_network_security">
        <vers num="4.0" />
      </prod>
      <prod vendor="cygnus" name="kerbnet">
        <vers num="5.0" />
      </prod>
      <prod vendor="mit" name="kerberos">
        <vers num="4.0" />
        <vers num="5-1.1" />
        <vers num="5_1.0" />
        <vers num="5_1.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0550" published="2000-06-09" name="CVE-2000-0550" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Kerberos 4 KDC program improperly frees memory twice (aka "double-free"), which allows remote attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2000-11.html" source="CERT" patch="1" adv="1">CA-2000-11</ref>
      <ref url="http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt" source="CONFIRM">http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt</ref>
      <ref url="http://www.securityfocus.com/bid/1465" source="BID">1465</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-031.html" source="REDHAT">RHSA-2000:031</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/k-051.shtml" source="CIAC">K-051</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0064.html" source="BUGTRAQ">20000609 Security Advisory: MULTIPLE DENIAL OF SERVICE VULNERABILITIES IN KRB4 KDC</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cygnus" name="cygnus_network_security">
        <vers num="4.0" />
      </prod>
      <prod vendor="cygnus" name="kerbnet">
        <vers num="5.0" />
      </prod>
      <prod vendor="mit" name="kerberos">
        <vers num="4.0" />
        <vers num="5-1.1" />
        <vers num="5_1.0" />
        <vers num="5_1.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0551" published="2000-05-23" name="CVE-2000-0551" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The file transfer mechanism in Danware NetOp 6.0 does not provide authentication, which allows remote attackers to access and modify arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4569.php" source="XF" patch="1" adv="1">danware-netop-bypass-security(4569)</ref>
      <ref url="http://www.securityfocus.com/bid/1263" source="BID" patch="1" adv="1">1263</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0339.html" source="BUGTRAQ" adv="1">20000523 I think</ref>
    </refs>
    <vuln_soft>
      <prod vendor="danware_data" name="netop">
        <vers num="6.0" />
        <vers num="6.50" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0552" published="2000-06-06" name="CVE-2000-0552" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">ICQwebmail client for ICQ 2000A creates a world readable temporary file during login and does not delete it, which allows local users to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1307" source="BID" patch="1" adv="1">1307</ref>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0237.html" source="NTBUGTRAQ" patch="1" adv="1">20000606 ICQ2000A ICQmail temparary internet link vulnearbility</ref>
      <ref url="http://xforce.iss.net/static/4607.php" source="XF" adv="1">icq-temp-link</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mirabilis" name="icq">
        <vers num="2000.0a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0553" published="2000-05-26" name="CVE-2000-0553" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Race condition in IPFilter firewall 3.4.3 and earlier, when configured with overlapping "return-rst" and "keep state" rules, allows remote attackers to bypass access restrictions.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1308" source="BID" patch="1" adv="1">1308</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0326.html" source="BUGTRAQ" patch="1" adv="1">20000525 Security Vulnerability in IPFilter 3.3.15 and 3.4.3</ref>
      <ref url="http://xforce.iss.net/static/4994.php" source="XF">ipfilter-firewall-race-condition</ref>
      <ref url="http://www.osvdb.org/1377" source="OSVDB">1377</ref>
    </refs>
    <vuln_soft>
      <prod vendor="darren_reed" name="ipfilter">
        <vers num="3.3.15" />
        <vers num="3.4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0554" published="2000-06-08" name="CVE-2000-0554" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Ceilidh allows remote attackers to obtain the real path of the Ceilidh directory via the translated_path hidden form field.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0246.html" source="NTBUGTRAQ" patch="1" adv="1">20000608 DST2K0010: DoS &amp; Path Revealing Vulnerability in Ceilidh v2.60a</ref>
      <ref url="http://www.securityfocus.com/bid/1320" source="BID" adv="1">1320</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lilikoi" name="ceilidh">
        <vers num="2.60" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0555" published="2000-06-09" name="CVE-2000-0555" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Ceilidh allows remote attackers to cause a denial of service via a large number of POST requests.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0246.html" source="NTBUGTRAQ" patch="1" adv="1">20000608 DST2K0010: DoS &amp; Path Revealing Vulnerability in Ceilidh v2.60a</ref>
      <ref url="http://xforce.iss.net/static/4622.php" source="XF" adv="1">ceilidh-post-dos</ref>
      <ref url="http://www.securityfocus.com/bid/1320" source="BID" adv="1">1320</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lilikoi" name="ceilidh">
        <vers num="2.60" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0556" published="2000-06-05" name="CVE-2000-0556" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in the web interface for Cmail 2.4.7 allows remote attackers to cause a denial of service by sending a large user name to the user dialog running on port 8002.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4625.php" source="XF" patch="1" adv="1">cmail-long-username-dos</ref>
      <ref url="http://www.securityfocus.com/bid/1319" source="BID" patch="1" adv="1">1319</ref>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0248.html" source="NTBUGTRAQ" patch="1" adv="1">20000608 DST2K0011: DoS &amp; BufferOverrun in CMail v2.4.7 WebMail</ref>
      <ref url="http://www.computalynx.net/news/Jun2000/news0806200001.html" source="CONFIRM">http://www.computalynx.net/news/Jun2000/news0806200001.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="computalynx" name="cmail">
        <vers num="2.4.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0557" published="2000-06-05" name="CVE-2000-0557" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the web interface for Cmail 2.4.7 allows remote attackers to execute arbitrary commands via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4626.php" source="XF" patch="1" adv="1">cmail-get-overflow-execute</ref>
      <ref url="http://www.securityfocus.com/bid/1318" source="BID" patch="1" adv="1">1318</ref>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0248.html" source="NTBUGTRAQ" patch="1" adv="1">20000608 DST2K0011: DoS &amp; BufferOverrun in CMail v2.4.7 WebMail</ref>
    </refs>
    <vuln_soft>
      <prod vendor="computalynx" name="cmail">
        <vers num="2.4.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0558" published="2000-06-06" name="CVE-2000-0558" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in HP Openview Network Node Manager 6.1 allows remote attackers to execute arbitrary commands via the Alarm service (OVALARMSRV) on port 2345.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1317" source="BID" adv="1">1317</ref>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0249.html" source="NTBUGTRAQ" adv="1">20000608 DST2K0012: BufferOverrun in HP Openview Network Node Manager v6.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0559" published="2000-06-07" name="CVE-2000-0559" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">eTrust Intrusion Detection System (formerly SessionWall-3) uses weak encryption (XOR) to store administrative passwords in the registry, which allows local users to easily decrypt the passwords.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1341" source="BID" patch="1" adv="1">1341</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.BSO.4.21.0006072124320.28062-100000@bearclaw.bogus.net" source="BUGTRAQ">20000607 SessionWall-3 Paper + (links to) code</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="etrust_intrusion_detection">
        <vers prev="1" num="1.4.1.13" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0561" published="2000-06-19" name="CVE-2000-0561" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in WebBBS 1.15 allows remote attackers to execute arbitrary commands via a long HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4742.php" source="XF" patch="1" adv="1">webbbs-get-request-overflow</ref>
      <ref url="http://www.securityfocus.com/bid/1365" source="BID" patch="1" adv="1">1365</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0175.html" source="BUGTRAQ" patch="1" adv="1">20000620 DST2K0018: Multiple BufferOverruns in WebBBS HTTP Server v1.15</ref>
      <ref url="http://www.osvdb.org/3544" source="OSVDB">3544</ref>
    </refs>
    <vuln_soft>
      <prod vendor="international_telecommunications" name="international_telecommunications_webbbs">
        <vers num="1.1.5" />
        <vers num="1.17" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0562" published="2000-06-22" name="CVE-2000-0562" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">BlackIce Defender 2.1 and earlier, and BlackIce Pro 2.0.23 and earlier, do not properly block Back Orifice traffic when the security setting is Nervous or lower.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0190.html" source="BUGTRAQ" patch="1" adv="1">20000620 BlackICE by Network ICE Corp vulnerability against Back Orifice 1.2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iss" name="blackice_agent">
        <vers prev="1" num="2.0.23" />
      </prod>
      <prod vendor="iss" name="blackice_defender">
        <vers prev="1" num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0563" published="2000-10-20" name="CVE-2000-0563" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The URLConnection function in MacOS Runtime Java (MRJ) 2.1 and earlier and the Microsoft virtual machine (VM) for MacOS allows a malicious web site operator to connect to arbitrary hosts using a HTTP redirection, in violation of the Java security model.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0056.html" source="BUGTRAQ" patch="1" adv="1">20000609 Security Holes Found in URLConnection of MRJ and IE of Mac OS (was Re: Reappearance of an old IE security bug)</ref>
      <ref url="http://www.securityfocus.com/bid/1336" source="BID">1336</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-05-8&amp;msg=391C95DE2DA.5E3BTAKAGI@java-house.etl.go.jp" source="BUGTRAQ">20000513 Re: Reappearance of an old IE security bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_runtime_for_java">
        <vers prev="1" num="2.1" edition="" />
        <vers prev="1" num="2.1" edition=":java" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0564" published="2000-05-29" name="CVE-2000-0564" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The guestbook CGI program in ICQ Web Front service for ICQ 2000a, 99b, and others allows remote attackers to cause a denial of service via a URL with a long name parameter.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0218.html" source="NTBUGTRAQ" patch="1" adv="1">20000529 ICQ Web Front Remote DoS Attack Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mirabilis" name="icq">
        <vers num="0.99b_1.1.1.1" />
        <vers num="0.99b_v.3.19" />
        <vers num="2000.0a" />
        <vers num="98.0a" />
        <vers num="99a_2.15build1701" />
        <vers num="99a_2.21build1800" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0565" published="2000-06-13" name="CVE-2000-0565" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">SmartFTP Daemon 0.2 allows a local user to access arbitrary files by uploading and specifying an alternate user configuration file via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4706.php" source="XF" patch="1" adv="1">smartftp-directory-traversal</ref>
      <ref url="http://www.securityfocus.com/bid/1344" source="BID" patch="1" adv="1">1344</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0100.html" source="BUGTRAQ" patch="1" adv="1">20000613 SmartFTP Daemon v0.2 Beta Build 9 - Remote Exploit</ref>
      <ref url="http://www.osvdb.org/1394" source="OSVDB">1394</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mindstorm" name="smartftp_daemon">
        <vers num="0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0566" published="2000-07-03" name="CVE-2000-0566" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">makewhatis in Linux man package allows local users to overwrite files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4900.php" source="XF" patch="1" adv="1">linux-man-makewhatis-tmp</ref>
      <ref url="http://www.securityfocus.com/bid/1434" source="BID">1434</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-041.html" source="REDHAT">RHSA-2000:041</ref>
      <ref url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2000:015" source="MANDRAKE">MDKSA-2000:015</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0390.html" source="BUGTRAQ">20000727 CONECTIVA LINUX SECURITY ANNOUNCEMENT - MAN</ref>
      <ref url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2000-021.0.txt" source="CALDERA">CSSA-2000-021.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="caldera" name="openlinux">
        <vers num="2.3" />
        <vers num="2.4" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="7.0" />
        <vers num="7.1" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="5.2" edition="" />
        <vers num="5.2" edition=":sparc" />
        <vers num="5.2" edition=":i386" />
        <vers num="5.2" edition=":alpha" />
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":i386" />
        <vers num="6.0" edition=":alpha" />
        <vers num="6.0" edition=":sparc" />
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":i386" />
        <vers num="6.1" edition=":alpha" />
        <vers num="6.1" edition=":sparc" />
        <vers num="6.2" edition="" />
        <vers num="6.2" edition=":alpha" />
        <vers num="6.2" edition=":sparc" />
        <vers num="6.2" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0567" published="2000-07-18" name="CVE-2000-0567" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Outlook and Outlook Express allows remote attackers to execute arbitrary commands via a long Date field in an email header, aka the "Malformed E-mail Header" vulnerability.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4953.php" source="XF">outlook-date-overflow</ref>
      <ref url="http://www.securityfocus.com/bid/1481" source="BID">1481</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-043.mspx" source="MS">MS00-043</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="outlook">
        <vers num="2000" />
        <vers num="97" />
        <vers num="98" />
      </prod>
      <prod vendor="microsoft" name="outlook_express">
        <vers num="4.0" />
        <vers num="4.01" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0568" published="2000-06-30" name="CVE-2000-0568" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sybergen Secure Desktop 2.1 does not properly protect against false router advertisements (ICMP type 9), which allows remote attackers to modify default routes.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=4125690E.00524395.00@guardianit.se" source="BUGTRAQ" adv="1">20000630 Multiple vulnerabilities in Sybergen Secure Desktop</ref>
      <ref url="http://www.securityfocus.com/bid/1417" source="BID">1417</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sybergen" name="secure_desktop">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0569" published="2000-06-30" name="CVE-2000-0569" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sybergen Sygate allows remote attackers to cause a denial of service by sending a malformed DNS UDP packet to its internal interface.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1420" source="BID" patch="1" adv="1">1420</ref>
      <ref url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q2/0189.html" source="WIN2KSEC" patch="1" adv="1">20000630 Any LAN user can crash Sygate</ref>
      <ref url="http://xforce.iss.net/static/5049.php" source="XF" adv="1">sygate-udp-packet-dos(5049)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sybergen" name="sygate">
        <vers num="2.0" />
        <vers num="3.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0570" published="2000-06-27" name="CVE-2000-0570" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">FirstClass Internet Services server 5.770, and other versions before 6.1, allows remote attackers to cause a denial of service by sending an email with a long To: mail header.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4843.php" source="XF" adv="1">firstclass-large-bcc-dos(4843)</ref>
      <ref url="http://www.securityfocus.com/bid/1421" source="BID" adv="1">1421</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0295.html" source="BUGTRAQ" adv="1">20000627 DoS in FirstClass Internet Services 5.770</ref>
      <ref url="http://www.osvdb.org/5718" source="OSVDB">5718</ref>
    </refs>
    <vuln_soft>
      <prod vendor="centrinity" name="firstclass_intranet_server">
        <vers num="5.770" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0571" published="2000-07-05" name="CVE-2000-0571" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">LocalWEB HTTP server 1.2.0 allows remote attackers to cause a denial of service via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4896.php" source="XF" patch="1" adv="1">localweb-get-bo</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-07-8&amp;msg=NCBBKFKDOLAGKIAPMILPCEIHCFAA.labs@ussrback.com" source="BUGTRAQ" adv="1">20000703 Remote DoS Attack in LocalWEB HTTP Server 1.2.0 Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/1423" source="BID">1423</ref>
    </refs>
    <vuln_soft>
      <prod vendor="west_street_software" name="localweb_http_server">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0572" published="2000-07-05" name="CVE-2000-0572" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The Razor configuration management tool uses weak encryption for its password file, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-07-8&amp;msg=613309F30B6DD2118C020000F809376C05CABD49@emss03m09.orl.lmco.com" source="BUGTRAQ" patch="1" adv="1">20000704 Recovering Passwords in Visible Systems' Razor</ref>
      <ref url="http://www.securityfocus.com/bid/1424" source="BID">1424</ref>
    </refs>
    <vuln_soft>
      <prod vendor="visible_systems" name="razor">
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0573" published="2000-07-07" name="CVE-2000-0573" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remote attackers to execute arbitrary commands via the SITE EXEC command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2000-13.html" source="CERT" patch="1" adv="1">CA-2000-13</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/4773" source="XF">wuftp-format-string-stack-overwrite(4773)</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000623091822.3321.qmail@fiver.freemessage.com" source="BUGTRAQ">20000623 ftpd: the advisory version</ref>
      <ref url="http://www.securityfocus.com/bid/1387" source="BID">1387</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-039.html" source="REDHAT">RHSA-2000:039</ref>
      <ref url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-020.0.txt" source="CALDERA">CSSA-2000-020.0</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96299933720862&amp;w=2" source="BUGTRAQ">20000707 New Released Version of the WuFTPD Sploit</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96179429114160&amp;w=2" source="BUGTRAQ">20000623 WUFTPD 2.6.0 remote root exploit</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96171893218000&amp;w=2" source="BUGTRAQ">20000622 WuFTPD: Providing *remote* root since at least1994</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0017.html" source="BUGTRAQ">20000702 [Security Announce] wu-ftpd update</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0244.html" source="BUGTRAQ">20000723 CONECTIVA LINUX SECURITY ANNOUNCEMENT - WU-FTPD (re-release)</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2000-009.txt.asc" source="NETBSD">NetBSD-SA2000-009</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:29.wu-ftpd.asc.v1.1" source="FREEBSD">FreeBSD-SA-00:29</ref>
      <ref url="ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-2000.02" source="AUSCERT">AA-2000.02</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0574" published="2000-07-07" name="CVE-2000-0574" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">FTP servers such as OpenBSD ftpd, NetBSD ftpd, ProFTPd and Opieftpd do not properly cleanse untrusted format strings that are used in the setproctitle function (sometimes called by set_proc_title), which allows remote attackers to cause a denial of service or execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2000-13.html" source="CERT" patch="1" adv="1">CA-2000-13</ref>
      <ref url="http://www.securityfocus.com/bid/1438" source="BID">1438</ref>
      <ref url="http://www.securityfocus.com/bid/1425" source="BID">1425</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0121.html" source="BUGTRAQ">20000710 opieftpd setproctitle() patches</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0061.html" source="BUGTRAQ">20000706 ftpd and setproctitle()</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0031.html" source="BUGTRAQ">20000705 proftp advisory</ref>
      <ref url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-009.txt.asc" source="NETBSD">NetBSD-SA2000-009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="ftpd">
        <vers num="5.51" />
        <vers num="5.60" />
      </prod>
      <prod vendor="washington_university" name="wu-ftpd">
        <vers num="2.4.2_beta1" edition="" />
        <vers num="2.4.2_beta1" edition=":academ" />
        <vers num="2.4.2_beta18" edition="" />
        <vers num="2.4.2_beta18" edition=":academ" />
        <vers num="2.4.2_beta18_vr10" />
        <vers num="2.4.2_beta18_vr11" />
        <vers num="2.4.2_beta18_vr12" />
        <vers num="2.4.2_beta18_vr13" />
        <vers num="2.4.2_beta18_vr14" />
        <vers num="2.4.2_beta18_vr15" />
        <vers num="2.4.2_beta18_vr4" />
        <vers num="2.4.2_beta18_vr5" />
        <vers num="2.4.2_beta18_vr6" />
        <vers num="2.4.2_beta18_vr7" />
        <vers num="2.4.2_beta18_vr8" />
        <vers num="2.4.2_beta18_vr9" />
        <vers num="2.4.2_vr16" />
        <vers num="2.4.2_vr17" />
        <vers num="2.5" />
        <vers num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0575" published="2000-07-05" name="CVE-2000-0575" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">SSH 1.2.27 with Kerberos authentication support stores Kerberos tickets in a file which is created in the current directory of the user who is logging in, which could allow remote attackers to sniff the ticket cache if the home directory is installed on NFS.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4903.php" source="XF" patch="1" adv="1">ssh-kerberos-tickets-disclosure(4903)</ref>
      <ref url="http://www.securityfocus.com/bid/1426" source="BID" patch="1" adv="1">1426</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96256265914116&amp;w=2" source="BUGTRAQ">20000630 Kerberos security vulnerability in SSH-1.2.27</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ssh" name="ssh">
        <vers num="1.2.27" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0576" published="2000-07-05" name="CVE-2000-0576" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Oracle Web Listener for AIX versions 4.0.7.0.0 and 4.0.8.1.0 allows remote attackers to cause a denial of service via a malformed URL.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1427" source="BID" adv="1">1427</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0027.html" source="BUGTRAQ" adv="1">20000704 Oracle Web Listener for AIX DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="web_listener">
        <vers num="4.0.7" edition="" />
        <vers num="4.0.7" edition=":aix" />
        <vers num="4.0.8" edition="" />
        <vers num="4.0.8" edition=":aix" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0577" published="2000-06-21" name="CVE-2000-0577" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Netscape Professional Services FTP Server 1.3.6 allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.21.0006211351280.23780-100000@nimue.tpi.pl" source="BUGTRAQ" patch="1" adv="1">20000621 Netscape FTP Server - "Professional" as hell :></ref>
      <ref url="http://www.securityfocus.com/bid/1411" source="BID">1411</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0345.html" source="BUGTRAQ">20000629 (forw) Re: Netscape ftp Server (fwd)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="professional_services_ftpserver">
        <vers num="1.3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0578" published="2000-06-21" name="CVE-2000-0578" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">SGI MIPSPro compilers C, C++, F77 and F90 generate temporary files in /tmp with predictable file names, which could allow local users to insert malicious contents into these files as they are being compiled by another user.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1412" source="BID" adv="1">1412</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0204.html" source="BUGTRAQ" adv="1">20000621 Predictability Problems in IRIX Cron and Compilers</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="mipspro_compilers">
        <vers num="7.1" />
        <vers num="7.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0579" published="2000-06-21" name="CVE-2000-0579" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">IRIX crontab creates temporary files with predictable file names and with the umask of the user, which could allow local users to modify another user's crontab file as it is being edited.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1413" source="BID" adv="1">1413</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0204.html" source="BUGTRAQ" adv="1">20000621 Predictability Problems in IRIX Cron and Compilers</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.3" />
        <vers num="6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0580" published="2000-06-30" name="CVE-2000-0580" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Windows 2000 Server allows remote attackers to cause a denial of service by sending a continuous stream of binary zeros to various TCP and UDP ports, which significantly increases the CPU utilization.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.3.96.1000630161935.4619B-100000@fjord.fscinternet.com" source="BUGTRAQ" adv="1">20000630 SecureXpert Advisory [SX-20000620-2]</ref>
      <ref url="http://www.securityfocus.com/bid/1415" source="BID" adv="1">1415</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="2000.0.2195" />
        <vers num="2000.2072" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0581" published="2000-06-30" name="CVE-2000-0581" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Windows 2000 Telnet Server allows remote attackers to cause a denial of service by sending a continuous stream of binary zeros, which causes the server to crash.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.3.96.1000630161841.4619A-100000@fjord.fscinternet.com" source="BUGTRAQ" adv="1">20000630 SecureXpert Advisory [SX-20000620-1]</ref>
      <ref url="http://www.securityfocus.com/bid/1414" source="BID">1414</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="2000.0.2195" />
        <vers num="2000.2031" />
        <vers num="2000.2072" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0582" published="2000-06-30" name="CVE-2000-0582" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Check Point FireWall-1 4.0 and 4.1 allows remote attackers to cause a denial of service by sending a stream of invalid commands (such as binary zeros) to the SMTP Security Server proxy.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.3.96.1000630162106.4619C-100000@fjord.fscinternet.com" source="BUGTRAQ" adv="1">20000630 SecureXpert Advisory [SX-20000620-3]</ref>
      <ref url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#SMTP_Security" source="CONFIRM">http://www.checkpoint.com/techsupport/alerts/list_vun.html#SMTP_Security</ref>
      <ref url="http://www.securityfocus.com/bid/1416" source="BID">1416</ref>
      <ref url="http://www.osvdb.org/1438" source="OSVDB">1438</ref>
    </refs>
    <vuln_soft>
      <prod vendor="checkpoint" name="firewall-1">
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0583" published="2000-06-30" name="CVE-2000-0583" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">vchkpw program in vpopmail before version 4.8 does not properly cleanse an untrusted format string used in a call to syslog, which allows remote attackers to cause a denial of service via a USER or PASS command that contains arbitrary formatting directives.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vpopmail.cx/vpopmail-ChangeLog" source="CONFIRM">http://www.vpopmail.cx/vpopmail-ChangeLog</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=395BD2A8.5D3396A7@secureaustin.com" source="BUGTRAQ" adv="1">20000626 vpopmail-3.4.11 problems</ref>
      <ref url="http://www.securityfocus.com/bid/1418" source="BID">1418</ref>
    </refs>
    <vuln_soft>
      <prod vendor="inter7" name="vpopmail_vchkpw">
        <vers num="4.5" />
        <vers num="4.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0584" published="2000-07-02" name="CVE-2000-0584" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Canna input system allows remote attackers to execute arbitrary commands via an SR_INIT command with a long user name or group name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4912.php" source="XF" patch="1" adv="1">canna-bin-execute-bo</ref>
      <ref url="http://shadowpenguin.backsection.net/advisories/advisory038.html" source="MISC">http://shadowpenguin.backsection.net/advisories/advisory038.html</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:31.canna.asc.v1.1" source="FREEBSD">FreeBSD-SA-00:31</ref>
      <ref url="http://www.securityfocus.com/bid/1445" source="BID">1445</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.1" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0585" published="2000-06-24" name="CVE-2000-0585" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">ISC DHCP client program dhclient allows remote attackers to execute arbitrary commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4772.php" source="XF" patch="1" adv="1">openbsd-isc-dhcp</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0247.html" source="BUGTRAQ" patch="1" adv="1">20000624 Possible root exploit in ISC DHCP client.</ref>
      <ref url="http://www.securityfocus.com/bid/1388" source="BID">1388</ref>
      <ref url="http://www.novell.com/linux/security/advisories/suse_security_announce_56.html" source="SUSE">20000711 Security Hole in dhclient &lt; 2.0</ref>
      <ref url="http://www.debian.org/security/2000/20000628" source="DEBIAN">20000628 dhcp client: remote root exploit in dhcp client </ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0014.html" source="BUGTRAQ">20000702 [Security Announce] dhcp update</ref>
      <ref url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-008.txt.asc" source="NETBSD">NetBSD-SA2000-008</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:34.dhclient.asc" source="FREEBSD">FreeBSD-SA-00:34</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="dhcp_client">
        <vers num="2.0" />
        <vers num="3.0b1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0586" published="2000-06-29" name="CVE-2000-0586" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Dalnet IRC server 4.6.5 allows remote attackers to cause a denial of service or execute arbitrary commands via the SUMMON command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1404" source="BID">1404</ref>
      <ref url="http://archives.neohapsis.com/archives/vuln-dev/2000-q2/1092.html" source="VULN-DEV">20000628 dalnet 4.6.5 remote vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dalnet" name="ircd">
        <vers num="4.6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0587" published="2000-06-26" name="CVE-2000-0587" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The privpath directive in glftpd 1.18 allows remote attackers to bypass access restrictions for directories by using the file name completion capability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.10.10006261041360.31907-200000@twix.thrijswijk.nl" source="BUGTRAQ" patch="1" adv="1">20000626 Glftpd privpath bugs... +fix</ref>
      <ref url="http://www.securityfocus.com/bid/1401" source="BID">1401</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0317.html" source="BUGTRAQ">20000627 Re: Glftpd privpath bugs... +fix</ref>
    </refs>
    <vuln_soft>
      <prod vendor="glftpd" name="glftpd">
        <vers num="1.18" />
        <vers num="1.19" />
        <vers num="1.20" />
        <vers num="1.21b1" />
        <vers num="1.21b2" />
        <vers num="1.21b3" />
        <vers num="1.21b4" />
        <vers num="1.21b5" />
        <vers num="1.21b6" />
        <vers num="1.21b7" />
        <vers num="1.21b8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0588" published="2000-06-26" name="CVE-2000-0588" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SawMill 5.0.21 CGI program allows remote attackers to read the first line of arbitrary files by listing the file in the rfcf parameter, whose contents SawMill attempts to parse as configuration commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0271.html" source="BUGTRAQ" adv="1">20000626 sawmill5.0.21 old path bug &amp; weak hash algorithm</ref>
      <ref url="http://www.securityfocus.com/bid/1402" source="BID">1402</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0080.html" source="BUGTRAQ">20000706 Patch for Flowerfire Sawmill Vulnerabilities Available</ref>
    </refs>
    <vuln_soft>
      <prod vendor="flowerfire" name="sawmill">
        <vers num="5.0.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0589" published="2000-06-26" name="CVE-2000-0589" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SawMill 5.0.21 uses weak encryption to store passwords, which allows attackers to easily decrypt the password and modify the SawMill configuration.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0271.html" source="BUGTRAQ" patch="1" adv="1">20000626 sawmill5.0.21 old path bug &amp; weak hash algorithm</ref>
      <ref url="http://www.securityfocus.com/bid/1403" source="BID">1403</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0080.html" source="BUGTRAQ">20000706 Patch for Flowerfire Sawmill Vulnerabilities Available</ref>
    </refs>
    <vuln_soft>
      <prod vendor="flowerfire" name="sawmill">
        <vers num="5.0.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0590" published="2000-07-04" name="CVE-2000-0590" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Poll It 2.0 CGI script allows remote attackers to read arbitrary files by specifying the file name in the data_dir parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1431" source="BID" patch="1" adv="1">1431</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0076.html" source="BUGTRAQ" patch="1" adv="1">20000706 Vulnerability in Poll_It cgi v2.0</ref>
      <ref url="http://xforce.iss.net/static/4878.php" source="XF" adv="1">http-cgi-pollit-variable-overwrite(4878)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cgi-world" name="poll_it">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0591" published="2000-07-05" name="CVE-2000-0591" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Novell BorderManager 3.0 and 3.5 allows remote attackers to bypass URL filtering by encoding characters in the requested URL.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0038.html" source="BUGTRAQ" adv="1">20000705 Novell BorderManager 3.0 EE - Encoded URL rule bypass</ref>
      <ref url="http://www.securityfocus.com/bid/1432" source="BID">1432</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="bordermanager">
        <vers num="3.0" />
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0592" published="2000-06-27" name="CVE-2000-0592" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflows in POP3 service in WinProxy 2.0 and 2.0.1 allow remote attackers to execute arbitrary commands via long USER, PASS, LIST, RETR, or DELE commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200006271417.GFE84146.-BJXON@lac.co.jp" source="BUGTRAQ" patch="1" adv="1">20000627 [SPSadvisory #37]WinProxy 2.0.0/2.0.1 DoS and Exploitable Buffer Overflow</ref>
      <ref url="http://www.securityfocus.com/bid/1400" source="BID">1400</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sapporoworks" name="sapporoworks_winproxy">
        <vers num="2.0" />
        <vers num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0593" published="2000-06-27" name="CVE-2000-0593" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WinProxy 2.0 and 2.0.1 allows remote attackers to cause a denial of service by sending an HTTP GET request without listing an HTTP version number.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4831.php" source="XF" patch="1" adv="1">winproxy-get-dos(4831)</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200006271417.GFE84146.-BJXON@lac.co.jp" source="BUGTRAQ">20000627 [SPSadvisory #37]WinProxy 2.0.0/2.0.1 DoS and Exploitable Buffer Overflow</ref>
      <ref url="http://www.securityfocus.com/bid/1400" source="BID">1400</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sapporoworks" name="sapporoworks_winproxy">
        <vers num="2.0" />
        <vers num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0594" published="2000-07-04" name="CVE-2000-0594" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BitchX IRC client does not properly cleanse an untrusted format string, which allows remote attackers to cause a denial of service via an invite to a channel whose name includes special formatting characters.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4897.php" source="XF" patch="1" adv="1">irc-bitchx-invite-dos</ref>
      <ref url="http://www.securityfocus.com/bid/1436" source="BID">1436</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-042.html" source="REDHAT">RHSA-2000:042</ref>
      <ref url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-022.0.txt" source="CALDERA">CSSA-2000-022.0</ref>
      <ref url="http://archives.neohapsis.com/archives/vuln-dev/2000-q3/0018.html" source="VULN-DEV">20000704 BitchX /ignore bug</ref>
      <ref url="http://archives.neohapsis.com/archives/freebsd/2000-07/0042.html" source="FREEBSD">FreeBSD-SA-00:32</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0105.html" source="BUGTRAQ">20000707 BitchX update</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0098.html" source="BUGTRAQ">20000707 CONECTIVA LINUX SECURITY ANNOUNCEMENT - BitchX</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0026.html" source="BUGTRAQ">20000704 BitchX exploit possibly waiting to happen, certain DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="caldera" name="openlinux_desktop">
        <vers num="2.3" />
      </prod>
      <prod vendor="caldera" name="openlinux_ebuilder">
        <vers num="2.3" />
      </prod>
      <prod vendor="caldera" name="openlinux_edesktop">
        <vers num="2.4" />
      </prod>
      <prod vendor="caldera" name="openlinux_eserver">
        <vers num="2.3" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.5" />
        <vers num="4.0" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="2007" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0595" published="2000-07-05" name="CVE-2000-0595" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">libedit searches for the .editrc file in the current directory instead of the user's home directory, which may allow local users to execute arbitrary commands by installing a modified .editrc in another directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1437" source="BID" patch="1" adv="1">1437</ref>
      <ref url="http://archives.neohapsis.com/archives/freebsd/2000-07/0035.html" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-00:24</ref>
      <ref url="http://www.osvdb.org/1446" source="OSVDB">1446</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0596" published="2000-06-27" name="CVE-2000-0596" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Internet Explorer 5.x does not warn a user before opening a Microsoft Access database file that is referenced within ActiveX OBJECT tags in an HTML document, which could allow remote attackers to execute arbitrary commands, aka the "IE Script" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2000-16.html" source="CERT">CA-2000-16</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=39589359.762392DB@nat.bg" source="BUGTRAQ" patch="1" adv="1">20000627 IE 5 and Access 2000 vulnerability - executing programs</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS00-049.asp" source="MS" patch="1" adv="1">MS00-049</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=000d01bfe0fb$418f59b0$96217aa8@src.bu.edu" source="BUGTRAQ">20000627 FW: IE 5 and Access 2000 vulnerability - executing programs</ref>
      <ref url="http://www.securityfocus.com/bid/1398" source="BID">1398</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.0.1" edition="sp2" />
        <vers num="5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0597" published="2000-06-27" name="CVE-2000-0597" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Microsoft Office 2000 (Excel and PowerPoint) and PowerPoint 97 are marked as safe for scripting, which allows remote attackers to force Internet Explorer or some email clients to save files to arbitrary locations via the Visual Basic for Applications (VBA) SaveAs function, aka the "Office HTML Script" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" />
    </loss_types>
    <vuln_types>
      <exception />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=39589349.ED9DBCAB@nat.bg" source="BUGTRAQ" patch="1" adv="1">20000627 IE 5 and Excel 2000, PowerPoint 2000 vulnerability - executing programs</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS00-049.asp" source="MS" patch="1" adv="1">MS00-049</ref>
      <ref url="http://www.securityfocus.com/bid/1399" source="BID">1399</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2000" />
      </prod>
      <prod vendor="microsoft" name="powerpoint">
        <vers num="2000" />
        <vers num="97" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0598" published="2000-06-26" name="CVE-2000-0598" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Fortech Proxy+ allows remote attackers to bypass access restrictions for to the administration service by redirecting their connections through the telnet proxy.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0268.html" source="BUGTRAQ" patch="1" adv="1">20000626 Proxy+ Telnet Gateway Problems</ref>
      <ref url="http://www.proxyplus.cz/faq/articles/EN/art01002.htm" source="MISC">http://www.proxyplus.cz/faq/articles/EN/art01002.htm</ref>
      <ref url="http://www.securityfocus.com/bid/1395" source="BID">1395</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fortech" name="proxy+">
        <vers num="2.40" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0599" published="2000-06-29" name="CVE-2000-0599" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in iMesh 1.02 allows remote attackers to execute arbitrary commands via a long string to the iMesh port.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0335.html" source="BUGTRAQ" patch="1" adv="1">20000629 iMesh 1.02 vulnerability</ref>
      <ref url="http://www.imesh.com/download/download.html" source="MISC">http://www.imesh.com/download/download.html</ref>
      <ref url="http://www.securityfocus.com/bid/1407" source="BID">1407</ref>
    </refs>
    <vuln_soft>
      <prod vendor="imesh.com" name="imesh">
        <vers prev="1" num="1.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0600" published="2000-06-26" name="CVE-2000-0600" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Netscape Enterprise Server in NetWare 5.1 allows remote attackers to cause a denial of service or execute arbitrary commands via a malformed URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4780.php" source="XF" patch="1" adv="1">netscape-virtual-directory-bo(4780)</ref>
      <ref url="http://www.securityfocus.com/bid/1393" source="BID" patch="1" adv="1">1393</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0264.html" source="BUGTRAQ" patch="1" adv="1">20000626 Netscape Enterprise Server for NetWare Virtual Directory Vulnerab ility</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="enterprise_server">
        <vers num="4.1.1" edition="" />
        <vers num="4.1.1" edition=":netware" />
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":netware" />
      </prod>
      <prod vendor="novell" name="netware">
        <vers num="5.0" />
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0601" published="2000-06-25" name="CVE-2000-0601" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">LeafChat 1.7 IRC client allows a remote IRC server to cause a denial of service by rapidly sending a large amount of error messages.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.BSF.4.10.10006252056110.74551-100000@unix.za.net" source="BUGTRAQ" adv="1">20000625 LeafChat Denial of Service</ref>
      <ref url="http://www.leafdigital.com/Software/leafChat/history.html" source="CONFIRM">http://www.leafdigital.com/Software/leafChat/history.html</ref>
      <ref url="http://www.securityfocus.com/bid/1396" source="BID">1396</ref>
    </refs>
    <vuln_soft>
      <prod vendor="leafdigital" name="leafchat">
        <vers num="1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0602" published="2000-06-21" name="CVE-2000-0602" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Secure Locate (slocate) in Red Hat Linux allows local users to gain privileges via a malformed configuration file that is specified in the LOCATE_PATH environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.21.0006211209500.22969-100000@nimue.tpi.pl" source="BUGTRAQ">20000621 rh 6.2 - gid compromises, etc</ref>
      <ref url="http://www.securityfocus.com/bid/1385" source="BID">1385</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kevin_lindsay" name="secure_locate">
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0603" published="2000-07-07" name="CVE-2000-0603" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Microsoft SQL Server 7.0 allows a local user to bypass permissions for stored procedures by referencing them via a temporary stored procedure, aka the "Stored Procedure Permissions" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1444" source="BID" patch="1" adv="1">1444</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-048.asp" source="MS" patch="1" adv="1">MS00-048</ref>
      <ref url="http://xforce.iss.net/static/4921.php" source="XF">mssql-procedure-perms</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="sql_server">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0604" published="2000-06-21" name="CVE-2000-0604" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">gkermit in Red Hat Linux is improperly installed with setgid uucp, which allows local users to modify files owned by uucp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.21.0006211209500.22969-100000@nimue.tpi.pl" source="BUGTRAQ" adv="1">20000621 rh 6.2 - gid compromises, etc</ref>
      <ref url="http://www.securityfocus.com/bid/1383" source="BID" adv="1">1383</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0605" published="2000-07-10" name="CVE-2000-0605" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Blackboard CourseInfo 4.0 stores the local and SQL administrator user names and passwords in cleartext in a registry key whose access control allows users to access the passwords.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1460" source="BID">1460</ref>
      <ref url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0007&amp;L=NTBUGTRAQ&amp;P=R1647" source="NTBUGTRAQ">20000710 Two issues: Blackboard CourseInfo 4.0 stores admin password in clear text; strange settings on the winreg key.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="blackboard" name="courseinfo">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0606" published="2000-06-21" name="CVE-2000-0606" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in kon program in Kanji on Console (KON) package on Linux may allow local users to gain root privileges via a long -StartupMessage parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.21.0006192340340.19998-100000@ferret.lmh.ox.ac.uk" source="BUGTRAQ" adv="1">20000619 Problems with "kon2" package</ref>
      <ref url="http://www.securityfocus.com/bid/1371" source="BID">1371</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="6.1" />
        <vers num="7.0" />
        <vers num="7.1" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="6.1" />
        <vers num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0607" published="2000-06-21" name="CVE-2000-0607" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in fld program in Kanji on Console (KON) package on Linux may allow local users to gain root privileges via an input file containing long CHARSET_REGISTRY or CHARSET_ENCODING settings.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.21.0006192340340.19998-100000@ferret.lmh.ox.ac.uk" source="BUGTRAQ" adv="1">20000619 Problems with "kon2" package</ref>
      <ref url="http://www.securityfocus.com/bid/1371" source="BID">1371</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="6.1" />
        <vers num="7.0" />
        <vers num="7.1" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="6.1" />
        <vers num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0608" published="2000-06-21" name="CVE-2000-0608" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">NetWin dMailWeb and cwMail 2.6i and earlier allows remote attackers to cause a denial of service via a long POP parameter (pophost).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-06-15&amp;msg=4.1.20000621113334.00996820@qlink.queensu.ca" source="BUGTRAQ" patch="1" adv="1">20000620 NetWin dMailWeb Denial of Service</ref>
      <ref url="http://www.securityfocus.com/bid/1376" source="BID" patch="1" adv="1">1376</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netwin" name="cwmail">
        <vers num="2.5e" />
        <vers num="2.6g" />
        <vers num="2.6i" />
        <vers num="2.6j" />
      </prod>
      <prod vendor="netwin" name="dmailweb">
        <vers num="2.5e" />
        <vers num="2.6g" />
        <vers num="2.6i" />
        <vers num="2.6j" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0609" published="2000-06-21" name="CVE-2000-0609" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">NetWin dMailWeb and cwMail 2.6g and earlier allows remote attackers to cause a denial of service via a long username parameter.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-06-15&amp;msg=4.1.20000621113334.00996820@qlink.queensu.ca" source="BUGTRAQ" adv="1">20000620 NetWin dMailWeb Denial of Service</ref>
      <ref url="http://www.securityfocus.com/bid/1376" source="BID">1376</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netwin" name="cwmail">
        <vers num="2.5e" />
        <vers num="2.6g" />
        <vers num="2.6i" />
        <vers num="2.6j" />
      </prod>
      <prod vendor="netwin" name="dmailweb">
        <vers num="2.5e" />
        <vers num="2.6g" />
        <vers num="2.6i" />
        <vers num="2.6j" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0610" published="2000-06-23" name="CVE-2000-0610" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">NetWin dMailWeb and cwMail 2.6g and earlier allows remote attackers to bypass authentication and use the server for mail relay via a username that contains a carriage return.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1390" source="BID" patch="1" adv="1">1390</ref>
      <ref url="http://xforce.iss.net/static/4770.php" source="XF" adv="1">netwin-dmailweb-newline</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0243.html" source="BUGTRAQ">20000623 NetWin dMailWeb Unrestricted Mail Relay</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netwin" name="cwmail">
        <vers num="2.6g" />
      </prod>
      <prod vendor="netwin" name="dmailweb">
        <vers num="2.6g" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0611" published="2000-06-23" name="CVE-2000-0611" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The default configuration of NetWin dMailWeb and cwMail trusts all POP servers, which allows attackers to bypass normal authentication and cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <access />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4771.php" source="XF" patch="1" adv="1">netwin-dmailweb-auth</ref>
      <ref url="http://www.securityfocus.com/bid/1391" source="BID" patch="1" adv="1">1391</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0243.html" source="BUGTRAQ" patch="1" adv="1">20000623 NetWin dMailWeb Unrestricted Mail Relay</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netwin" name="cwmail">
        <vers num="2.6g" />
      </prod>
      <prod vendor="netwin" name="dmailweb">
        <vers num="2.6g" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0612" published="2000-06-29" name="CVE-2000-0612" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Windows 95 and Windows 98 do not properly process spoofed ARP packets, which allows remote attackers to overwrite static entries in the cache table.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=395B7E64.9FB3D4DB@starzetz.de" source="BUGTRAQ" adv="1">20000629 Buggy ARP handling in Windoze</ref>
      <ref url="http://www.securityfocus.com/bid/1406" source="BID" adv="1">1406</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_95">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0613" published="2000-03-20" name="CVE-2000-0613" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco Secure PIX Firewall does not properly identify forged TCP Reset (RST) packets, which allows remote attackers to force the firewall to close legitimate connections.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=B3D6883199DBD311868100A0C9FC2CDC046B72@protea.citec.net" source="BUGTRAQ" adv="1">20000320 PIX DMZ Denial of Service - TCP Resets</ref>
      <ref url="http://xforce.iss.net/static/4928.php" source="XF">cisco-pix-firewall-tcp</ref>
      <ref url="http://www.securityfocus.com/bid/1454" source="BID">1454</ref>
      <ref url="http://www.osvdb.org/1457" source="OSVDB">1457</ref>
      <ref url="http://www.cisco.com/warp/public/707/pixtcpreset-pub.shtml" source="CISCO">20000711 Cisco Secure PIX Firewall TCP Reset Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="pix_firewall">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0614" published="2000-07-10" name="CVE-2000-0614" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Tnef program in Linux systems allows remote attackers to overwrite arbitrary files via TNEF encoded compressed attachments which specify absolute path names for the decompressed output.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1450" source="BID" patch="1" adv="1">1450</ref>
      <ref url="http://archives.neohapsis.com/archives/vendor/2000-q3/0002.html" source="SUSE" patch="1" adv="1">20000710 Security Hole in tnef &lt; 0-124</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="suse_linux">
        <vers num="6.3" edition="" />
        <vers num="6.3" edition=":ppc" />
        <vers num="6.3" edition="alpha" />
        <vers num="6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0615" published="2000-07-19" name="CVE-2000-0615" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">LPRng 3.6.x improperly installs lpd as setuid root, which can allow local users to append lpd trace and logging messages to files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1447" source="BID" patch="1" adv="1">1447</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0117.html" source="BUGTRAQ" patch="1" adv="1">20000709 LPRng lpd should not be SETUID root</ref>
      <ref url="http://xforce.iss.net/static/7361.php" source="XF">lpd-suid-root(7361)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="astart_technologies" name="lprng">
        <vers num="3.6.1" />
        <vers num="3.6.10" />
        <vers num="3.6.11" />
        <vers num="3.6.12" />
        <vers num="3.6.13" />
        <vers num="3.6.14" />
        <vers num="3.6.15" />
        <vers num="3.6.2" />
        <vers num="3.6.3" />
        <vers num="3.6.4" />
        <vers num="3.6.5" />
        <vers num="3.6.6" />
        <vers num="3.6.7" />
        <vers num="3.6.8" />
        <vers num="3.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0616" published="2000-06-26" name="CVE-2000-0616" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Vulnerability in HP TurboIMAGE DBUTIL allows local users to gain additional privileges via DBUTIL.PUB.SYS.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1405" source="BID" patch="1" adv="1">1405</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0294.html" source="HP" patch="1" adv="1">HPSBMP0006-007</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="mpe_ix">
        <vers num="4.5" />
        <vers num="5.0" />
        <vers num="5.5" />
        <vers num="6.0" />
        <vers num="6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0617" published="2000-06-22" name="CVE-2000-0617" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in xconq and cconq game programs on Red Hat Linux allows local users to gain additional privileges via long USER environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0222.html" source="BUGTRAQ" adv="1">20000622 RHL 6.2 xconq package - overflows yield gid games</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stanley_t._shebs" name="xconq">
        <vers num="7.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0618" published="2000-06-22" name="CVE-2000-0618" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in xconq and cconq game programs on Red Hat Linux allows local users to gain additional privileges via long DISPLAY environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0222.html" source="BUGTRAQ" adv="1">20000622 RHL 6.2 xconq package - overflows yield gid games</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stanley_t._shebs" name="xconq">
        <vers num="7.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0619" published="2000-07-19" name="CVE-2000-0619" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Top Layer AppSwitch 2500 allows remote attackers to cause a denial of service via malformed ICMP packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1258" source="BID" patch="1" adv="1">1258</ref>
      <ref url="http://archives.neohapsis.com/archives/vuln-dev/2000-q2/0921.html" source="VULN-DEV" adv="1">20000614 Update on TopLayer Advisory</ref>
      <ref url="http://archives.neohapsis.com/archives/vuln-dev/2000-q2/0680.html" source="VULN-DEV" adv="1">20000520 TopLayer layer 7 switch Advisory</ref>
      <ref url="http://xforce.iss.net/static/7364.php" source="XF">toplayer-icmp-dos(7364)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="toplayer" name="appswitch">
        <vers num="2500.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0620" published="2000-06-19" name="CVE-2000-0620" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">libX11 X library allows remote attackers to cause a denial of service via a resource mask of 0, which causes libX11 to go into an infinite loop.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4996.php" source="XF" patch="1" adv="1">libx11-infinite-loop-dos(4996)</ref>
      <ref url="http://www.securityfocus.com/bid/1409" source="BID" patch="1" adv="1">1409</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96146116627474&amp;w=2" source="BUGTRAQ">20000619 XFree86: Various nasty libX11 holes</ref>
    </refs>
    <vuln_soft>
      <prod vendor="open_group" name="x">
        <vers num="11.0r6" />
        <vers num="11.0r6.1" />
        <vers num="11.0r6.2" />
        <vers num="11.0r6.3" />
        <vers num="11.0r6.4" />
      </prod>
      <prod vendor="xfree86_project" name="x11r6">
        <vers num="3.3.3" />
        <vers num="3.3.4" />
        <vers num="3.3.5" />
        <vers num="3.3.6" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0621" published="2000-07-20" name="CVE-2000-0621" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Microsoft Outlook 98 and 2000, and Outlook Express 4.0x and 5.0x, allow remote attackers to read files on the client's system via a malformed HTML message that stores files outside of the cache, aka the "Cache Bypass" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2000-14.html" source="CERT" patch="1" adv="1">CA-2000-14</ref>
      <ref url="http://www.securityfocus.com/bid/1501" source="BID" patch="1" adv="1">1501</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS00-046.asp" source="MS" patch="1" adv="1">MS00-046</ref>
      <ref url="http://xforce.iss.net/static/5013.php" source="XF">outlook-cache-bypass</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="outlook">
        <vers num="2000" />
        <vers num="97" />
        <vers num="98" />
      </prod>
      <prod vendor="microsoft" name="outlook_express">
        <vers num="4.0" />
        <vers num="4.01" />
        <vers num="5.0" />
        <vers num="5.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0622" published="2000-07-19" name="CVE-2000-0622" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Webfind CGI program in O'Reilly WebSite Professional web server 2.x allows remote attackers to execute arbitrary commands via a URL containing a long "keywords" parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://website.oreilly.com/support/software/wspro25_releasenotes.txt" source="CONFIRM">http://website.oreilly.com/support/software/wspro25_releasenotes.txt</ref>
      <ref url="http://xforce.iss.net/static/4962.php" source="XF">website-webfind-bo(4962)</ref>
      <ref url="http://www.securityfocus.com/bid/1487" source="BID">1487</ref>
      <ref url="http://www.nai.com/research/covert/advisories/043.asp" source="NAI">20000719 O'Reilly WebSite Professional Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oreilly" name="website_professional">
        <vers num="2.3.18" />
        <vers num="2.4" />
        <vers num="2.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0623" published="2000-07-17" name="CVE-2000-0623" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in O'Reilly WebSite Professional web server 2.4 and earlier allows remote attackers to execute arbitrary commands via a long GET request or Referrer header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1492" source="BID" patch="1" adv="1">1492</ref>
      <ref url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0007&amp;L=ntbugtraq&amp;F=&amp;S=&amp;P=5946" source="NTBUGTRAQ" patch="1" adv="1">20000719 Alert: Buffer Overrun is O'Reilly WebsitePro httpd32.exe (CISADV000717)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oreilly" name="website_professional">
        <vers num="2.3.18" />
        <vers num="2.4" />
        <vers num="2.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0624" published="2000-07-20" name="CVE-2000-0624" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Winamp 2.64 and earlier allows remote attackers to execute arbitrary commands via a long #EXTINF: extension in the M3U playlist.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4956.php" source="XF" adv="1">winamp-playlist-parser-bo</ref>
      <ref url="http://www.winamp.com/getwinamp/newfeatures.jhtml" source="CONFIRM">http://www.winamp.com/getwinamp/newfeatures.jhtml</ref>
      <ref url="http://www.securityfocus.com/bid/1496" source="BID" adv="1">1496</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0289.html" source="BUGTRAQ" adv="1">20000720 Winamp M3U playlist parser buffer overflow security vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nullsoft" name="winamp">
        <vers prev="1" num="2.64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0625" published="2000-07-18" name="CVE-2000-0625" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">NetZero 3.0 and earlier uses weak encryption for storing a user's login information, which allows a local user to decrypt the password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1483" source="BID" patch="1" adv="1">1483</ref>
      <ref url="http://www.l0pht.com/advisories/netzero.txt" source="L0PHT" patch="1" adv="1">20000718 NetZero Password Encryption Algorithm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netzero" name="zeroport">
        <vers prev="1" num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0626" published="2000-07-18" name="CVE-2000-0626" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Alibaba web server allows remote attackers to cause a denial of service via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1482" source="BID" adv="1">1482</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0237.html" source="BUGTRAQ" adv="1">20000718 Multiple bugs in Alibaba 2.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="computer_software_manufaktur" name="alibaba">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0627" published="2000-07-18" name="CVE-2000-0627" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">BlackBoard CourseInfo 4.0 does not properly authenticate users, which allows local users to modify CourseInfo database information and gain privileges by directly calling the supporting CGI programs such as user_update_passwd.pl and user_update_admin.pl.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4946.php" source="XF" patch="1" adv="1">blackboard-courseinfo-dbase-modification</ref>
      <ref url="http://www.securityfocus.com/bid/1486" source="BID" patch="1" adv="1">1486</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0254.html" source="BUGTRAQ" adv="1">20000718 Blackboard Courseinfo v4.0 User Authentication</ref>
      <ref url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D20000719151904.I17986@securityfocus.com" source="BUGTRAQ">20000719 Security Fix for Blackboard CourseInfo 4.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="blackboard" name="courseinfo">
        <vers num="4.0" />
        <vers num="unix" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0628" published="2000-07-11" name="CVE-2000-0628" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The source.asp example script in the Apache ASP module Apache::ASP 1.93 and earlier allows remote attackers to modify files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4931.php" source="XF" patch="1" adv="1">apache-source-asp-file-write</ref>
      <ref url="http://www.securityfocus.com/bid/1457" source="BID" patch="1" adv="1">1457</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0142.html" source="BUGTRAQ" patch="1" adv="1">20000710 ANNOUNCE Apache::ASP v1.95 - Security Hole Fixed</ref>
      <ref url="http://www.nodeworks.com/asp/changes.html" source="CONFIRM">http://www.nodeworks.com/asp/changes.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joshua_chamas" name="apache_asp">
        <vers num="0.16" />
        <vers num="0.17" />
        <vers num="0.18" />
        <vers num="1.93" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0629" published="2000-07-12" name="CVE-2000-0629" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The default configuration of the Sun Java web server 2.0 and earlier allows remote attackers to execute arbitrary commands by uploading Java code to the server via board.html, then directly calling the JSP compiler servlet.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.sun.com/software/jwebserver/faq/jwsca-2000-02.html" source="MISC" patch="1" adv="1">http://www.sun.com/software/jwebserver/faq/jwsca-2000-02.html </ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0163.html" source="BUGTRAQ" patch="1" adv="1">20000711 Sun's Java Web Server remote command execution vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/1459" source="BID">1459</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_web_server">
        <vers num="1.1.3" />
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0630" published="2000-07-17" name="CVE-2000-0630" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IIS 4.0 and 5.0 allows remote attackers to obtain fragments of source code by appending a +.htr to the URL, a variant of the "File Fragment Reading via .HTR" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-044.asp" source="MS" patch="1" adv="1">MS00-044</ref>
      <ref url="http://xforce.iss.net/static/5104.php" source="XF">iis-htr-obtain-code</ref>
      <ref url="http://www.securityfocus.com/bid/1488" source="BID">1488</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0631" published="2000-07-14" name="CVE-2000-0631" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">An administrative script from IIS 3.0, later included in IIS 4.0 and 5.0, allows remote attackers to cause a denial of service by accessing the script without a particular argument, aka the "Absent Directory Browser Argument" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4951.php" source="XF" patch="1" adv="1">iis-absent-directory-dos</ref>
      <ref url="http://www.securityfocus.com/bid/1476" source="BID" patch="1" adv="1">1476</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-044.asp" source="MS" patch="1" adv="1">MS00-044</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96390444022878&amp;w=2" source="BUGTRAQ">20000718 ISBASE Security Advisory(SA2000-02)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0632" published="2000-07-17" name="CVE-2000-0632" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the web archive component of L-Soft Listserv 1.8d and earlier allows remote attackers to execute arbitrary commands via a long query string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.lsoft.com/news/default.asp?item=Advisory1" source="CONFIRM">http://www.lsoft.com/news/default.asp?item=Advisory1</ref>
      <ref url="http://xforce.iss.net/static/4952.php" source="XF">lsoft-listserv-querystring-bo</ref>
      <ref url="http://www.securityfocus.com/bid/1490" source="BID">1490</ref>
      <ref url="http://www.nai.com/nai_labs/asp_set/advisory/43_Advisory.asp" source="NAI">20000717 [COVERT-2000-07] LISTSERV Web Archive Remote Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lsoft" name="listserv">
        <vers num="1.8c" />
        <vers num="1.8d" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0633" published="2000-07-18" name="CVE-2000-0633" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Vulnerability in Mandrake Linux usermode package allows local users to to reboot or halt the system.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4944.php" source="XF" patch="1" adv="1">linux-usermode-dos</ref>
      <ref url="http://www.securityfocus.com/bid/1489" source="BID" patch="1" adv="1">1489</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0251.html" source="BUGTRAQ" patch="1" adv="1">20000718 MDKSA-2000:020 usermode update</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-053.html" source="REDHAT">RHSA-2000:053</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0117.html" source="BUGTRAQ">20000812 Conectiva Linux security announcement - usermode</ref>
    </refs>
    <vuln_soft>
      <prod vendor="conectiva" name="linux">
        <vers num="4.0" />
        <vers num="4.0es" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="7.1" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":i386" />
        <vers num="6.0" edition=":alpha" />
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":i386" />
        <vers num="6.1" edition=":alpha" />
        <vers num="6.1" edition=":sparc" />
        <vers num="6.2" edition="" />
        <vers num="6.2" edition=":alpha" />
        <vers num="6.2" edition=":sparc" />
        <vers num="6.2" edition=":i386" />
        <vers num="6.2e" edition="" />
        <vers num="6.2e" edition=":alpha" />
        <vers num="6.2e" edition=":i386" />
        <vers num="6.2e" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0634" published="2000-04-03" name="CVE-2000-0634" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The web administration interface for CommuniGate Pro 3.2.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1493" source="BID" patch="1" adv="1">1493</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0223.html" source="BUGTRAQ" patch="1" adv="1">20000717 S21SEC-003: Vulnerabilities in CommuniGate Pro v3.2.4</ref>
      <ref url="http://xforce.iss.net/static/5105.php" source="XF">communigate-pro-file-read</ref>
      <ref url="http://www.osvdb.org/5774" source="OSVDB">5774</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stalker" name="communigate_pro">
        <vers num="3.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0635" published="2000-07-10" name="CVE-2000-0635" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The view_page.html sample page in the MiniVend shopping cart program allows remote attackers to execute arbitrary commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4880.php" source="XF" patch="1" adv="1">minivend-viewpage-sample</ref>
      <ref url="http://www.securityfocus.com/bid/1449" source="BID" patch="1" adv="1">1449</ref>
      <ref url="http://www.zdnet.com/zdnn/stories/news/0,4586,2600258,00.html" source="CONFIRM">http://www.zdnet.com/zdnn/stories/news/0,4586,2600258,00.html</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0150.html" source="BUGTRAQ" adv="1">20000711 Akopia MiniVend Piped Command Execution Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="akopia" name="minivend">
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="4.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0636" published="2000-07-19" name="CVE-2000-0636" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">HP JetDirect printers versions G.08.20 and H.08.20 and earlier allow remote attackers to cause a denial of service via a malformed FTP quote command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1491" source="BID" patch="1" adv="1">1491</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0265.html" source="BUGTRAQ" patch="1" adv="1">20000719 HP Jetdirect - Invalid FTP Command DoS</ref>
      <ref url="http://xforce.iss.net/static/4947.php" source="XF">hp-jetdirect-quote-dos</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="jetdirect">
        <vers num="j3111a_rev._a.08.06" />
        <vers num="j3111a_rev._g.05.35" />
        <vers num="j3111a_rev._g.07.02" />
        <vers num="j3111a_rev._g.07.03" />
        <vers num="j3111a_rev._g.07.17" />
        <vers num="j3111a_rev._g.08.03" />
        <vers num="rev._g.08.04" />
        <vers num="rev._g.08.20" />
        <vers num="rev._h.08.05" />
        <vers num="rev._h.08.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0637" published="2000-07-26" name="CVE-2000-0637" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Microsoft Excel 97 and 2000 allows an attacker to execute arbitrary commands by specifying a malicious .dll using the Register.ID function, aka the "Excel REGISTER.ID Function" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5016.php" source="XF" patch="1" adv="1">excel-register-function</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=396B3F8F.9244D290@nat.bg" source="BUGTRAQ" patch="1" adv="1">20000711 Excel 2000 vulnerability - executing programs</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-051.asp" source="MS" patch="1" adv="1">MS00-051</ref>
      <ref url="http://www.securityfocus.com/bid/1451" source="BID">1451</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2000" />
        <vers num="97" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0638" published="2000-07-11" name="CVE-2000-0638" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">bb-hostsvc.sh in Big Brother 1.4h1 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack on the HOSTSVC parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4879.php" source="XF">http-cgi-bigbrother-bbhostsvc</ref>
      <ref url="http://www.securityfocus.com/bid/1455" source="BID">1455</ref>
      <ref url="http://bb4.com/README.CHANGES" source="CONFIRM">http://bb4.com/README.CHANGES</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0147.html" source="BUGTRAQ">20000711 REMOTE EXPLOIT IN ALL CURRENT VERSIONS OF BIG BROTHER</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0146.html" source="BUGTRAQ">20000711 BIG BROTHER EXPLOIT</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sean_macguire" name="big_brother">
        <vers num="1.0" />
        <vers num="1.09b" />
        <vers num="1.09c" />
        <vers num="1.09d" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.3b" />
        <vers num="1.4" />
        <vers num="1.4g" />
        <vers num="1.4h" />
        <vers num="1.4h1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0639" published="2000-06-11" name="CVE-2000-0639" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The default configuration of Big Brother 1.4h2 and earlier does not include proper access restrictions, which allows remote attackers to execute arbitrary commands by using bbd to upload a file whose extension will cause it to be executed as a CGI script by the web server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0171.html" source="BUGTRAQ" patch="1" adv="1">20000711 Big Brother filename extension vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/1494" source="BID" adv="1">1494</ref>
      <ref url="http://xforce.iss.net/static/5103.php" source="XF">big-brother-filename-extension</ref>
      <ref url="http://www.osvdb.org/1472" source="OSVDB">1472</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sean_macguire" name="big_brother">
        <vers num="1.0" />
        <vers num="1.09b" />
        <vers num="1.09c" />
        <vers num="1.09d" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.3b" />
        <vers num="1.4" />
        <vers num="1.4g" />
        <vers num="1.4h" />
        <vers num="1.4h1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0640" published="2000-07-08" name="CVE-2000-0640" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Guild FTPd allows remote attackers to determine the existence of files outside the FTP root via a .. (dot dot) attack, which provides different error messages depending on whether the file exists or not.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0114.html" source="BUGTRAQ" patch="1" adv="1">20000708 gnu-pop3d (FTGate problem), Savant Webserver, Guild FTPd </ref>
      <ref url="http://xforce.iss.net/static/4922.php" source="XF" adv="1">guild-ftpd-disclosure</ref>
      <ref url="http://www.securityfocus.com/bid/1452" source="BID" adv="1">1452</ref>
      <ref url="http://www.osvdb.org/573" source="OSVDB">573</ref>
    </refs>
    <vuln_soft>
      <prod vendor="steve_poulsen" name="guildftpd">
        <vers num="0.9.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0641" published="2000-07-08" name="CVE-2000-0641" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Savant web server allows remote attackers to execute arbitrary commands via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4901.php" source="XF" adv="1">savant-get-bo</ref>
      <ref url="http://www.securityfocus.com/bid/1453" source="BID" adv="1">1453</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0114.html" source="BUGTRAQ" adv="1">20000708 gnu-pop3d (FTGate problem), Savant Webserver, Guild FTPd </ref>
    </refs>
    <vuln_soft>
      <prod vendor="michael_lamont" name="savant_webserver">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0642" published="2000-07-12" name="CVE-2000-0642" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The default configuration of WebActive HTTP Server 1.00 stores the web access log active.log in the document root, which allows remote attackers to view the logs by directly requesting the page.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200007130827.BAA32671@Rage.Resentment.org" source="BUGTRAQ" patch="1" adv="1">20000711 Lame DoS in WEBactive win65/NT server</ref>
      <ref url="http://www.securityfocus.com/bid/1497" source="BID" adv="1">1497</ref>
      <ref url="http://xforce.iss.net/static/5184.php" source="XF">webactive-active-log</ref>
    </refs>
    <vuln_soft>
      <prod vendor="itafrica" name="webactive">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0643" published="2000-07-12" name="CVE-2000-0643" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in WebActive HTTP Server 1.00 allows remote attackers to cause a denial of service via a long URL.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4949.php" source="XF" adv="1">webactive-long-get-dos</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200007130827.BAA32671@Rage.Resentment.org" source="BUGTRAQ" adv="1">20000711 Lame DoS in WEBactive win65/NT server</ref>
      <ref url="http://www.securityfocus.com/bid/1470" source="BID" adv="1">1470</ref>
    </refs>
    <vuln_soft>
      <prod vendor="itafrica" name="webactive">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0644" published="2000-07-21" name="CVE-2000-0644" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by executing a STAT command while the LIST command is still executing.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1506" source="BID" patch="1" adv="1">1506</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0295.html" source="BUGTRAQ" patch="1" adv="1">20000721 WFTPD/WFTPD Pro 2.41 RC11 vulnerabilities.</ref>
      <ref url="http://xforce.iss.net/static/5003.php" source="XF">wftpd-stat-dos</ref>
      <ref url="http://www.osvdb.org/1477" source="OSVDB">1477</ref>
    </refs>
    <vuln_soft>
      <prod vendor="texas_imperial_software" name="wftpd">
        <vers num="2.34" />
        <vers num="2.4.1" />
        <vers num="2.4.1_rc11" />
        <vers num="2.40" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0645" published="2000-07-21" name="CVE-2000-0645" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by using the RESTART (REST) command and writing beyond the end of a file, or writing to a file that does not exist, via commands such as STORE UNIQUE (STOU), STORE (STOR), or APPEND (APPE).</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1506" source="BID" patch="1" adv="1">1506</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0295.html" source="BUGTRAQ" patch="1" adv="1">20000721 WFTPD/WFTPD Pro 2.41 RC11 vulnerabilities.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="texas_imperial_software" name="wftpd">
        <vers num="2.34" />
        <vers num="2.4.1" />
        <vers num="2.4.1_rc11" />
        <vers num="2.40" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0646" published="2000-07-21" name="CVE-2000-0646" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WFTPD and WFTPD Pro 2.41 allows remote attackers to obtain the real pathname for a file by executing a STATUS (STAT) command while the file is being transferred.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1506" source="BID" patch="1" adv="1">1506</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0295.html" source="BUGTRAQ" patch="1" adv="1">20000721 WFTPD/WFTPD Pro 2.41 RC11 vulnerabilities.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="texas_imperial_software" name="wftpd">
        <vers num="2.34" />
        <vers num="2.4.1" />
        <vers num="2.4.1_rc11" />
        <vers num="2.40" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0647" published="2000-07-21" name="CVE-2000-0647" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by executing an MLST command before logging into the server.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1506" source="BID" patch="1" adv="1">1506</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0295.html" source="BUGTRAQ" patch="1" adv="1">20000721 WFTPD/WFTPD Pro 2.41 RC11 vulnerabilities.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="texas_imperial_software" name="wftpd">
        <vers num="2.34" />
        <vers num="2.4.1" />
        <vers num="2.4.1_rc11" />
        <vers num="2.40" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0648" published="2000-07-11" name="CVE-2000-0648" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WFTPD and WFTPD Pro 2.41 allows local users to cause a denial of service by executing the RENAME TO (RNTO) command before a RENAME FROM (RNFR) command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1456" source="BID" patch="1" adv="1">1456</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=E13BvU6-0007d8-00@dwarf.box.sk" source="BUGTRAQ" adv="1">20000711 WFTPD/WFTPD Pro 2.41 RC10 denial-of-service</ref>
    </refs>
    <vuln_soft>
      <prod vendor="texas_imperial_software" name="wftpd">
        <vers num="2.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0649" published="2000-07-13" name="CVE-2000-0649" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by basic authentication and has no realm defined.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1499" source="BID" patch="1" adv="1">1499</ref>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0025.html" source="NTBUGTRAQ" patch="1" adv="1">20000713 IIS4 Basic authentication realm issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0650" published="2000-07-11" name="CVE-2000-0650" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The default installation of VirusScan 4.5 and NetShield 4.5 has insecure permissions for the registry key that identifies the AutoUpgrade directory, which allows local users to execute arbitrary commands by replacing SETUP.EXE in that directory with a Trojan Horse.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1458" source="BID" patch="1" adv="1">1458</ref>
      <ref url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0007&amp;L=ntbugtraq&amp;F=&amp;S=&amp;P=2753" source="NTBUGTRAQ" patch="1" adv="1">20000711 Potential Vulnerability in McAfee Netshield and VirusScan 4.5</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5177" source="XF">nai-virusscan-netshield-autoupgrade(5177)</ref>
      <ref url="http://www.osvdb.org/4200" source="OSVDB">4200</ref>
      <ref url="http://www.osvdb.org/1458" source="OSVDB">1458</ref>
    </refs>
    <vuln_soft>
      <prod vendor="network_associates" name="netshield">
        <vers num="4.5" />
      </prod>
      <prod vendor="network_associates" name="virusscan">
        <vers num="4.5" edition="" />
        <vers num="4.5" edition=":windows_nt" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0651" published="2000-07-07" name="CVE-2000-0651" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The ClientTrust program in Novell BorderManager does not properly verify the origin of authentication requests, which could allow remote attackers to impersonate another user by replaying the authentication requests and responses from port 3024 of the victim's machine.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1440" source="BID" patch="1" adv="1">1440</ref>
      <ref url="http://xforce.iss.net/static/5186.php" source="XF">novell-bordermanager-verification</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=06256915.00591E18.00@uprrsmtp2.notes.up.com" source="BUGTRAQ">20000707 Novell Border Manger - Anyone can pose as an authenticated user</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="bordermanager">
        <vers num="3.0" />
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0652" published="2000-07-24" name="CVE-2000-0652" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IBM WebSphere allows remote attackers to read source code for executable web files by directly calling the default InvokerServlet using a URL which contains the "/servlet/file" string.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1500" source="BID" patch="1" adv="1">1500</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0342.html" source="BUGTRAQ" patch="1" adv="1">20000723 IBM WebSphere default servlet handler showcode vulnerability</ref>
      <ref url="http://xforce.iss.net/static/5012.php" source="XF">websphere-showcode</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="3.0.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0653" published="2000-07-20" name="CVE-2000-0653" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Outlook Express allows remote attackers to monitor a user's email by creating a persistent browser link to the Outlook Express windows, aka the "Persistent Mail-Browser Link" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1502" source="BID" patch="1" adv="1">1502</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS00-045.asp" source="MS" patch="1" adv="1">MS00-045</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="outlook_express">
        <vers num="4.0" />
        <vers num="4.01" />
        <vers num="5.0" />
        <vers num="5.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0654" published="2000-07-11" name="CVE-2000-0654" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Microsoft Enterprise Manager allows local users to obtain database passwords via the Data Transformation Service (DTS) package Registered Servers Dialog dialog, aka a variant of the "DTS Password" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4582.php" source="XF" patch="1" adv="1">mssql-dts-reveal-passwords</ref>
      <ref url="http://www.securityfocus.com/bid/1466" source="BID" patch="1" adv="1">1466</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-041.asp" source="MS" patch="1" adv="1">MS00-041</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="sql_server">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0655" published="2000-07-25" name="CVE-2000-0655" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Netscape Communicator 4.73 and earlier allows remote attackers to cause a denial of service or execute arbitrary commands via a JPEG image containing a comment with an illegal field length of 1.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D200007242356.DAA01274%40false.com" source="BUGTRAQ" patch="1" adv="1">20000724 JPEG COM Marker Processing Vulnerability in Netscape Browsers</ref>
      <ref url="http://www.turbolinux.com/pipermail/tl-security-announce/2000-August/000016.html" source="TURBO">TLSA2000017-1</ref>
      <ref url="http://www.securityfocus.com/bid/1503" source="BID">1503</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-046.html" source="REDHAT">RHSA-2000:046</ref>
      <ref url="http://www.novell.com/linux/security/advisories/suse_security_announce_60.html" source="SUSE">20000823 Security Hole in Netscape, Versions 4.x, possibly others</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0116.html" source="BUGTRAQ">20000810 Conectiva Linux Security Announcement - netscape</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0456.html" source="BUGTRAQ">20000801 MDKSA-2000:027-1 netscape update</ref>
      <ref url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-011.txt.asc" source="NETBSD">NetBSD-SA2000-011</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:39.netscape.asc" source="FREEBSD">FreeBSD-SA-00:39</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="mozilla">
        <vers num="m15" />
      </prod>
      <prod vendor="netscape" name="communicator">
        <vers num="4.0" />
        <vers num="4.05" />
        <vers num="4.06" />
        <vers num="4.07" />
        <vers num="4.08" />
        <vers num="4.5" />
        <vers num="4.51" />
        <vers num="4.5_beta" />
        <vers num="4.6" />
        <vers num="4.61" />
        <vers num="4.7" />
        <vers num="4.72" />
        <vers num="4.73" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0656" published="2000-07-25" name="CVE-2000-0656" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long USER command in the FTP protocol.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1504" source="BID" patch="1" adv="1">1504</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0360.html" source="BUGTRAQ" patch="1" adv="1">20000724 AnalogX Proxy DoS</ref>
      <ref url="http://www.analogx.com/contents/download/network/proxy.htm" source="CONFIRM">http://www.analogx.com/contents/download/network/proxy.htm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="analogx" name="proxy">
        <vers num="4.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0657" published="2000-07-25" name="CVE-2000-0657" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long HELO command in the SMTP protocol.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1504" source="BID" patch="1" adv="1">1504</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0360.html" source="BUGTRAQ" patch="1" adv="1">20000724 AnalogX Proxy DoS</ref>
      <ref url="http://www.analogx.com/contents/download/network/proxy.htm" source="CONFIRM">http://www.analogx.com/contents/download/network/proxy.htm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="analogx" name="proxy">
        <vers num="4.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0658" published="2000-07-25" name="CVE-2000-0658" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long USER command in the POP3 protocol.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1504" source="BID" patch="1" adv="1">1504</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0360.html" source="BUGTRAQ" patch="1" adv="1">20000724 AnalogX Proxy DoS</ref>
      <ref url="http://www.analogx.com/contents/download/network/proxy.htm" source="CONFIRM">http://www.analogx.com/contents/download/network/proxy.htm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="analogx" name="proxy">
        <vers num="4.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0659" published="2000-07-25" name="CVE-2000-0659" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long user ID in a SOCKS4 CONNECT request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1504" source="BID" patch="1" adv="1">1504</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0360.html" source="BUGTRAQ" patch="1" adv="1">20000724 AnalogX Proxy DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="analogx" name="proxy">
        <vers num="4.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0660" published="2000-07-12" name="CVE-2000-0660" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The WDaemon web server for WorldClient 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0173.html" source="BUGTRAQ" patch="1" adv="1">20000712 Infosec.20000712.worldclient.2.1</ref>
      <ref url="http://xforce.iss.net/static/4913.php" source="XF" adv="1">worldclient-dir-traverse</ref>
      <ref url="http://www.securityfocus.com/bid/1462" source="BID" adv="1">1462</ref>
      <ref url="http://www.altn.com/Downloads/WorldClient/Release/RelNotes.txt" source="CONFIRM">http://www.altn.com/Downloads/WorldClient/Release/RelNotes.txt</ref>
      <ref url="http://www.osvdb.org/1459" source="OSVDB">1459</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alt-n" name="worldclient">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":standard" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0661" published="2000-07-10" name="CVE-2000-0661" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WircSrv IRC Server 5.07s allows remote attackers to cause a denial of service via a long string to the server port.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4914.php" source="XF" adv="1">wircsrv-character-flood-dos</ref>
      <ref url="http://www.securityfocus.com/bid/1448" source="BID" adv="1">1448</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0120.html" source="BUGTRAQ" adv="1">20000710 Remote DoS Attack in WircSrv Irc Server v5.07s Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wircsrv" name="irc_server">
        <vers num="5.0.7s" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0662" published="2000-07-14" name="CVE-2000-0662" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Internet Explorer 5.x and Microsoft Outlook allows remote attackers to read arbitrary files by redirecting the contents of an IFRAME using the DHTML Edit Control (DHTMLED).</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=396EF9D5.62EEC625@nat.bg" source="BUGTRAQ" adv="1">20000714 IE 5.5 and 5.01 vulnerability - reading at least local and from any host text and parsed html files</ref>
      <ref url="http://xforce.iss.net/static/5107.php" source="XF">ie-dhtmled-file-read(5107)</ref>
      <ref url="http://www.securityfocus.com/bid/1474" source="BID">1474</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" />
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0663" published="2000-07-25" name="CVE-2000-0663" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The registry entry for the Windows Shell executable (Explorer.exe) in Windows NT and Windows 2000 uses a relative path name, which allows local users to execute arbitrary commands by inserting a Trojan Horse named Explorer.exe into the %Systemdrive% directory, aka the "Relative Shell Path" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5040.php" source="XF" patch="1" adv="1">explorer-relative-path-name</ref>
      <ref url="http://www.securityfocus.com/bid/1507" source="BID" patch="1" adv="1">1507</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS00-052.asp" source="MS" patch="1" adv="1">MS00-052</ref>
      <ref url="http://www.microsoft.com/technet/support/kb.asp?ID=269049" source="MSKB">Q269049</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0664" published="2000-07-26" name="CVE-2000-0664" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">AnalogX SimpleServer:WWW 1.06 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack that uses the %2E URL encoding for the dots.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0374.html" source="BUGTRAQ" patch="1" adv="1">20000726 AnalogX "SimpleServer:WWW" dot dot bug</ref>
      <ref url="http://www.analogx.com/contents/download/network/sswww.htm" source="CONFIRM">http://www.analogx.com/contents/download/network/sswww.htm</ref>
      <ref url="http://xforce.iss.net/static/4999.php" source="XF">analogx-simpleserver-directory-path</ref>
      <ref url="http://www.securityfocus.com/bid/1508" source="BID">1508</ref>
      <ref url="http://www.osvdb.org/388" source="OSVDB">388</ref>
    </refs>
    <vuln_soft>
      <prod vendor="analogx" name="simpleserver_www">
        <vers num="1.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0665" published="2000-07-17" name="CVE-2000-0665" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">GAMSoft TelSrv telnet server 1.5 and earlier allows remote attackers to cause a denial of service via a long username.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0031.html" source="NTBUGTRAQ" patch="1" adv="1">20000717 DoS in Gamsoft TelSrv telnet server for MS Windows 95/98/NT/2k.</ref>
      <ref url="http://xforce.iss.net/static/4945.php" source="XF" adv="1">gamsoft-telsrv-dos</ref>
      <ref url="http://www.securityfocus.com/bid/1478" source="BID" adv="1">1478</ref>
      <ref url="http://www.osvdb.org/373" source="OSVDB">373</ref>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0056.html" source="NTBUGTRAQ">20000729 TelSrv Reveals Usernames &amp; Passwords After DoS Attack</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gamsoft" name="telsrv">
        <vers num="1.4" />
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0666" published="2000-07-16" name="CVE-2000-0666" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">rpc.statd in the nfs-utils package in various Linux distributions does not properly cleanse untrusted format strings, which allows remote attackers to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2000-17.html" source="CERT">CA-2000-17</ref>
      <ref url="http://xforce.iss.net/static/4939.php" source="XF" patch="1" adv="1">linux-rpcstatd-format-overwrite</ref>
      <ref url="http://www.securityfocus.com/bid/1480" source="BID" patch="1" adv="1">1480</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0206.html" source="BUGTRAQ" patch="1" adv="1">20000716 Lots and lots of fun with rpc.statd</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-043.html" source="REDHAT">RHSA-2000:043</ref>
      <ref url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-025.0.txt" source="CALDERA">CSSA-2000-025.0</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0260.html" source="BUGTRAQ">20000718 [Security Announce] MDKSA-2000:021 nfs-utils update</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0236.html" source="BUGTRAQ">20000718 Trustix Security Advisory - nfs-utils</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0230.html" source="BUGTRAQ">20000717 CONECTIVA LINUX SECURITY ANNOUNCEMENT - nfs-utils</ref>
    </refs>
    <vuln_soft>
      <prod vendor="conectiva" name="linux">
        <vers num="4.0" />
        <vers num="4.0es" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.2" edition="" />
        <vers num="2.2" edition=":powerpc" />
        <vers num="2.2" edition=":alpha" />
        <vers num="2.2" edition=":sparc" />
        <vers num="2.3" edition="" />
        <vers num="2.3" edition=":powerpc" />
        <vers num="2.3" edition=":sparc" />
        <vers num="2.3" edition=":alpha" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":i386" />
        <vers num="6.0" edition=":sparc" />
        <vers num="6.0" edition=":alpha" />
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":i386" />
        <vers num="6.1" edition=":alpha" />
        <vers num="6.1" edition=":sparc" />
        <vers num="6.2" edition="" />
        <vers num="6.2" edition=":sparc" />
        <vers num="6.2" edition=":alpha" />
        <vers num="6.2" edition=":i386" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="6.3" edition="" />
        <vers num="6.3" edition=":ppc" />
        <vers num="6.3" edition="alpha" />
        <vers num="6.4" edition="" />
        <vers num="6.4" edition=":ppc" />
        <vers num="6.4" edition="alpha" />
        <vers num="7.0" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="1.0" />
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0667" published="2000-07-27" name="CVE-2000-0667" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Vulnerability in gpm in Caldera Linux allows local users to delete arbitrary files or conduct a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1512" source="BID" patch="1" adv="1">1512</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0273.html" source="CALDERA" patch="1" adv="1">CSSA-2000-024.0 </ref>
    </refs>
    <vuln_soft>
      <prod vendor="conectiva" name="linux">
        <vers num="4.0" />
        <vers num="4.0es" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0668" published="2000-07-27" name="CVE-2000-0668" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">pam_console PAM module in Linux systems allows a user to access the system console and reboot the system when a display manager such as gdm or kdm has XDMCP enabled.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5001.php" source="XF" patch="1" adv="1">linux-pam-console</ref>
      <ref url="http://www.securityfocus.com/bid/1513" source="BID" patch="1" adv="1">1513</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-044.html" source="REDHAT">RHSA-2000:044</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0455.html" source="BUGTRAQ">20000801 MDKSA-2000:029 pam update</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0398.html" source="BUGTRAQ">20000727 CONECTIVA LINUX SECURITY ANNOUNCEMENT - PAM</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michael_k._johnson" name="pam_console">
        <vers num="0.66" />
        <vers num="0.72_unpatched" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="4.0" />
        <vers num="4.0es" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":i386" />
        <vers num="6.0" edition=":alpha" />
        <vers num="6.0" edition=":sparc" />
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":i386" />
        <vers num="6.1" edition=":alpha" />
        <vers num="6.1" edition=":sparc" />
        <vers num="6.2" edition="" />
        <vers num="6.2" edition=":alpha" />
        <vers num="6.2" edition=":sparc" />
        <vers num="6.2" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0669" published="2000-07-11" name="CVE-2000-0669" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Novell NetWare 5.0 allows remote attackers to cause a denial of service by flooding port 40193 with random data.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=000501bfeab5$9330c3d0$d801a8c0@dimuthu.baysidegrp.com.au" source="BUGTRAQ" adv="1">20000711 Remote Denial Of Service -- NetWare 5.0 with SP 5</ref>
      <ref url="http://www.securityfocus.com/bid/1467" source="BID" adv="1">1467</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="netware">
        <vers num="5.0" edition="sp5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0670" published="2000-07-12" name="CVE-2000-0670" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The cvsweb CGI script in CVSWeb 1.80 allows remote attackers with write access to a CVS repository to execute arbitrary commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4925.php" source="XF" patch="1" adv="1">cvsweb-shell-access</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0196.html" source="BUGTRAQ" patch="1" adv="1">20000714 MDKSA-2000:019 cvsweb update</ref>
      <ref url="http://www.turbolinux.com/pipermail/tl-security-announce/2000-August/000015.html" source="TURBO">TLSA2000016-1</ref>
      <ref url="http://www.securityfocus.com/bid/1469" source="BID">1469</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0178.html" source="BUGTRAQ">20000712 cvsweb: remote shell for cvs committers</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:37.cvsweb.asc" source="FREEBSD">FreeBSD-SA-00:37</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cvsweb_developer" name="cvsweb">
        <vers num="1.80" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0671" published="2000-07-21" name="CVE-2000-0671" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Roxen web server earlier than 2.0.69 allows allows remote attackers to bypass access restrictions, list directory contents, and read source code by inserting a null character (%00) to the URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0321.html" source="BUGTRAQ" patch="1" adv="1">20000721 Roxen security alert: Problems with URLs containing null characters.</ref>
      <ref url="http://xforce.iss.net/static/4965.php" source="XF">roxen-null-char-url</ref>
      <ref url="http://www.securityfocus.com/bid/1510" source="BID">1510</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0307.html" source="BUGTRAQ">20000721 Roxen Web Server Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="roxen" name="webserver">
        <vers num="2.0.x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0672" published="2000-07-20" name="CVE-2000-0672" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The default configuration of Jakarta Tomcat does not restrict access to the /admin context, which allows remote attackers to read arbitrary files by directly calling the administrative servlets to add a context for the root directory.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0309.html" source="BUGTRAQ" patch="1" adv="1">20000721 Jakarta-tomcat.../admin</ref>
      <ref url="http://xforce.iss.net/static/5160.php" source="XF">jakarta-tomcat-admin</ref>
      <ref url="http://www.securityfocus.com/bid/1548" source="BID">1548</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="3.1" />
      </prod>
      <prod vendor="apache" name="tomcat">
        <vers num="3.0" />
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0673" published="2000-07-27" name="CVE-2000-0673" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The NetBIOS Name Server (NBNS) protocol does not perform authentication, which allows remote attackers to cause a denial of service by sending a spoofed Name Conflict or Name Release datagram, aka the "NetBIOS Name Server Protocol Spoofing" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5035.php" source="XF" patch="1" adv="1">netbios-name-server-spoofing</ref>
      <ref url="http://www.securityfocus.com/bid/1514" source="BID" patch="1" adv="1">1514</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS00-047.asp" source="MS" patch="1" adv="1">MS00-047</ref>
      <ref url="http://www.securityfocus.com/bid/1515" source="BID">1515</ref>
      <ref url="http://www.nai.com/research/covert/advisories/044.asp" source="NAI">20000727 Windows NetBIOS Name Conflicts</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
        <vers num="terminal_server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0674" published="2000-07-12" name="CVE-2000-0674" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ftp.pl CGI program for Virtual Visions FTP browser allows remote attackers to read directories outside of the document root via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1471" source="BID" patch="1" adv="1">1471</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0177.html" source="BUGTRAQ" adv="1">20000712 ftp.pl vulnerability</ref>
      <ref url="http://xforce.iss.net/static/5187.php" source="XF">virtualvision-ftp-browser</ref>
    </refs>
    <vuln_soft>
      <prod vendor="virtual_vision" name="ftp_browser">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0675" published="2000-07-13" name="CVE-2000-0675" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Infopulse Gatekeeper 3.5 and earlier allows remote attackers to execute arbitrary commands via a long string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4948.php" source="XF" patch="1" adv="1">gatekeeper-long-string-bo</ref>
      <ref url="http://www.securityfocus.com/bid/1477" source="BID" patch="1" adv="1">1477</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=00af01bfece2$a52cbd80$367e1ec4@kungphusion" source="BUGTRAQ" adv="1">20000713 The MDMA Crew's GateKeeper Exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="infopulse" name="gatekeeper">
        <vers prev="1" num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0676" published="2000-10-20" name="CVE-2000-0676" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Netscape Communicator and Navigator 4.04 through 4.74 allows remote attackers to read arbitrary files by using a Java applet to open a connection to a URL using the "file", "http", "https", and "ftp" protocols, as demonstrated by Brown Orifice.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2000-15.html" source="CERT" patch="1" adv="1">CA-2000-15</ref>
      <ref url="http://www.securityfocus.com/bid/1546" source="BID" patch="1" adv="1">1546</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-054.html" source="REDHAT">RHSA-2000:054</ref>
      <ref url="http://www.novell.com/linux/security/advisories/suse_security_announce_60.html" source="SUSE">20000823 Security Hole in Netscape, Versions 4.x, possibly others</ref>
      <ref url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-027.1.txt" source="CALDERA">CSSA-2000-027.1</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0265.html" source="BUGTRAQ">20000821 MDKSA-2000:036 - netscape update</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0236.html" source="BUGTRAQ">20000818 Conectiva Linux Security Announcement - netscape</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0115.html" source="BUGTRAQ">20000810 MDKSA-2000:033 Netscape Java vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0019.html" source="BUGTRAQ">20000804 Dangerous Java/Netscape Security Hole</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:39.netscape.asc" source="FREEBSD">FreeBSD-SA-00:39</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="communicator">
        <vers num="4.0" />
        <vers num="4.04" />
        <vers num="4.05" />
        <vers num="4.06" />
        <vers num="4.07" />
        <vers num="4.08" />
        <vers num="4.5" />
        <vers num="4.51" />
        <vers num="4.5_beta" />
        <vers num="4.6" />
        <vers num="4.61" />
        <vers num="4.72" />
        <vers num="4.73" />
        <vers num="4.74" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0677" published="2000-10-20" name="CVE-2000-0677" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in IBM Net.Data db2www CGI program allows remote attackers to execute arbitrary commands via a long PATH_INFO environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/alerts/advise60.php" source="ISS" adv="1">20000907 Buffer Overflow in IBM Net.Data db2www CGI program.</ref>
      <ref url="http://xforce.iss.net/static/4976.php" source="XF">ibm-netdata-db2www-bo</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="net.data">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0678" published="2000-10-20" name="CVE-2000-0678" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PGP 5.5.x through 6.5.3 does not properly check if an Additional Decryption Key (ADK) is stored in the signed portion of a public certificate, which allows an attacker who can modify a victim's public certificate to decrypt any data that has been encrypted with the modified certificate.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2000-18.html" source="CERT" adv="1">CA-2000-18</ref>
      <ref url="http://www.securityfocus.com/bid/1606" source="BID" patch="1" adv="1">1606</ref>
      <ref url="http://www.osvdb.org/4354" source="OSVDB">4354</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pgp" name="pgp">
        <vers num="5.5.3i" />
        <vers num="6.5.1i" />
        <vers num="6.5.3i" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0679" published="2000-10-20" name="CVE-2000-0679" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The CVS 1.10.8 client trusts pathnames that are provided by the CVS server, which allows the server to force the client to create arbitrary files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3Dhvou2daoebb.fsf%40serein.m17n.org" source="BUGTRAQ" adv="1">20000728 cvs security problem</ref>
      <ref url="http://www.securityfocus.com/bid/1523" source="BID" adv="1">1523</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cvs" name="cvs">
        <vers num="1.10.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0680" published="2000-10-20" name="CVE-2000-0680" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The CVS 1.10.8 server does not properly restrict users from creating arbitrary Checkin.prog or Update.prog programs, which allows remote CVS committers to modify or create Trojan horse programs with the Checkin.prog or Update.prog names, then performing a CVS commit action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1524" source="BID" patch="1" adv="1">1524</ref>
      <ref url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3Dhvou2daoebb.fsf%40serein.m17n.org" source="BUGTRAQ" adv="1">20000728 cvs security problem</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cvs" name="cvs">
        <vers num="1.10.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0681" published="2000-10-20" name="CVE-2000-0681" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in BEA WebLogic server proxy plugin allows remote attackers to execute arbitrary commands via a long URL with a .JSP extension.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1570" source="BID" patch="1" adv="1">1570</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0186.html" source="BUGTRAQ" patch="1" adv="1">20000815 BEA Weblogic server proxy library vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers prev="1" num="4.5.2" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0682" published="2000-10-20" name="CVE-2000-0682" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BEA WebLogic 5.1.x allows remote attackers to read source code for parsed pages by inserting /ConsoleHelp/ into the URL, which invokes the FileServlet.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1518" source="BID" patch="1" adv="1">1518</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0410.html" source="BUGTRAQ" patch="1" adv="1">20000728 BEA's WebLogic force handlers show code vulnerability</ref>
      <ref url="http://www.osvdb.org/1481" source="OSVDB">1481</ref>
      <ref url="http://developer.bea.com/alerts/security_000731.html" source="CONFIRM">http://developer.bea.com/alerts/security_000731.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="5.1" edition="" />
        <vers num="5.1" edition=":enterprise" />
        <vers num="5.1" edition=":express" />
        <vers num="5.1" edition="sp1" />
        <vers num="5.1" edition="sp1:express" />
        <vers num="5.1" edition="sp10" />
        <vers num="5.1" edition="sp10:express" />
        <vers num="5.1" edition="sp11" />
        <vers num="5.1" edition="sp11:express" />
        <vers num="5.1" edition="sp12" />
        <vers num="5.1" edition="sp12:express" />
        <vers num="5.1" edition="sp2" />
        <vers num="5.1" edition="sp2:express" />
        <vers num="5.1" edition="sp3" />
        <vers num="5.1" edition="sp3:express" />
        <vers num="5.1" edition="sp4" />
        <vers num="5.1" edition="sp4:express" />
        <vers num="5.1" edition="sp5" />
        <vers num="5.1" edition="sp5:express" />
        <vers num="5.1" edition="sp6" />
        <vers num="5.1" edition="sp6:express" />
        <vers num="5.1" edition="sp7" />
        <vers num="5.1" edition="sp7:express" />
        <vers num="5.1" edition="sp8" />
        <vers num="5.1" edition="sp8:express" />
        <vers num="5.1" edition="sp9" />
        <vers num="5.1" edition="sp9:express" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0683" published="2000-10-20" name="CVE-2000-0683" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BEA WebLogic 5.1.x allows remote attackers to read source code for parsed pages by inserting /*.shtml/ into the URL, which invokes the SSIServlet.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1517" source="BID" patch="1" adv="1">1517</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0410.html" source="BUGTRAQ" patch="1" adv="1">20000728 BEA's WebLogic force handlers show code vulnerability</ref>
      <ref url="http://www.osvdb.org/1480" source="OSVDB">1480</ref>
      <ref url="http://developer.bea.com/alerts/security_000728.html" source="CONFIRM">http://developer.bea.com/alerts/security_000728.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="5.1" edition="" />
        <vers num="5.1" edition=":enterprise" />
        <vers num="5.1" edition=":express" />
        <vers num="5.1" edition="sp1" />
        <vers num="5.1" edition="sp1:express" />
        <vers num="5.1" edition="sp10" />
        <vers num="5.1" edition="sp10:express" />
        <vers num="5.1" edition="sp11" />
        <vers num="5.1" edition="sp11:express" />
        <vers num="5.1" edition="sp12" />
        <vers num="5.1" edition="sp12:express" />
        <vers num="5.1" edition="sp2" />
        <vers num="5.1" edition="sp2:express" />
        <vers num="5.1" edition="sp3" />
        <vers num="5.1" edition="sp3:express" />
        <vers num="5.1" edition="sp4" />
        <vers num="5.1" edition="sp4:express" />
        <vers num="5.1" edition="sp5" />
        <vers num="5.1" edition="sp5:express" />
        <vers num="5.1" edition="sp6" />
        <vers num="5.1" edition="sp6:express" />
        <vers num="5.1" edition="sp7" />
        <vers num="5.1" edition="sp7:express" />
        <vers num="5.1" edition="sp8" />
        <vers num="5.1" edition="sp8:express" />
        <vers num="5.1" edition="sp9" />
        <vers num="5.1" edition="sp9:express" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0684" published="2000-10-20" name="CVE-2000-0684" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP code by directly invoking the servlet on any source file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1525" source="BID" patch="1" adv="1">1525</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0434.html" source="BUGTRAQ" patch="1" adv="1">20000731 BEA's WebLogic *.jsp/*.jhtml remote command execution</ref>
      <ref url="http://developer.bea.com/alerts/security_000731.html" source="CONFIRM">http://developer.bea.com/alerts/security_000731.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="3.1.8" />
        <vers num="4.0.4" />
        <vers num="4.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0685" published="2000-10-20" name="CVE-2000-0685" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">BEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to compile and execute Java JHTML code by directly invoking the servlet on any source file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1525" source="BID" patch="1" adv="1">1525</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0434.html" source="BUGTRAQ" patch="1" adv="1">20000731 BEA's WebLogic *.jsp/*.jhtml remote command execution</ref>
      <ref url="http://developer.bea.com/alerts/security_000731.html" source="CONFIRM">http://developer.bea.com/alerts/security_000731.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="3.1.8" />
        <vers num="4.0.4" />
        <vers num="4.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0686" published="2000-10-20" name="CVE-2000-0686" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Auction Weaver CGI script 1.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack in the fromfile parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1630" source="BID" adv="1">1630</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0310.html" source="BUGTRAQ" adv="1">20000823 Auction WeaverT LITE 1.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cgi_script_center" name="auction_weaver">
        <vers prev="1" num="1.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0687" published="2000-10-20" name="CVE-2000-0687" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Auction Weaver CGI script 1.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack in the catdir parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1630" source="BID" adv="1">1630</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0310.html" source="BUGTRAQ" adv="1">20000823 Auction WeaverT LITE 1.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cgi_script_center" name="auction_weaver">
        <vers prev="1" num="1.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0688" published="2000-10-20" name="CVE-2000-0688" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Subscribe Me LITE does not properly authenticate attempts to change the administrator password, which allows remote attackers to gain privileges for the Account Manager by directly calling the subscribe.pl script with the setpwd parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1607" source="BID" patch="1" adv="1">1607</ref>
      <ref url="http://www.cgiscriptcenter.com/subscribe/" source="CONFIRM">http://www.cgiscriptcenter.com/subscribe/</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0292.html" source="BUGTRAQ" adv="1">20000823 Subscribe Me Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96722957421029&amp;w=2" source="BUGTRAQ">20000823 Re: Subscribe Me CGI Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cgi_script_center" name="subscribe_me_lite">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0689" published="2000-10-20" name="CVE-2000-0689" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Account Manager LITE does not properly authenticate attempts to change the administrator password, which allows remote attackers to gain privileges for the Account Manager by directly calling the amadmin.pl script with the setpasswd parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1604" source="BID" patch="1" adv="1">1604</ref>
      <ref url="http://www.cgiscriptcenter.com/acctlite/" source="CONFIRM">http://www.cgiscriptcenter.com/acctlite/</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0291.html" source="BUGTRAQ" adv="1">20000823 Account Manager CGI Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5125" source="XF">account-manager-overwrite-password(5125)</ref>
      <ref url="http://www.osvdb.org/13341" source="OSVDB">13341</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cgi_script_center" name="account_manager">
        <vers num="lite_1.0" />
        <vers num="pro_1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0690" published="2000-10-20" name="CVE-2000-0690" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Auction Weaver CGI script 1.02 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the fromfile parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0452.html" source="BUGTRAQ" adv="1">20000830 More problems with Auction Weaver &amp; CGI Script Center.</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0370.html" source="BUGTRAQ" adv="1">20000830 More problems with Auction Weaver &amp; CGI Script Center.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cgi_script_center" name="auction_weaver">
        <vers num="1.0" />
        <vers num="1.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0691" published="2000-10-20" name="CVE-2000-0691" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The faxrunq and faxrunqd in the mgetty package allows local users to create or modify arbitrary files via a symlink attack which creates a symlink in from /var/spool/fax/outgoing/.last_run to the target file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1612" source="BID" patch="1" adv="1">1612</ref>
      <ref url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-029.0.txt" source="CALDERA" patch="1" adv="1">CSSA-2000-029.0</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0330.html" source="CONFIRM">http://archives.neohapsis.com/archives/bugtraq/2000-08/0330.html</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0329.html" source="BUGTRAQ" adv="1">20000826 Advisory: mgetty local compromise</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gert_doering" name="mgetty">
        <vers num="1.1.19" />
        <vers num="1.1.20" />
        <vers num="1.1.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0692" published="2000-10-20" name="CVE-2000-0692" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ISS RealSecure 3.2.1 and 3.2.2 allows remote attackers to cause a denial of service via a flood of fragmented packets with the SYN flag set.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0267.html" source="BUGTRAQ" patch="1" adv="1">20000822 DOS on RealSecure 3.2</ref>
      <ref url="http://www.securityfocus.com/bid/1597" source="BID" adv="1">1597</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iss" name="realsecure">
        <vers num="3.2.1" />
        <vers num="3.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0693" published="2000-10-20" name="CVE-2000-0693" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">pgxconfig in the Raptor GFX configuration tool uses a relative path name for a system call to the "cp" program, which allows local users to execute arbitrary commands by modifying their path to point to an alternate "cp" program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1563" source="BID" patch="1" adv="1">1563</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0463.html" source="BUGTRAQ" adv="1">20000802 Local root compromise in PGX Config Sun Sparc Solaris</ref>
      <ref url="http://www.osvdb.org/1501" source="OSVDB">1501</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tech-source" name="raptor_gfx_pgx32">
        <vers num="2.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0694" published="2000-10-20" name="CVE-2000-0694" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">pgxconfig in the Raptor GFX configuration tool allows local users to gain privileges via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0463.html" source="BUGTRAQ" adv="1">20000802 Local root compromise in PGX Config Sun Sparc Solaris</ref>
      <ref url="http://www.osvdb.org/5740" source="OSVDB">5740</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tech-source" name="raptor_gfx_pgx32">
        <vers num="2.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0695" published="2000-10-20" name="CVE-2000-0695" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflows in pgxconfig in the Raptor GFX configuration tool allow local users to gain privileges via command line options.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0463.html" source="BUGTRAQ" adv="1">20000802 Local root compromise in PGX Config Sun Sparc Solaris</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tech-source" name="raptor_gfx_pgx32">
        <vers num="2.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0696" published="2000-10-20" name="CVE-2000-0696" modified="2008-09-24" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The administration interface for the dwhttpd web server in Solaris AnswerBook2 does not properly authenticate requests to its supporting CGI scripts, which allows remote attackers to add user accounts to the interface by directly calling the admin CGI script.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1554" source="BID" patch="1" adv="1">1554</ref>
      <ref url="http://archives.neohapsis.com/archives/sun/2000-q3/0001.html" source="SUN" patch="1" adv="1">00196</ref>
      <ref url="http://xforce.iss.net/static/5069.php" source="XF">solaris-answerbook2-admin-interface(5069)</ref>
      <ref url="http://www.s21sec.com/en/avisos/s21sec-004-en.txt" source="MISC">http://www.s21sec.com/en/avisos/s21sec-004-en.txt</ref>
      <ref url="http://seclists.org/bugtraq/2000/Aug/0105.html" source="BUGTRAQ">20000807 Vulnerabilities in Sun Solaris AnswerBook2 dwhttpd server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris_answerbook2">
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0697" published="2000-10-20" name="CVE-2000-0697" modified="2008-09-24" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The administration interface for the dwhttpd web server in Solaris AnswerBook2 allows interface users to remotely execute commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1556" source="BID" patch="1" adv="1">1556</ref>
      <ref url="http://archives.neohapsis.com/archives/sun/2000-q3/0001.html" source="SUN" patch="1" adv="1">00196</ref>
      <ref url="http://www.s21sec.com/en/avisos/s21sec-004-en.txt" source="MISC">http://www.s21sec.com/en/avisos/s21sec-004-en.txt</ref>
      <ref url="http://www.iss.net/security_center/static/5058.php" source="XF">solaris-answerbook2-remote-execution(5058)</ref>
      <ref url="http://seclists.org/bugtraq/2000/Aug/0105.html" source="BUGTRAQ">20000807 Vulnerabilities in Sun Solaris AnswerBook2 dwhttpd server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris_answerbook2">
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0698" published="2000-10-20" name="CVE-2000-0698" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Minicom 1.82.1 and earlier on some Linux systems allows local users to create arbitrary files owned by the uucp user via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1599" source="BID" adv="1">1599</ref>
      <ref url="http://www.securityfocus.com/archive/1/77361" source="BUGTRAQ" adv="1">20000819 RH 6.1 / 6.2 minicom vulnerability</ref>
      <ref url="http://xforce.iss.net/static/5151.php" source="XF">minicom-capture-groupown</ref>
    </refs>
    <vuln_soft>
      <prod vendor="minicom" name="minicom">
        <vers num="1.82.0" />
        <vers num="1.82.1" />
        <vers num="1.83.0" />
        <vers num="1.83.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0699" published="2000-10-20" name="CVE-2000-0699" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in ftpd in HP-UX 10.20 allows remote attackers to cause a denial of service or execute arbitrary commands via format strings in the PASS command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1560" source="BID" adv="1">1560</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0028.html" source="BUGTRAQ" adv="1">20000806 HPUX FTPd vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.20" />
        <vers num="11.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0700" published="2000-10-20" name="CVE-2000-0700" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco Gigabit Switch Routers (GSR) with Fast Ethernet / Gigabit Ethernet cards, from IOS versions 11.2(15)GS1A up to 11.2(19)GS0.2 and some versions of 12.0, do not properly handle line card failures, which allows remote attackers to bypass ACLs or force the interface to stop forwarding packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1541" source="BID" patch="1" adv="1">1541</ref>
      <ref url="http://www.cisco.com/warp/public/707/gsraclbypassdos-pub.shtml" source="CISCO" patch="1" adv="1">20000803 Possible Access Control Bypass and Denial of Service in Gigabit Switch Routers Using Gigabit Ethernet or Fast Ethernet Cards</ref>
      <ref url="http://www.osvdb.org/798" source="OSVDB">798</ref>
      <ref url="http://www.osvdb.org/793" source="OSVDB">793</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="gigabit_switch_router_12008">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="gigabit_switch_router_12012">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="gigabit_switch_router_12016">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="ios">
        <vers num="11.2" />
        <vers num="11.2(10)" />
        <vers num="11.2(8)" />
        <vers num="11.2p" />
        <vers num="11.3" />
        <vers num="11.3(1)" />
        <vers num="12.0" />
        <vers num="12.0(1)" />
        <vers num="12.0(2)" />
        <vers num="12.0(3)" />
        <vers num="12.0(4)" />
        <vers num="12.0(5)" />
        <vers num="12.0(6)" />
        <vers num="12.0(7)t" />
        <vers num="12.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0701" published="2000-10-20" name="CVE-2000-0701" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The wrapper program in mailman 2.0beta3 and 2.0beta4 does not properly cleanse untrusted format strings, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1539" source="BID" patch="1" adv="1">1539</ref>
      <ref url="http://www.securityfocus.com/archive/1/73220" source="BUGTRAQ" patch="1" adv="1">20000801 Advisory: mailman local compromise</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0474.html" source="BUGTRAQ" patch="1" adv="1">20000802 CONECTIVA LINUX SECURITY ANNOUNCEMENT - mailman</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-030.html" source="REDHAT">RHSA-2000:030</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0479.html" source="BUGTRAQ" adv="1">20000802 MDKSA-2000:030 - Linux-Mandrake not affected by mailman problem</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000802105050.A11733@rak.isternet.sk" source="CONFIRM">http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000802105050.A11733@rak.isternet.sk</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="mailman">
        <vers num="2.0" edition="beta3" />
        <vers num="2.0" edition="beta4" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0702" published="2000-10-20" name="CVE-2000-0702" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The net.init rc script in HP-UX 11.00 (S008net.init) allows local users to overwrite arbitrary files via a symlink attack that points from /tmp/stcp.conf to the targeted file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1602" source="BID" patch="1" adv="1">1602</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0261.html" source="BUGTRAQ">20000821 [HackersLab bugpaper] HP-UX net.init rc script</ref>
      <ref url="http://xforce.iss.net/static/5131.php" source="XF">hp-netinit-symlink</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0703" published="2000-10-20" name="CVE-2000-0703" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">suidperl (aka sperl) does not properly cleanse the escape sequence "~!" before calling /bin/mail to send an error report, which allows local users to gain privileges by setting the "interactive" environmental variable and calling suidperl with a filename that contains the escape sequence.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1547" source="BID" patch="1" adv="1">1547</ref>
      <ref url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-026.0.txt" source="CALDERA" patch="1" adv="1">CSSA-2000-026.0</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0022.html" source="BUGTRAQ" adv="1">20000805 sperl 5.00503 (and newer ;) exploit</ref>
      <ref url="http://www.turbolinux.com/pipermail/tl-security-announce/2000-August/000017.html" source="TURBO">TLSA2000018-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-048.html" source="REDHAT">RHSA-2000:048</ref>
      <ref url="http://www.novell.com/linux/security/advisories/suse_security_announce_59.html" source="SUSE">20000810 Security Hole in perl, all versions</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0153.html" source="BUGTRAQ">20000814 Trustix Security Advisory - perl and mailx</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0113.html" source="BUGTRAQ">20000810 Conectiva Linux security announcemente - PERL</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0086.html" source="BUGTRAQ">20000808 MDKSA-2000:031 perl update</ref>
    </refs>
    <vuln_soft>
      <prod vendor="larry_wall" name="perl">
        <vers num="5.4.5" />
        <vers num="5.5" />
        <vers num="5.5.3" />
        <vers num="5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0704" published="2000-10-20" name="CVE-2000-0704" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in SGI Omron WorldView Wnn allows remote attackers to execute arbitrary commands via long JS_OPEN, JS_MKDIR, or JS_FILE_INFO commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1603" source="BID" adv="1">1603</ref>
      <ref url="ftp://sgigate.sgi.com/security/20000803-01-A" source="SGI">20000803-01-A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5163" source="XF">irix-worldview-wnn-bo(5163)</ref>
      <ref url="http://www.osvdb.org/11080" source="OSVDB">11080</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freewnn" name="freewnn">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.1.1_axxx" />
      </prod>
      <prod vendor="omron" name="worldview">
        <vers num="6.5" />
      </prod>
      <prod vendor="wnn" name="wnn4">
        <vers num="4.2.2tl" />
        <vers num="4.2.5tl" />
        <vers num="4.2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0705" published="2000-10-20" name="CVE-2000-0705" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ntop running in web mode allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1550" source="BID" patch="1" adv="1">1550</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0459.html" source="BUGTRAQ">20000802 [ Hackerslab bug_paper ] ntop web mode vulnerabliity</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-049.html" source="REDHAT">RHSA-2000:049</ref>
      <ref url="http://www.osvdb.org/1496" source="OSVDB">1496</ref>
    </refs>
    <vuln_soft>
      <prod vendor="luca_deri" name="ntop">
        <vers num="1.2a7_9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0706" published="2000-10-20" name="CVE-2000-0706" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflows in ntop running in web mode allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1576" source="BID" adv="1">1576</ref>
      <ref url="http://www.debian.org/security/2000/20000830" source="DEBIAN" adv="1">20000830 ntop: Still remotely exploitable using buffer overflows</ref>
      <ref url="http://www.osvdb.org/1513" source="OSVDB">1513</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:36.ntop.asc" source="FREEBSD">FreeBSD-SA-00:36</ref>
    </refs>
    <vuln_soft>
      <prod vendor="luca_deri" name="ntop">
        <vers num="1.2a7_9" />
        <vers num="1.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0707" published="2000-10-20" name="CVE-2000-0707" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PCCS MySQLDatabase Admin Tool Manager 1.2.4 and earlier installs the file dbconnect.inc within the web root, which allows remote attackers to obtain sensitive information such as the administrative password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1557" source="BID" patch="1" adv="1">1557</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0015.html" source="BUGTRAQ" patch="1" adv="1">20000804 PCCS MySQL DB Admin Tool v1.2.3- Advisory</ref>
      <ref url="http://pccs-linux.com/public/view.php3?bn=agora_pccslinux&amp;key=965951324" source="CONFIRM">http://pccs-linux.com/public/view.php3?bn=agora_pccslinux&amp;key=965951324</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pccs-linux" name="mysqldatabase_admin_tool">
        <vers num="1.2.3" />
        <vers num="1.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0708" published="2000-10-20" name="CVE-2000-0708" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Pragma Systems TelnetServer 2000 version 4.0 allows remote attackers to cause a denial of service via a long series of null characters to the rexec port.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1605" source="BID" adv="1">1605</ref>
      <ref url="http://www.pragmasys.com/TelnetServer/" source="CONFIRM">http://www.pragmasys.com/TelnetServer/</ref>
      <ref url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0008&amp;L=NTBUGTRAQ&amp;P=R4247" source="NTBUGTRAQ" adv="1">20000824 Remote DoS Attack in Pragma TelnetServer 2000 (Remote Execute Daemon) Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pragma_systems" name="telnetserver">
        <vers num="2000" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0709" published="2000-10-20" name="CVE-2000-0709" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to cause a denial of service in some components by requesting a URL whose name includes a standard DOS device name.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1608" source="BID" patch="1" adv="1">1608</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0288.html" source="BUGTRAQ" patch="1" adv="1">20000823 Xato Advisory: FrontPage DOS Device DoS</ref>
      <ref url="http://msdn.microsoft.com/workshop/languages/fp/2000/sr12.asp" source="CONFIRM">http://msdn.microsoft.com/workshop/languages/fp/2000/sr12.asp</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="frontpage">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0710" published="2000-10-20" name="CVE-2000-0710" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers determine the physical path of the server components by requesting an invalid URL whose name includes a standard DOS device name.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1608" source="BID" patch="1" adv="1">1608</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0288.html" source="BUGTRAQ" patch="1" adv="1">20000823 Xato Advisory: FrontPage DOS Device DoS</ref>
      <ref url="http://msdn.microsoft.com/workshop/languages/fp/2000/sr12.asp" source="CONFIRM">http://msdn.microsoft.com/workshop/languages/fp/2000/sr12.asp</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="frontpage">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0711" published="2000-10-20" name="CVE-2000-0711" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Netscape Communicator does not properly prevent a ServerSocket object from being created by untrusted entities, which allows remote attackers to create a server on the victim's system via a malicious applet, as demonstrated by Brown Orifice.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2000-15.html" source="CERT" patch="1" adv="1">CA-2000-15</ref>
      <ref url="http://www.securityfocus.com/bid/1545" source="BID" patch="1" adv="1">1545</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=3999922128E.EE84TAKAGI@java-house.etl.go.jp" source="BUGTRAQ" adv="1">20000816 JDK 1.1.x Listening Socket Vulnerability (was Re: BrownOrifice can break firewalls!)</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000805020429.11774.qmail@securityfocus.com" source="BUGTRAQ" adv="1">20000805 Dangerous Java/Netscape Security Hole</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="virtual_machine">
        <vers num="2000" />
        <vers num="3100" />
        <vers num="3200" />
        <vers num="3300" />
      </prod>
      <prod vendor="netscape" name="communicator">
        <vers num="4.0" />
        <vers num="4.04" />
        <vers num="4.05" />
        <vers num="4.06" />
        <vers num="4.07" />
        <vers num="4.08" />
        <vers num="4.5" />
        <vers num="4.51" />
        <vers num="4.6" />
        <vers num="4.61" />
        <vers num="4.7" />
        <vers num="4.72" />
        <vers num="4.73" />
        <vers num="4.74" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0712" published="2000-10-20" name="CVE-2000-0712" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Linux Intrusion Detection System (LIDS) 0.9.7 allows local users to gain root privileges when LIDS is disabled via the security=0 boot option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1549" source="BID" patch="1" adv="1">1549</ref>
      <ref url="http://www.lids.org/changelog.html" source="CONFIRM">http://www.lids.org/changelog.html</ref>
      <ref url="http://www.egroups.com/message/lids/1038" source="MISC">http://www.egroups.com/message/lids/1038</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0486.html" source="BUGTRAQ" adv="1">2000803 LIDS severe bug</ref>
      <ref url="http://www.osvdb.org/1495" source="OSVDB">1495</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lids" name="lids">
        <vers num="0.9.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0713" published="2000-10-20" name="CVE-2000-0713" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Buffer overflow in Adobe Acrobat 4.05, Reader, Business Tools, and Fill In products that handle PDF files allows attackers to execute arbitrary commands via a long /Registry or /Ordering specifier.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1509" source="BID" patch="1" adv="1">1509</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0382.html" source="BUGTRAQ" patch="1" adv="1">20000726 [SPSadvisory#39]Adobe Acrobat Series PDF File Buffer Overflow</ref>
      <ref url="http://www.adobe.com/misc/pdfsecurity.html" source="CONFIRM">http://www.adobe.com/misc/pdfsecurity.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="4.0.5" />
      </prod>
      <prod vendor="adobe" name="acrobat_business_tools">
        <vers num="4.0" />
        <vers num="4.05" />
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="4.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0714" published="2000-10-20" name="CVE-2000-0714" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">umb-scheme 3.2-11 for Red Hat Linux is installed with world-writeable files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1551" source="BID" patch="1" adv="1">1551</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-047.html" source="REDHAT">RHSA-2000:047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_massachusetts" name="scheme">
        <vers num="3.2.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0715" published="2000-10-20" name="CVE-2000-0715" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">DiskCheck script diskcheck.pl in Red Hat Linux 6.2 allows local users to create or overwrite arbitrary files via a symlink attack on a temporary file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1552" source="BID" patch="1" adv="1">1552</ref>
      <ref url="http://seclists.org/bugtraq/2000/Jun/0298.html" source="BUGTRAQ">20000622 Re: rh 6.2 - gid compromises, etc [+ MORE!!!]</ref>
      <ref url="http://seclists.org/bugtraq/2000/Aug/0096.html" source="BUGTRAQ">20000807 Re: Diskcheck 3.1.1 Symlink Vulnerability</ref>
      <ref url="http://seclists.org/bugtraq/2000/Aug/0082.html" source="BUGTRAQ">20000805 Diskcheck 3.1.1 Symlink Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kirk_bauer" name="diskcheck">
        <vers num="3.1.1" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="5.0" />
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0716" published="2000-10-20" name="CVE-2000-0716" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">WorldClient email client in MDaemon 2.8 includes the session ID in the referer field of an HTTP request when the user clicks on a URL, which allows the visited web site to hijcak the session ID and read the user's email.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1553" source="BID" patch="1" adv="1">1553</ref>
      <ref url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0008&amp;L=ntbugtraq&amp;F=&amp;S=&amp;P=459" source="NTBUGTRAQ" patch="1" adv="1">20000809 Session hijacking in Alt-N's MDaemon 2.8</ref>
      <ref url="http://xforce.iss.net/static/5070.php" source="XF">mdaemon-session-id-hijack</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alt-n" name="mdaemon">
        <vers num="2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0717" published="2000-10-20" name="CVE-2000-0717" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">GoodTech FTP server allows remote attackers to cause a denial of service via a large number of RNTO commands.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=02ff01c0124c$e9387660$0201a8c0@aviram" source="BUGTRAQ" patch="1" adv="1">20000830 [EXPL] GoodTech's FTP Server vulnerable to a DoS (RNTO)</ref>
      <ref url="http://www.securityfocus.com/bid/1619" source="BID" adv="1">1619</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5166" source="XF">ftp-goodtech-rnto-dos(5166)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="goodtech" name="ftp_server_95_98">
        <vers num="3.0" />
        <vers num="3.0.1" />
      </prod>
      <prod vendor="goodtech" name="ftp_server_nt_2000">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0718" published="2000-10-20" name="CVE-2000-0718" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">A race condition in MandrakeUpdate allows local users to modify RPM files while they are in the /tmp directory before they are installed.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1567" source="BID" patch="1" adv="1">1567</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0146.html" source="BUGTRAQ" patch="1" adv="1">20000812 MDKSA-2000:034 MandrakeUpdate update</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="7.0" />
        <vers num="7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0719" published="2000-10-20" name="CVE-2000-0719" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">VariCAD 7.0 is installed with world-writeable files, which allows local users to replace the VariCAD programs with a Trojan horse program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0126.html" source="BUGTRAQ" patch="1" adv="1">20000810 VariCAD 7.0 premission vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="varicad" name="varicad">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0720" published="2000-10-20" name="CVE-2000-0720" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">news.cgi in GWScripts News Publisher does not properly authenticate requests to add an author to the author index, which allows remote attackers to add new authors by directly posting an HTTP request to the new.cgi program with an addAuthor parameter, and setting the Referer to the news.cgi program.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=003301c0123b$18f8c1a0$953b29d4@e8s9s4" source="BUGTRAQ" adv="1">20000829 News Publisher CGI Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/1621" source="BID" adv="1">1621</ref>
      <ref url="http://xforce.iss.net/static/5169.php" source="XF">news-publisher-add-author(5169)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gwscripts" name="gwscripts_news_publisher">
        <vers num="1.05" />
        <vers num="1.05a" />
        <vers num="1.05b" />
        <vers num="1.06" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0721" published="2000-10-20" name="CVE-2000-0721" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">The FSserial, FlagShip_c, and FlagShip_p programs in the FlagShip package are installed world-writeable, which allows local users to replace them with Trojan horses.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0114.html" source="BUGTRAQ" patch="1" adv="1">20000810 FlagShip v4.48.7449 premission vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/1586" source="BID" adv="1">1586</ref>
    </refs>
    <vuln_soft>
      <prod vendor="multisoft" name="flagship">
        <vers num="4.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0722" published="2000-10-20" name="CVE-2000-0722" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">Helix GNOME Updater helix-update 0.5 and earlier allows local users to install arbitrary RPM packages by creating the /tmp/helix-install installation directory before root has begun installing packages.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1593" source="BID" patch="1" adv="1">1593</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0251.html" source="BUGTRAQ" patch="1" adv="1">20000820 [Helix Beta] Helix Code Security Advisory - Helix GNOME Installer</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0240.html" source="BUGTRAQ" adv="1">20000820 Helix Code Security Advisory - Helix GNOME Update</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=E13QAYl-0007il-00@the-village.bc.nu" source="BUGTRAQ">20000819 Multiple Local Vulnerabilities in Helix Gnome Installer</ref>
    </refs>
    <vuln_soft>
      <prod vendor="helix_code" name="gnome_updater">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0723" published="2000-10-20" name="CVE-2000-0723" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">Helix GNOME Updater helix-update 0.5 and earlier does not properly create /tmp directories, which allows local users to create empty system configuration files such as /etc/config.d/bashrc, /etc/config.d/csh.cshrc, and /etc/rc.config.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1596" source="BID" patch="1" adv="1">1596</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0251.html" source="BUGTRAQ" patch="1" adv="1">20000820 [Helix Beta] Helix Code Security Advisory - Helix GNOME Installer</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=E13QAYl-0007il-00@the-village.bc.nu" source="BUGTRAQ">20000819 Multiple Local Vulnerabilities in Helix Gnome Installer</ref>
    </refs>
    <vuln_soft>
      <prod vendor="helix_code" name="gnome_installer">
        <vers num="0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0724" published="2000-10-20" name="CVE-2000-0724" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">The go-gnome Helix GNOME pre-installer allows local users to overwrite arbitrary files via a symlink attack on various files in /tmp, including uudecode, snarf, and some installer files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1622" source="BID" patch="1" adv="1">1622</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0356.html" source="BUGTRAQ" patch="1" adv="1">20000829 Helix Code Security Advisory - go-gnome pre-installer</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0351.html" source="BUGTRAQ" adv="1">20000829 More Helix Code installation problems (go-gnome)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="helix_code" name="go-gnome_pre-installer">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0725" published="2000-10-20" name="CVE-2000-0725" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Zope before 2.2.1 does not properly restrict access to the getRoles method, which allows users who can edit DTML to add or modify roles by modifying the roles list that is included in a request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1577" source="BID" patch="1" adv="1">1577</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0259.html" source="BUGTRAQ" patch="1">20000821 Conectiva Linux Security Announcement - Zope</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0198.html" source="BUGTRAQ" patch="1" adv="1">20000816 MDKSA-2000:035 Zope update</ref>
      <ref url="http://www.zope.org/Products/Zope/Hotfix_08_09_2000/security_alert" source="CONFIRM">http://www.zope.org/Products/Zope/Hotfix_08_09_2000/security_alert</ref>
      <ref url="http://www.debian.org/security/2000/20000821" source="DEBIAN" adv="1">20000821 zope: unauthorized escalation of privilege (update)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-052.html" source="REDHAT">RHSA-2000:052</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zope" name="zope">
        <vers num="1.10.3" />
        <vers num="2.1.1" />
        <vers num="2.1.7" />
        <vers num="2.2_beta1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0726" published="2000-10-20" name="CVE-2000-0726" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">CGIMail.exe CGI program in Stalkerlab Mailers 1.1.2 allows remote attackers to read arbitrary files by specifying the file in the $Attach$ hidden form variable.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000829194618.H7744@thathost.com" source="BUGTRAQ" adv="1">20000829 Stalker's CGImail Gives Read Access to All Server Files</ref>
      <ref url="http://www.securityfocus.com/bid/1623" source="BID" adv="1">1623</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5165" source="XF">mailers-cgimail-spoof(5165)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stalkerlab" name="mailers">
        <vers num="1.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0727" published="2000-10-20" name="CVE-2000-0727" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">xpdf PDF viewer client earlier than 0.91 does not properly launch a web browser for embedded URL's, which allows an attacker to execute arbitrary commands via a URL that contains shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1624" source="BID" patch="1" adv="1">1624</ref>
      <ref url="http://www.debian.org/security/2000/20000910a" source="DEBIAN" patch="1" adv="1">20000910 xpdf: local exploit</ref>
      <ref url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-031.0.txt" source="CALDERA" patch="1" adv="1">CSSA-2000-031.0</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96766355023239&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20000829 MDKSA-2000:041 - xpdf update</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-060.html" source="REDHAT">RHSA-2000:060</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96886599829687&amp;w=2" source="BUGTRAQ">20000913 Conectiva Linux Security Announcement - xpdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xpdf" name="xpdf">
        <vers num="0.90" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0728" published="2000-10-20" name="CVE-2000-0728" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">xpdf PDF viewer client earlier than 0.91 allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1624" source="BID" patch="1" adv="1">1624</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96886599829687&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20000913 Conectiva Linux Security Announcement - xpdf</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96766355023239&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20000829 MDKSA-2000:041 - xpdf update</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-060.html" source="REDHAT">RHSA-2000:060</ref>
      <ref url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-031.0.txt" source="CALDERA">CSSA-2000-031.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xpdf" name="xpdf">
        <vers num="0.90" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0729" published="2000-10-20" name="CVE-2000-0729" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">FreeBSD 5.x, 4.x, and 3.x allows local users to cause a denial of service by executing a program with a malformed ELF image header.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1625" source="BID" patch="1" adv="1">1625</ref>
      <ref url="http://archives.neohapsis.com/archives/freebsd/2000-08/0337.html" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-00:41</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5967" source="XF">freebsd-elf-dos(5967)</ref>
      <ref url="http://www.osvdb.org/1534" source="OSVDB">1534</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="3.5" />
        <vers num="4.0" edition="alpha" />
        <vers num="4.1" />
        <vers num="5.0" edition="alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0730" published="2000-10-20" name="CVE-2000-0730" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Vulnerability in newgrp command in HP-UX 11.0 allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1580" source="BID" patch="1" adv="1">1580</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0144.html" source="HP" patch="1" adv="1">HPSBUX0008-118</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0731" published="2000-10-20" name="CVE-2000-0731" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Worm HTTP server allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0111.html" source="NTBUGTRAQ" patch="1" adv="1">20000825 DST2K0023: Directory Traversal Possible &amp; Denial of Service in Wo rm HTTP Server</ref>
      <ref url="http://www.securityfocus.com/bid/1626" source="BID" adv="1">1626</ref>
      <ref url="http://xforce.iss.net/static/5148.php" source="XF">wormhttp-dir-traverse(5148)</ref>
      <ref url="http://www.osvdb.org/1535" source="OSVDB">1535</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jeremy_arnold" name="worm_webserver">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0732" published="2000-10-20" name="CVE-2000-0732" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Worm HTTP server allows remote attackers to cause a denial of service via a long URL.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0111.html" source="NTBUGTRAQ" patch="1" adv="1">20000825 DST2K0023: Directory Traversal Possible &amp; Denial of Service in Wo rm HTTP Server</ref>
      <ref url="http://www.securityfocus.com/bid/1626" source="BID" adv="1">1626</ref>
      <ref url="http://xforce.iss.net/static/5149.php" source="XF">wormhttp-filename-dos</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jeremy_arnold" name="worm_webserver">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0733" published="2000-10-20" name="CVE-2000-0733" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Telnetd telnet server in IRIX 5.2 through 6.1 does not properly cleans user-injected format strings, which allows remote attackers to execute arbitrary commands via a long RLD variable in the IAC-SB-TELOPT_ENVIRON request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0154.html" source="BUGTRAQ" patch="1" adv="1">20000814 [LSD] IRIX telnetd remote vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/1572" source="BID" adv="1">1572</ref>
      <ref url="ftp://sgigate.sgi.com/security/20000801-02-P" source="SGI">20000801-02-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="5.2" />
        <vers num="5.3" edition="" />
        <vers num="5.3" edition=":xfs" />
        <vers num="6.0" />
        <vers num="6.0.1" edition="" />
        <vers num="6.0.1" edition=":xfs" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.2m" />
        <vers num="6.5.3" />
        <vers num="6.5.3f" />
        <vers num="6.5.3m" />
        <vers num="6.5.4" />
        <vers num="6.5.6" />
        <vers num="6.5.7" />
        <vers num="6.5.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0734" published="2000-10-20" name="CVE-2000-0734" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">eEye IRIS 1.01 beta allows remote attackers to cause a denial of service via a large number of UDP connections.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1627" source="BID" patch="1" adv="1">1627</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96774637326591&amp;w=2" source="BUGTRAQ">20000831 Remote DoS Attack in Eeye Iris 1.01 and SpyNet CaptureNet v3.12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eeye_digital_security" name="iris">
        <vers num="1.0.1" />
      </prod>
      <prod vendor="spynet" name="capturenet">
        <vers num="3.0.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0735" published="2000-10-20" name="CVE-2000-0735" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Becky! Internet Mail client 1.26.03 and earlier allows remote attackers to cause a denial of service via a long Content-type: MIME header when the user replies to a message.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0234.html" source="BUGTRAQ" patch="1" adv="1">20000818 Becky! Internet Mail Buffer overflow</ref>
      <ref url="http://www.securityfocus.com/bid/1588" source="BID" adv="1">1588</ref>
      <ref url="http://member.nifty.ne.jp/rimarts/becky-e/Readme.txt" source="CONFIRM">http://member.nifty.ne.jp/rimarts/becky-e/Readme.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rimarts_inc." name="becky_internet_mail">
        <vers num="1.26.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0736" published="2000-10-20" name="CVE-2000-0736" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Becky! Internet Mail client 1.26.04 and earlier allows remote attackers to cause a denial of service via a long Content-type: MIME header when the user forwards a message.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0234.html" source="BUGTRAQ" patch="1" adv="1">20000818 Becky! Internet Mail Buffer overflow</ref>
      <ref url="http://www.securityfocus.com/bid/1588" source="BID" adv="1">1588</ref>
      <ref url="http://member.nifty.ne.jp/rimarts/becky-e/Readme.txt" source="CONFIRM">http://member.nifty.ne.jp/rimarts/becky-e/Readme.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rimarts_inc." name="becky_internet_mail">
        <vers num="1.26.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0737" published="2000-10-20" name="CVE-2000-0737" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The Service Control Manager (SCM) in Windows 2000 creates predictable named pipes, which allows a local user with console access to gain administrator privileges, aka the "Service Control Manager Named Pipe Impersonation" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1535" source="BID" patch="1" adv="1">1535</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-053.asp" source="MS" patch="1" adv="1">MS00-053</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0738" published="2000-10-20" name="CVE-2000-0738" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WebShield SMTP 4.5 allows remote attackers to cause a denial of service by sending e-mail with a From: address that has a . (period) at the end, which causes WebShield to continuously send itself copies of the e-mail.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1589" source="BID" patch="1" adv="1">1589</ref>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0101.html" source="NTBUGTRAQ" patch="1" adv="1">20000818 WebShield SMTP infinite loop DoS Attack</ref>
      <ref url="http://xforce.iss.net/static/5100.php" source="XF">webshield-smtp-dos</ref>
    </refs>
    <vuln_soft>
      <prod vendor="network_associates" name="webshield_smtp">
        <vers num="4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0739" published="2000-10-20" name="CVE-2000-0739" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to read arbitrary files via a .. (dot dot) attack in an HTTPS request to the enrollment server.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1537" source="BID" patch="1" adv="1">1537</ref>
      <ref url="http://download.nai.com/products/licensed/pgp/hf3pki10.txt" source="CONFIRM">http://download.nai.com/products/licensed/pgp/hf3pki10.txt</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0473.html" source="BUGTRAQ" adv="1">20000802 NAI Net Tools PKI Server vulnerabilities</ref>
      <ref url="http://xforce.iss.net/static/5066.php" source="XF">nettools-pki-dir-traverse(5066)</ref>
      <ref url="http://www.osvdb.org/1489" source="OSVDB">1489</ref>
    </refs>
    <vuln_soft>
      <prod vendor="network_associates" name="net_tools_pki_server">
        <vers num="1.0" />
        <vers num="1.0hotfix1" />
        <vers num="1.0hotfix2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0740" published="2000-10-20" name="CVE-2000-0740" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to execute arbitrary commands via a long URL in the HTTPS port.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1536" source="BID" patch="1" adv="1">1536</ref>
      <ref url="http://download.nai.com/products/licensed/pgp/hf3pki10.txt" source="CONFIRM">http://download.nai.com/products/licensed/pgp/hf3pki10.txt</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0473.html" source="BUGTRAQ" adv="1">20000802 NAI Net Tools PKI Server vulnerabilities</ref>
      <ref url="http://xforce.iss.net/static/5026.php" source="XF">nai-nettools-strong-bo(5026)</ref>
      <ref url="http://www.osvdb.org/1488" source="OSVDB">1488</ref>
    </refs>
    <vuln_soft>
      <prod vendor="network_associates" name="net_tools_pki_server">
        <vers num="1.0" />
        <vers num="1.0hotfix1" />
        <vers num="1.0hotfix2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0741" published="2000-10-20" name="CVE-2000-0741" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to execute arbitrary code via format strings in a URL with a .XUDA extension.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1538" source="BID" patch="1" adv="1">1538</ref>
      <ref url="http://download.nai.com/products/licensed/pgp/hf3pki10.txt" source="CONFIRM">http://download.nai.com/products/licensed/pgp/hf3pki10.txt</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0473.html" source="BUGTRAQ" adv="1">20000802 NAI Net Tools PKI Server vulnerabilities</ref>
      <ref url="http://www.osvdb.org/1490" source="OSVDB">1490</ref>
    </refs>
    <vuln_soft>
      <prod vendor="network_associates" name="net_tools_pki_server">
        <vers num="1.0" />
        <vers num="1.0hotfix1" />
        <vers num="1.0hotfix2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0742" published="2000-10-20" name="CVE-2000-0742" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The IPX protocol implementation in Microsoft Windows 95 and 98 allows remote attackers to cause a denial of service by sending a ping packet with a source IP address that is a broadcast address, aka the "Malformed IPX Ping Packet" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1544" source="BID" patch="1" adv="1">1544</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-054.asp" source="MS" patch="1" adv="1">MS00-054</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;mid=63120" source="BUGTRAQ" adv="1">20000602 ipx storm</ref>
      <ref url="http://xforce.iss.net/static/5079.php" source="XF">win-ipx-ping-packet(5079)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_95">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0743" published="2000-10-20" name="CVE-2000-0743" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in University of Minnesota (UMN) gopherd 2.x allows remote attackers to execute arbitrary commands via a DES key generation request (GDESkey) that contains a long ticket value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1569" source="BID" patch="1" adv="1">1569</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0112.html" source="BUGTRAQ" patch="1" adv="1">20000810 Remote vulnerability in Gopherd 2.x</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_minnesota" name="gopherd">
        <vers num="2.3" />
        <vers num="2.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0744" published="2000-10-20" name="CVE-2000-0744" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">DEPRECATED.  This entry has been deprecated.  It is a duplicate of CVE-2000-0743.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="university_of_minnesota" name="gopherd">
        <vers num="2.3" />
        <vers num="2.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0745" published="2000-10-20" name="CVE-2000-0745" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">admin.php3 in PHP-Nuke does not properly verify the PHP-Nuke administrator password, which allows remote attackers to gain privileges by requesting a URL that does not specify the aid or pwd parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1592" source="BID" patch="1" adv="1">1592</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0243.html" source="BUGTRAQ" patch="1" adv="1">20000821 Vuln. in all sites using PHP-Nuke, versions less than 3</ref>
      <ref url="http://www.osvdb.org/1521" source="OSVDB">1521</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="1.0" />
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0746" published="2000-10-20" name="CVE-2000-0746" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attacks.  They allow a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client.  The client then executes those scripts in the same context as the trusted site, aka the "IIS Cross-Site Scripting" vulnerabilities.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1595" source="BID" patch="1" adv="1">1595</ref>
      <ref url="http://www.securityfocus.com/bid/1594" source="BID" patch="1" adv="1">1594</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-060.asp" source="MS" patch="1" adv="1">MS00-060</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=39A12BD6.E811BF4F@nat.bg" source="BUGTRAQ">20000821 IIS 5.0 cross site scripting vulnerability - using .shtml files or /_vti_bin/shtml.dll</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="frontpage">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0747" published="2000-10-20" name="CVE-2000-0747" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The logrotate script for OpenLDAP before 1.2.11 in Conectiva Linux sends an improper signal to the kernel log daemon (klogd) and kills it.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0379.html" source="BUGTRAQ" patch="1" adv="1">20000726 CONECTIVA LINUX SECURITY ANNOUNCEMENT - OPENLDAP</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5036" source="XF" adv="1">openldap-logrotate-script-dos(5036)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="conectiva" name="linux">
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0748" published="2000-10-20" name="CVE-2000-0748" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">OpenLDAP 1.2.11 and earlier improperly installs the ud binary with group write permissions, which could allow any user in that group to replace the binary with a Trojan horse.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1511" source="BID" patch="1" adv="1">1511</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0375.html" source="BUGTRAQ" patch="1" adv="1">20000726 Group-writable executable in OpenLDAP</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openldap" name="openldap">
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0749" published="2000-10-20" name="CVE-2000-0749" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the Linux binary compatibility module in FreeBSD 3.x through 5.x allows local users to gain root privileges via long filenames in the linux shadow file system.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1628" source="BID" patch="1" adv="1">1628</ref>
      <ref url="http://archives.neohapsis.com/archives/freebsd/2000-08/0338.html" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-00:42</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5968" source="XF">freebsd-linux-module-bo(5968)</ref>
      <ref url="http://www.osvdb.org/1536" source="OSVDB">1536</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="3.5" />
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0750" published="2000-10-20" name="CVE-2000-0750" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in mopd (Maintenance Operations Protocol loader daemon) allows remote attackers to execute arbitrary commands via a long file name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1558" source="BID" patch="1" adv="1">1558</ref>
      <ref url="http://archives.neohapsis.com/archives/freebsd/2000-08/0336.html" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-00:40</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0064.html" source="BUGTRAQ" adv="1">20000808 OpenBSD 2.7 / NetBSD 1.4.2 mopd buffer overflow</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-050.html" source="REDHAT">RHSA-2000:050</ref>
      <ref url="http://www.openbsd.org/errata.html#mopd" source="OPENBSD">20000705 Mopd contained a buffer overflow.</ref>
      <ref url="http://cvsweb.netbsd.org/bsdweb.cgi/basesrc/usr.sbin/mopd/mopd/process.c.diff?r1=1.7&amp;r2=1.8&amp;f=h" source="MISC">http://cvsweb.netbsd.org/bsdweb.cgi/basesrc/usr.sbin/mopd/mopd/process.c.diff?r1=1.7&amp;r2=1.8&amp;f=h</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.4.1" />
        <vers num="1.4.2" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.6" />
        <vers num="2.7" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0751" published="2000-10-20" name="CVE-2000-0751" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">mopd (Maintenance Operations Protocol loader daemon) does not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1559" source="BID" patch="1" adv="1">1559</ref>
      <ref url="http://archives.neohapsis.com/archives/freebsd/2000-08/0336.html" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-00:40</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0064.html" source="BUGTRAQ" adv="1">20000808 OpenBSD 2.7 / NetBSD 1.4.2 mopd buffer overflow</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-050.html" source="REDHAT">RHSA-2000:050</ref>
      <ref url="http://www.openbsd.org/errata.html#mopd" source="OPENBSD">20000705 Mopd contained a buffer overflow.</ref>
      <ref url="http://cvsweb.netbsd.org/bsdweb.cgi/basesrc/usr.sbin/mopd/mopd/process.c.diff?r1=1.7&amp;r2=1.8&amp;f=h" source="MISC">http://cvsweb.netbsd.org/bsdweb.cgi/basesrc/usr.sbin/mopd/mopd/process.c.diff?r1=1.7&amp;r2=1.8&amp;f=h</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.4.1" />
        <vers num="1.4.2" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.6" />
        <vers num="2.7" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0752" published="2000-10-20" name="CVE-2000-0752" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflows in brouted in FreeBSD and possibly other OSes allows local users to gain root privileges via long command line arguments.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1629" source="BID" patch="1" adv="1">1629</ref>
      <ref url="http://archives.neohapsis.com/archives/freebsd/2000-08/0339.html" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-00:43</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.5" />
        <vers num="4.0" edition="alpha" />
        <vers num="4.1" />
        <vers num="5.0" edition="alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0753" published="2000-10-20" name="CVE-2000-0753" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Microsoft Outlook mail client identifies the physical path of the sender's machine within a winmail.dat attachment to Rich Text Format (RTF) files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1631" source="BID" patch="1" adv="1">1631</ref>
      <ref url="http://xforce.iss.net/static/5508.php" source="XF">outlook-reveal-path(5508)</ref>
      <ref url="http://www.securityfocus.com/archive/1/78240" source="BUGTRAQ">20000824 Outlook winmail.dat</ref>
      <ref url="http://www.securityfocus.com/archive/1/201422" source="BUGTRAQ">20010802 Outlook 2000 Rich Text information disclosure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="outlook">
        <vers num="2000" />
        <vers num="97" />
        <vers num="98" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0754" published="2000-10-20" name="CVE-2000-0754" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Vulnerability in HP OpenView Network Node Manager (NMM) version 6.1 related to passwords.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0144.html" source="HP" patch="1" adv="1">HPSBUX0008-119</ref>
      <ref url="http://www.securityfocus.com/bid/1581" source="BID" adv="1">1581</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0755" published="2000-10-20" name="CVE-2000-0755" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Vulnerability in the newgrp command in HP-UX 11.00 allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0144.html" source="HP" patch="1" adv="1">HPSBUX0008-118</ref>
      <ref url="http://www.securityfocus.com/bid/1581" source="BID" adv="1">1581</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0756" published="2000-10-20" name="CVE-2000-0756" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Outlook 2000 does not properly process long or malformed fields in vCard (.vcf) files, which allows attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1633" source="BID" adv="1">1633</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Springmail.105.967737080.0.16997300@www.springmail.com" source="BUGTRAQ">20000831 vCard DoS on Outlook 2000</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="outlook">
        <vers num="2000" />
        <vers num="98" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0757" published="2000-10-20" name="CVE-2000-0757" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The sysgen service in Aptis Totalbill does not perform authentication, which allows remote attackers to gain root privileges by connecting to the service and specifying the commands to be executed.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1555" source="BID" adv="1">1555</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0074.html" source="BUGTRAQ" adv="1">20000808 Exploit for Totalbill...</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aptis_software" name="totalbill">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0758" published="2000-10-20" name="CVE-2000-0758" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The web interface for Lyris List Manager 3 and 4 allows list subscribers to obtain administrative access by modifying the value of the list_admin hidden form field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1584" source="BID" patch="1" adv="1">1584</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0149.html" source="BUGTRAQ" patch="1" adv="1">20000811 Lyris List Manager Administration Hole</ref>
      <ref url="http://www.lyris.com/lm/lm_updates.html" source="CONFIRM">http://www.lyris.com/lm/lm_updates.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lyris" name="list_manager">
        <vers num="3.0" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0759" published="2000-10-20" name="CVE-2000-0759" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a URL that does not exist, which generates an error message that includes the physical path.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-07-15%26msg%3DPine.SUN.3.96.1000719184401.17782A-100000@grex.cyberspace.org" source="BUGTRAQ" adv="1">20000719 [LoWNOISE] Tomcat 3.1 Path Revealing Problem.</ref>
      <ref url="http://www.securityfocus.com/bid/1531" source="BID" adv="1">1531</ref>
      <ref url="http://www.iss.net/security_center/static/4967.php" source="XF">tomcat-error-path-reveal(4967)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="tomcat">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0760" published="2000-10-20" name="CVE-2000-0760" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-07-15%26msg%3DPine.SUN.3.96.1000719235404.24004A-100000@grex.cyberspace.org" source="BUGTRAQ" adv="1">20000719 [LoWNOISE] Snoop Servlet (Tomcat 3.1 and 3.0)</ref>
      <ref url="http://www.securityfocus.com/bid/1532" source="BID" adv="1">1532</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="tomcat">
        <vers num="3.0" />
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0761" published="2000-10-20" name="CVE-2000-0761" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">OS2/Warp 4.5 FTP server allows remote attackers to cause a denial of service via a long username.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1582" source="BID" patch="1" adv="1">1582</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0166.html" source="BUGTRAQ" patch="1" adv="1">20000815 OS/2 Warp 4.5 FTP Server DoS</ref>
      <ref url="ftp://ftp.software.ibm.com/ps/products/tcpip/fixes/v4.3os2/ic27721/README" source="CONFIRM">ftp://ftp.software.ibm.com/ps/products/tcpip/fixes/v4.3os2/ic27721/README</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="os2_ftp_server">
        <vers num="4.0" />
        <vers num="4.2" />
        <vers num="4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0762" published="2000-10-20" name="CVE-2000-0762" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The default installation of eTrust Access Control (formerly SeOS) uses a default encryption key, which allows remote attackers to spoof the eTrust administrator and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=004601c003a1$ba473260$ddeaa2cd@itradefair.net" source="BUGTRAQ" patch="1" adv="1">20000811 eTrust Access Control - Root compromise for default install</ref>
      <ref url="http://www.securityfocus.com/bid/1583" source="BID" patch="1" adv="1">1583</ref>
      <ref url="http://support.ca.com/techbases/eTrust/etrust_access_control-response.html" source="CONFIRM">http://support.ca.com/techbases/eTrust/etrust_access_control-response.html</ref>
      <ref url="http://xforce.iss.net/static/5076.php" source="XF">etrust-access-control-default</ref>
      <ref url="http://www.osvdb.org/1517" source="OSVDB">1517</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="etrust_access_control">
        <vers num="4.1" edition="sp1" />
        <vers num="5.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0763" published="2000-10-20" name="CVE-2000-0763" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">xlockmore and xlockf do not properly cleanse user-injected format strings, which allows local users to gain root privileges via the -d option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000815231724.A14694@subterrain.net" source="BUGTRAQ" patch="1" adv="1">20000816 xlock vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/1585" source="BID" patch="1" adv="1">1585</ref>
      <ref url="http://www.debian.org/security/2000/20000816" source="DEBIAN" patch="1" adv="1">20000816 xlockmore: possible shadow file compromise</ref>
      <ref url="http://archives.neohapsis.com/archives/freebsd/2000-08/0340.html" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-00:44.xlockmore</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0294.html" source="BUGTRAQ">20000823 MDKSA-2000:038 - xlockmore update</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0212.html" source="BUGTRAQ">20000817 Conectiva Linux Security Announcement - xlockmore</ref>
    </refs>
    <vuln_soft>
      <prod vendor="david_bagley" name="xlock">
        <vers num="4.16" />
        <vers num="4.16.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0764" published="2000-10-20" name="CVE-2000-0764" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Intel Express 500 series switches allow a remote attacker to cause a denial of service via a malformed IP packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1609" source="BID" adv="1">1609</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0338.html" source="BUGTRAQ" adv="1">20000828 Intel Express Switch 500 series DoS</ref>
      <ref url="http://xforce.iss.net/static/5154.php" source="XF">intel-express-switch-dos</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intel" name="express_8100">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0765" published="2000-10-20" name="CVE-2000-0765" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in the HTML interpreter in Microsoft Office 2000 allows an attacker to execute arbitrary commands via a long embedded object tag, aka the "Microsoft Office HTML Object Tag" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1561" source="BID" patch="1" adv="1">1561</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS00-056.asp" source="MS" patch="1" adv="1">MS00-056</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2000" />
      </prod>
      <prod vendor="microsoft" name="powerpoint">
        <vers num="2000" />
      </prod>
      <prod vendor="microsoft" name="word">
        <vers num="2000" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0766" published="2000-10-20" name="CVE-2000-0766" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in vqSoft vqServer 1.4.49 allows remote attackers to cause a denial of service or possibly gain privileges via a long HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1610" source="BID" patch="1" adv="1">1610</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200008270354.UAA10952@user4.hushmail.com" source="BUGTRAQ" adv="1">20000819 D.o.S Vulnerability in vqServer</ref>
      <ref url="http://xforce.iss.net/static/5152.php" source="XF">vqserver-get-dos</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vqsoft" name="vqserver">
        <vers num="1.4.49" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0767" published="2000-10-20" name="CVE-2000-0767" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">The ActiveX control for invoking a scriptlet in Internet Explorer 4.x and 5.x renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka the "Scriptlet Rendering" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1564" source="BID" patch="1" adv="1">1564</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS00-055.asp" source="MS" patch="1" adv="1">MS00-055</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="5.01" />
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0768" published="2000-10-20" name="CVE-2000-0768" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">A function in Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a variant of the "Frame Domain Verification" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1564" source="BID" patch="1" adv="1">1564</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS00-055.asp" source="MS" patch="1" adv="1">MS00-055</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":windows_98" />
        <vers num="4.0" edition=":windows_nt" />
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":windows" />
        <vers num="5.0" edition=":windows_98" />
        <vers num="5.0" edition=":windows_95" />
        <vers num="5.0" edition=":windows_2000" />
        <vers num="5.01" />
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0769" published="2000-10-20" name="CVE-2000-0769" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">O'Reilly WebSite Pro 2.3.7 installs the uploader.exe program with execute permissions for all users, which allows remote attackers to create and execute arbitrary files by directly calling uploader.exe.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1611" source="BID" patch="1" adv="1">1611</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96715834610888&amp;w=2" source="BUGTRAQ">20000824 WebServer Pro 2.3.7 Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oreilly" name="website_pro">
        <vers prev="1" num="2.3.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0770" published="2000-10-20" name="CVE-2000-0770" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">IIS 4.0 and 5.0 does not properly restrict access to certain types of files when their parent folders have less restrictive permissions, which could allow remote attackers to bypass access restrictions to some files, aka the "File Permission Canonicalization" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1565" source="BID" patch="1" adv="1">1565</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS00-057.asp" source="MS" patch="1" adv="1">MS00-057</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0771" published="2000-10-20" name="CVE-2000-0771" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Microsoft Windows 2000 allows local users to cause a denial of service by corrupting the local security policy via malformed RPC traffic, aka the "Local Security Policy Corruption" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1613" source="BID" patch="1" adv="1">1613</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS00-062.asp" source="MS" patch="1" adv="1">MS00-062</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0772" published="2000-10-20" name="CVE-2000-0772" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The installation of Tumbleweed Messaging Management System (MMS) 4.6 and earlier (formerly Worldtalk Worldsecure) creates a default account "sa" with no password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1562" source="BID" patch="1" adv="1">1562</ref>
      <ref url="http://xforce.iss.net/static/5072.php" source="XF">tumbleweed-mms-blank-password</ref>
      <ref url="http://thompson.tumbleweed.com/NewKB/bulletin/UPFiles/sa-official.htm" source="CONFIRM">http://thompson.tumbleweed.com/NewKB/bulletin/UPFiles/sa-official.htm</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0098.html" source="BUGTRAQ" adv="1">20000810 Tumbleweed Worldsecure (MMS) BLANK 'sa' account password vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tumbleweed" name="messaging_management_system">
        <vers num="4.3" />
        <vers num="4.5" />
        <vers num="4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0773" published="2000-10-20" name="CVE-2000-0773" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Bajie HTTP web server 0.30a allows remote attackers to read arbitrary files via a URL that contains a "....", a variant of the dot dot directory traversal attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/5021" source="XF" adv="1">bajie-view-arbitrary-files(5021)</ref>
      <ref url="http://www.securityfocus.com/bid/1522" source="BID" adv="1">1522</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0426.html" source="BUGTRAQ" adv="1">20000731 Two security flaws in Bajie Webserver</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bajie" name="java_http_server">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0774" published="2000-10-20" name="CVE-2000-0774" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The sample Java servlet "test" in Bajie HTTP web server 0.30a reveals the real pathname of the web document root.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1521" source="BID" patch="1" adv="1">1521</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0426.html" source="BUGTRAQ" adv="1">20000731 Two security flaws in Bajie Webserver</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bajie" name="java_http_server">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0775" published="2000-10-20" name="CVE-2000-0775" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in RobTex Viking server earlier than 1.06-370 allows remote attackers to cause a denial of service or execute arbitrary commands via a long HTTP GET request, or long Unless-Modified-Since, If-Range, or If-Modified-Since headers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1614" source="BID" patch="1" adv="1">1614</ref>
      <ref url="http://www.robtex.com/viking/bugs.htm" source="CONFIRM">http://www.robtex.com/viking/bugs.htm</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=399a01c01122$0d7f2310$0201a8c0@aviram" source="BUGTRAQ">20000828 [NT] Viking security vulnerabilities enable remote code execution (long URL, date parsing)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="robtex" name="viking_server">
        <vers prev="1" num="1.0.6_build355" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0776" published="2000-10-20" name="CVE-2000-0776" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Mediahouse Statistics Server 5.02x allows remote attackers to execute arbitrary commands via a long HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1568" source="BID" patch="1" adv="1">1568</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0118.html" source="BUGTRAQ" adv="1">20000810 [DeepZone Advisory] Statistics Server 5.02x stack overflow (Win2k remote exploit)</ref>
      <ref url="http://xforce.iss.net/static/5113.php" source="XF">mediahouse-stats-livestats-bo(5113)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mediahouse_software" name="statistics_server_livestats">
        <vers num="5.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0777" published="2000-10-20" name="CVE-2000-0777" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The password protection feature of Microsoft Money can store the password in plaintext, which allows attackers with physical access to the system to obtain the password, aka the "Money Password" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-061.asp" source="MS" patch="1" adv="1">MS00-061</ref>
      <ref url="http://www.securityfocus.com/bid/1615" source="BID" adv="1">1615</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="money">
        <vers num="2000" />
        <vers num="2001" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0778" published="2000-10-20" name="CVE-2000-0778" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IIS 5.0 allows remote attackers to obtain source code for .ASP files and other scripts via an HTTP GET request with a "Translate: f" header, aka the "Specialized Header" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=080D5336D882D211B56B0060080F2CD696A7C9@beta.mia.cz" source="BUGTRAQ" patch="1" adv="1">20000815 Translate:f summary, history and thoughts</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS00-058.asp" source="MS" patch="1" adv="1">MS00-058</ref>
      <ref url="http://www.securityfocus.com/bid/1578" source="BID" adv="1">1578</ref>
      <ref url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0008&amp;L=ntbugtraq&amp;F=&amp;S=&amp;P=5212" source="NTBUGTRAQ" adv="1">20000816 Translate: f</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:927" source="OVAL" sig="1">oval:org.mitre.oval:def:927</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0779" published="2000-10-20" name="CVE-2000-0779" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Checkpoint Firewall-1 with the RSH/REXEC setting enabled allows remote attackers to bypass access restrictions and connect to a RSH/REXEC client via malformed connection requests.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1534" source="BID" patch="1" adv="1">1534</ref>
      <ref url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#Improper_stderr" source="CONFIRM">http://www.checkpoint.com/techsupport/alerts/list_vun.html#Improper_stderr</ref>
      <ref url="http://www.osvdb.org/1487" source="OSVDB">1487</ref>
    </refs>
    <vuln_soft>
      <prod vendor="checkpoint" name="firewall-1">
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0780" published="2000-10-20" name="CVE-2000-0780" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The web server in IPSWITCH IMail 6.04 and earlier allows remote attackers to read and delete arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1617" source="BID" adv="1">1617</ref>
      <ref url="http://www.ipswitch.com/Support/IMail/news.html" source="CONFIRM">http://www.ipswitch.com/Support/IMail/news.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96767207207553&amp;w=2" source="BUGTRAQ" adv="1">20000830 Vulnerability Report On IPSWITCH's IMail</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="imail">
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0781" published="2000-10-20" name="CVE-2000-0781" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">uagentsetup in ARCServeIT Client Agent 6.62 does not properly check for the existence or ownership of a temporary file which is moved to the agent.cfg configuration file, which allows local users to execute arbitrary commands by modifying the temporary file before it is moved.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/5023" source="XF" adv="1">arcserveit-clientagent-temp-file(5023)</ref>
      <ref url="http://www.securityfocus.com/bid/1519" source="BID" adv="1">1519</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0431.html" source="BUGTRAQ">20000728 Client Agent 6.62 for Unix Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="arcserve_backup">
        <vers num="6.63_linux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0782" published="2000-10-20" name="CVE-2000-0782" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">netauth.cgi program in Netwin Netauth 4.2e and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=NEBBJCLKGNOGCOIOBJNAGEHLCPAA.marc@eeye.com" source="BUGTRAQ" patch="1" adv="1">20000817 Netauth: Web Based Email Management System</ref>
      <ref url="http://www.securityfocus.com/bid/1587" source="BID" patch="1" adv="1">1587</ref>
      <ref url="http://netwinsite.com/netauth/updates.htm" source="CONFIRM">http://netwinsite.com/netauth/updates.htm</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5090" source="XF">netwin-netauth-dir-traverse(5090)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netwin" name="netauth">
        <vers prev="1" num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0783" published="2000-10-20" name="CVE-2000-0783" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Watchguard Firebox II allows remote attackers to cause a denial of service by sending a malformed URL to the authentication service on port 4100.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1573" source="BID" patch="1" adv="1">1573</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0162.html" source="BUGTRAQ" patch="1" adv="1">20000815 Watchguard Firebox Authentication DoS</ref>
      <ref url="http://xforce.iss.net/static/5098.php" source="XF">firebox-url-dos</ref>
    </refs>
    <vuln_soft>
      <prod vendor="watchguard" name="firebox">
        <vers num="ii" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0784" published="2000-10-20" name="CVE-2000-0784" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">sshd program in the Rapidstream 2.1 Beta VPN appliance has a hard-coded "rsadmin" account with a null password, which allows remote attackers to execute arbitrary commands via ssh.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1574" source="BID" patch="1" adv="1">1574</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0216.html" source="BUGTRAQ" patch="1" adv="1">20000816 Remote Root Compromise On All RapidStream VPN Appliances</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rapidstream" name="rapidstream">
        <vers num="2000" />
        <vers num="4000" />
        <vers num="6000" />
        <vers num="8000" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0785" published="2000-10-20" name="CVE-2000-0785" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WircSrv IRC Server 5.07s allows IRC operators to read arbitrary files via the importmotd command, which sets the Message of the Day (MOTD) to the specified file.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96353027909756&amp;w=2" source="BUGTRAQ">20000713 More wIRCSrv stupidity</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wircsrv" name="irc_server">
        <vers num="5.0.7s" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0786" published="2000-10-20" name="CVE-2000-0786" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">GNU userv 1.0.0 and earlier does not properly perform file descriptor swapping, which can corrupt the USERV_GROUPS and USERV_GIDS environmental variables and allow local users to bypass some access restrictions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1516" source="BID" adv="1">1516</ref>
      <ref url="http://www.debian.org/security/2000/20000727" source="DEBIAN" adv="1">20000727 userv: local exploit</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0389.html" source="BUGTRAQ" adv="1">20000726 userv security boundary tool 1.0.1 (SECURITY FIX)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96473640717095&amp;w=2" source="CONFIRM">http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96473640717095&amp;w=2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="userv">
        <vers num="1.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0787" published="2000-10-20" name="CVE-2000-0787" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">IRC Xchat client versions 1.4.2 and earlier allows remote attackers to execute arbitrary commands by encoding shell metacharacters into a URL which XChat uses to launch a web browser.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1601" source="BID" adv="1">1601</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0305.html" source="BUGTRAQ" adv="1">20000825 Conectiva Linux Security Announcement - xchat</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0301.html" source="BUGTRAQ" adv="1">20000824 MDKSA-2000:039 - xchat update</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0215.html" source="BUGTRAQ" adv="1"> 20000817 XChat URL handler vulnerabilty</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-055.html" source="REDHAT">RHSA-2000:055</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xchat" name="xchat">
        <vers num="1.2.1" />
        <vers num="1.3.10" />
        <vers num="1.3.11" />
        <vers num="1.3.12" />
        <vers num="1.3.13" />
        <vers num="1.3.9" />
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.5.6" />
        <vers num="1.5.xdev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0788" published="2000-10-20" name="CVE-2000-0788" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Mail Merge tool in Microsoft Word does not prompt the user before executing Visual Basic (VBA) scripts in an Access database, which could allow an attacker to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=398EB9CA.27E03A9C@nat.bg" source="BUGTRAQ" adv="1">20000807 MS Word and MS Access vulnerability - executing arbitrary programs, may be exploited by IE/Outlook</ref>
      <ref url="http://www.securityfocus.com/bid/1566" source="BID" adv="1">1566</ref>
      <ref url="http://xforce.iss.net/static/5322.php" source="XF">word-mail-merge(5322)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-071.asp" source="MS">MS00-071</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="access">
        <vers num="2000" />
      </prod>
      <prod vendor="microsoft" name="word">
        <vers num="2000" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0789" published="2000-10-20" name="CVE-2000-0789" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">WinU 5.x and earlier uses weak encryption to store its configuration password, which allows local users to decrypt the password and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0201.html" source="BUGTRAQ" adv="1">20000816 WinU 4/5 weak password vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bardon_data_systems" name="winu">
        <vers num="4.x" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0790" published="2000-10-20" name="CVE-2000-0790" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The web-based folder display capability in Microsoft Internet Explorer 5.5 on Windows 98 allows local users to insert Trojan horse programs by modifying the Folder.htt file and using the InvokeVerb method in the ShellDefView ActiveX control to specify a default execute option for the first file that is listed in the folder.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=3998370D.732A03F1@nat.bg" source="BUGTRAQ" adv="1">20000828 IE 5.5/5.x for Win98 may execute arbitrary files that can be accessed thru Microsoft Networking. Also local Administrator compromise at least on default Windows 2000.</ref>
      <ref url="http://www.securityfocus.com/bid/1571" source="BID" adv="1">1571</ref>
      <ref url="http://xforce.iss.net/static/5097.php" source="XF">ie-folder-remote-exe(5097)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0791" published="2000-10-20" name="CVE-2000-0791" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Trustix installs the httpsd program for Apache-SSL with world-writeable permissions, which allows local users to replace it with a Trojan horse.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0179.html" source="BUGTRAQ" patch="1" adv="1">20000815 Trustix security advisory - apache-ssl</ref>
      <ref url="http://www.securityfocus.com/bid/1575" source="BID" adv="1">1575</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trustix" name="secure_linux">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0792" published="2000-10-20" name="CVE-2000-0792" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Gnome Lokkit firewall package before 0.41 does not properly restrict access to some ports, even if a user does not make any services available.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0252.html" source="BUGTRAQ" patch="1" adv="1">20000819 Security update for Gnome-Lokkit</ref>
      <ref url="http://www.securityfocus.com/bid/1590" source="BID" adv="1">1590</ref>
      <ref url="http://www.osvdb.org/1520" source="OSVDB">1520</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alan_cox" name="gnome-lokkit">
        <vers num="0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0793" published="2000-10-20" name="CVE-2000-0793" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Norton AntiVirus 5.00.01C with the Novell Netware client does not properly restart the auto-protection service after the first user has logged off of the system.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1533" source="BID" adv="1">1533</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=398222C5@zathras.cc.vt.edu" source="BUGTRAQ">20000728 Norton Antivirus Protection Disabled under Novell Netware</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="client">
        <vers num="3.1" />
      </prod>
      <prod vendor="symantec" name="norton_antivirus">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0794" published="2000-10-20" name="CVE-2000-0794" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in IRIX libgl.so library allows local users to gain root privileges via a long HOME variable to programs such as (1) gmemusage and (2) gr_osview.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1527" source="BID" adv="1">1527</ref>
      <ref url="http://www.iss.net/security_center/static/5063.php" source="XF">irix-libgl-bo(5063)</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200008021924.e72JOVs12558@ix.put.poznan.pl" source="BUGTRAQ">20000802 [LSD] some unpublished LSD exploit codes</ref>
      <ref url="http://www.osvdb.org/8568" source="OSVDB">8568</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0795" published="2000-10-20" name="CVE-2000-0795" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in lpstat in IRIX 6.2 and 6.3 allows local users to gain root privileges via a long -n option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200008021924.e72JOVs12558@ix.put.poznan.pl" source="BUGTRAQ" adv="1">20000802 [LSD] some unpublished LSD exploit codes</ref>
      <ref url="http://www.securityfocus.com/bid/1529" source="BID" adv="1">1529</ref>
      <ref url="http://www.osvdb.org/1485" source="OSVDB">1485</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.2" />
        <vers num="6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0796" published="2000-10-20" name="CVE-2000-0796" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in dmplay in IRIX 6.2 and 6.3 allows local users to gain root privileges via a long command line option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200008021924.e72JOVs12558@ix.put.poznan.pl" source="BUGTRAQ" adv="1">20000802 [LSD] some unpublished LSD exploit codes</ref>
      <ref url="http://www.securityfocus.com/bid/1528" source="BID" adv="1">1528</ref>
      <ref url="http://xforce.iss.net/static/5064.php" source="XF">irix-dmplay-bo(5064)</ref>
      <ref url="http://www.osvdb.org/1484" source="OSVDB">1484</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.2" />
        <vers num="6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0797" published="2000-10-20" name="CVE-2000-0797" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in gr_osview in IRIX 6.2 and 6.3 allows local users to gain privileges via a long -D option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/5062" source="XF" adv="1">irix-grosview-bo(5062)</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200008021924.e72JOVs12558@ix.put.poznan.pl" source="BUGTRAQ" adv="1">20000802 [LSD] some unpublished LSD exploit codes</ref>
      <ref url="http://www.securityfocus.com/bid/1526" source="BID" adv="1">1526</ref>
      <ref url="http://www.osvdb.org/3815" source="OSVDB">3815</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20040104-01-P.asc" source="SGI">20040104-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.2" />
        <vers num="6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0798" published="2000-10-20" name="CVE-2000-0798" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The truncate function in IRIX 6.x does not properly check for privileges when the file is in the xfs file system, which allows local users to delete the contents of arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1540" source="BID" adv="1">1540</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200008021924.e72JOVs12558@ix.put.poznan.pl" source="BUGTRAQ">20000802 [LSD] some unpublished LSD exploit codes</ref>
      <ref url="http://www.osvdb.org/8569" source="OSVDB">8569</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0799" published="2000-10-20" name="CVE-2000-0799" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">inpview in InPerson in SGI IRIX 5.3 through IRIX 6.5.10 allows local users to gain privileges via a symlink attack on the .ilmpAAA temporary file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200008021924.e72JOVs12558@ix.put.poznan.pl" source="BUGTRAQ" adv="1">20000802 [LSD] some unpublished LSD exploit codes</ref>
      <ref url="http://www.securityfocus.com/bid/1530" source="BID" adv="1">1530</ref>
      <ref url="http://xforce.iss.net/static/5065.php" source="XF">irix-inpview-symlink(5065)</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20001101-01-I" source="SGI">20001101-01-I</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.2m" />
        <vers num="6.5.3" />
        <vers num="6.5.3f" />
        <vers num="6.5.3m" />
        <vers num="6.5.4" />
        <vers num="6.5.6" />
        <vers num="6.5.7" />
        <vers num="6.5.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0800" published="2000-10-20" name="CVE-2000-0800" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">String parsing error in rpc.kstatd in the linuxnfs or knfsd packages in SuSE and possibly other Linux systems allows remote attackers to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.novell.com/linux/security/advisories/suse_security_announce_58.html" source="SUSE">20000810 Security Hole in knfsd, all versions</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="suse_linux">
        <vers num="6.1" edition="alpha" />
        <vers num="6.2" />
        <vers num="6.3" edition="" />
        <vers num="6.3" edition=":ppc" />
        <vers num="6.3" edition="alpha" />
        <vers num="6.4" edition="" />
        <vers num="6.4" edition=":ppc" />
        <vers num="6.4" edition="alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0801" published="2000-10-20" name="CVE-2000-0801" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in bdf program in HP-UX 11.00 may allow local users to gain root privileges via a long -t option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1520" source="BID" adv="1">1520</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0388.html" source="BUGTRAQ" adv="1">20000727 [ Hackerslab bug_paper ] HP-UX bdf -t option buffer overflow vul.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.20" />
        <vers num="11.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0802" published="2000-10-20" name="CVE-2000-0802" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">The BAIR program does not properly restrict access to the Internet Explorer Internet options menu, which allows local users to obtain access to the menu by modifying the registry key that starts BAIR.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96430372326912&amp;w=2" source="BUGTRAQ">20000722 More bad censorware</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pgp" name="personal_privacy">
        <vers num="6.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0803" published="2000-12-19" name="CVE-2000-0803" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">GNU Groff uses the current working directory to find a device description file, which allows a local user to gain additional privileges by including a malicious postpro directive in the description file, which is executed when another user runs groff.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/5280" source="XF">gnu-groff-utilities(5280)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="groff">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0804" published="2000-11-14" name="CVE-2000-0804" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to bypass the directionality check via fragmented TCP connection requests or reopening closed TCP connection requests, aka "One-way Connection Enforcement Bypass."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#One-way_Connection" source="CONFIRM">http://www.checkpoint.com/techsupport/alerts/list_vun.html#One-way_Connection</ref>
      <ref url="http://xforce.iss.net/static/5468.php" source="XF">fw1-remote-bypass</ref>
      <ref url="http://www.osvdb.org/4419" source="OSVDB">4419</ref>
    </refs>
    <vuln_soft>
      <prod vendor="checkpoint" name="firewall-1">
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0805" published="2000-11-14" name="CVE-2000-0805" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Check Point VPN-1/FireWall-1 4.1 and earlier improperly retransmits encapsulated FWS packets, even if they do not come from a valid FWZ client, aka "Retransmission of Encapsulated Packets."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#Retransmission_of" source="CONFIRM">http://www.checkpoint.com/techsupport/alerts/list_vun.html#Retransmission_of</ref>
      <ref url="http://xforce.iss.net/static/5469.php" source="XF">fw1-client-spoof</ref>
      <ref url="http://www.osvdb.org/4415" source="OSVDB">4415</ref>
    </refs>
    <vuln_soft>
      <prod vendor="checkpoint" name="firewall-1">
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0806" published="2000-11-14" name="CVE-2000-0806" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The inter-module authentication mechanism (fwa1) in Check Point VPN-1/FireWall-1 4.1 and earlier may allow remote attackers to conduct a denial of service, aka "Inter-module Communications Bypass."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#Inter-module_Communications" source="CONFIRM">http://www.checkpoint.com/techsupport/alerts/list_vun.html#Inter-module_Communications</ref>
      <ref url="http://xforce.iss.net/static/5162.php" source="XF">fw1-fwa1-auth-replay</ref>
      <ref url="http://www.osvdb.org/4413" source="OSVDB">4413</ref>
    </refs>
    <vuln_soft>
      <prod vendor="checkpoint" name="firewall-1">
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0807" published="2000-11-14" name="CVE-2000-0807" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The OPSEC communications authentication mechanism (fwn1) in Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to spoof connections, aka the "OPSEC Authentication Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#OPSEC_Authentication" source="CONFIRM">http://www.checkpoint.com/techsupport/alerts/list_vun.html#OPSEC_Authentication</ref>
      <ref url="http://xforce.iss.net/static/5471.php" source="XF">fw1-opsec-auth-spoof</ref>
      <ref url="http://www.osvdb.org/4420" source="OSVDB">4420</ref>
    </refs>
    <vuln_soft>
      <prod vendor="checkpoint" name="firewall-1">
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0808" published="2000-11-14" name="CVE-2000-0808" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The seed generation mechanism in the inter-module S/Key authentication mechanism in Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to bypass authentication via a brute force attack, aka "One-time (s/key) Password Authentication."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#One-time_Password" source="CONFIRM">http://www.checkpoint.com/techsupport/alerts/list_vun.html#One-time_Password</ref>
      <ref url="http://xforce.iss.net/static/5137.php" source="XF">fw1-localhost-auth</ref>
      <ref url="http://www.osvdb.org/4421" source="OSVDB">4421</ref>
    </refs>
    <vuln_soft>
      <prod vendor="checkpoint" name="firewall-1">
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0809" published="2000-11-14" name="CVE-2000-0809" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Getkey in the protocol checker in the inter-module communication mechanism in Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#Getkey_Buffer" source="CONFIRM">http://www.checkpoint.com/techsupport/alerts/list_vun.html#Getkey_Buffer</ref>
      <ref url="http://xforce.iss.net/static/5139.php" source="XF">fw1-getkey-bo</ref>
      <ref url="http://www.osvdb.org/4422" source="OSVDB">4422</ref>
    </refs>
    <vuln_soft>
      <prod vendor="checkpoint" name="firewall-1">
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0810" published="2000-12-19" name="CVE-2000-0810" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Auction Weaver 1.0 through 1.04 does not properly validate the names of form fields, which allows remote attackers to delete arbitrary files and directories via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5371.php" source="XF">auction-weaver-delete-files</ref>
      <ref url="http://www.securityfocus.com/bid/1782" source="BID">1782</ref>
      <ref url="http://www.osvdb.org/1600" source="OSVDB">1600</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cgi_script_center" name="auction_weaver">
        <vers num="1.0" />
        <vers num="1.01" />
        <vers num="1.02" />
        <vers num="1.03" />
        <vers num="1.04" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0811" published="2000-12-19" name="CVE-2000-0811" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Auction Weaver 1.0 through 1.04 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the username or bidfile form fields.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5372.php" source="XF">auction-weaver-username-bidfile</ref>
      <ref url="http://www.securityfocus.com/bid/1783" source="BID">1783</ref>
      <ref url="http://www.osvdb.org/4053" source="OSVDB">4053</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cgi_script_center" name="auction_weaver">
        <vers num="1.0" />
        <vers num="1.01" />
        <vers num="1.02" />
        <vers num="1.03" />
        <vers num="1.04" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0812" published="2000-11-14" name="CVE-2000-0812" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The administration module in Sun Java web server allows remote attackers to execute arbitrary commands by uploading Java code to the module and invoke the com.sun.server.http.pagecompile.jsp92.JspServlet by requesting a URL that begins with a /servlet/ tag.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/templates/advisory.html?id=2542" source="MISC" patch="1" adv="1">http://www.securityfocus.com/templates/advisory.html?id=2542</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/197&amp;type=0&amp;nav=sec.sba" source="SUN" patch="1" adv="1">00197</ref>
      <ref url="http://xforce.iss.net/static/5135.php" source="XF">sunjava-webadmin-bbs</ref>
      <ref url="http://www.securityfocus.com/bid/1600" source="BID">1600</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_web_server">
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1_beta" />
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0813" published="2000-11-14" name="CVE-2000-0813" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to redirect FTP connections to other servers ("FTP Bounce") via invalid FTP commands that are processed improperly by FireWall-1, aka "FTP Connection Enforcement Bypass."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#FTP_Connection" source="CONFIRM">http://www.checkpoint.com/techsupport/alerts/list_vun.html#FTP_Connection</ref>
      <ref url="http://xforce.iss.net/static/5474.php" source="XF">fw1-ftp-redirect</ref>
      <ref url="http://www.osvdb.org/4434" source="OSVDB">4434</ref>
    </refs>
    <vuln_soft>
      <prod vendor="checkpoint" name="firewall-1">
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0816" published="2000-10-06" name="CVE-2000-0816" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Linux tmpwatch --fuser option allows local users to execute arbitrary commands by creating files whose names contain shell metacharacters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/alerts/advise64.php" source="ISS" adv="1">20001006 Insecure call of external programs in Red Hat Linux tmpwatch</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5320" source="XF">linux-tmpwatch-fuser(5320)</ref>
      <ref url="http://www.securityfocus.com/bid/1785" source="BID">1785</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-080.html" source="REDHAT">RHSA-2000:080</ref>
      <ref url="http://www.linux-mandrake.com/en/security/MDKSA-2000-056.php3?dis=7.1" source="MANDRAKE">MDKSA-2000:056</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="6.2" edition="" />
        <vers num="6.2" edition=":alpha" />
        <vers num="6.2" edition=":sparc" />
        <vers num="6.2" edition=":i386" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0817" published="2000-12-19" name="CVE-2000-0817" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the HTTP protocol parser for Microsoft Network Monitor (Netmon) allows remote attackers to execute arbitrary commands via malformed data, aka the "Netmon Protocol Parsing" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/alerts/index.php" source="ISS" adv="1">20001101 Buffer Overflow in Microsoft Windows NT 4.0 and Windows 2000 Network Monitor</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS00-083.asp" source="MS" adv="1">MS00-083</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="network_monitor">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0818" published="2000-12-19" name="CVE-2000-0818" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The default installation for the Oracle listener program 7.3.4, 8.0.6, and 8.1.6 allows an attacker to cause logging information to be appended to arbitrary files and execute commands via the SET TRC_FILE or SET LOG_FILE commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://otn.oracle.com/deploy/security/pdf/listener_alert.pdf" source="CONFIRM" patch="1" adv="1">http://otn.oracle.com/deploy/security/pdf/listener_alert.pdf</ref>
      <ref url="http://xforce.iss.net/alerts/advise66.php" source="ISS" adv="1">20001025 Vulnerability in the Oracle Listener Program</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5380" source="XF">oracle-listener-connect-statements(5380)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="listener">
        <vers num="7.3.4" />
        <vers num="8.0.6" />
        <vers num="8.1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0824" published="2000-11-14" name="CVE-2000-0824" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The unsetenv function in glibc 2.1.1 does not properly unset an environmental variable if the variable is provided twice to a program, which could allow local users to execute arbitrary commands in setuid programs by specifying their own duplicate environmental variables such as LD_PRELOAD or LD_LIBRARY_PATH.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/648" source="BID" patch="1" adv="1">648</ref>
      <ref url="http://www.securityfocus.com/archive/1/79537" source="BUGTRAQ" patch="1" adv="1">20000831 glibc unsetenv bug</ref>
      <ref url="http://xforce.iss.net/static/5173.php" source="XF">glibc-ld-unsetenv</ref>
      <ref url="http://www.turbolinux.com/pipermail/tl-security-announce/2000-September/000020.html" source="TURBO">TLSA2000020-1</ref>
      <ref url="http://www.securityfocus.com/bid/1639" source="BID">1639</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-057.html" source="REDHAT">RHSA-2000:057</ref>
      <ref url="http://www.novell.com/linux/security/advisories/adv5_draht_glibc_txt.html" source="SUSE">20000924 glibc locale security problem</ref>
      <ref url="http://www.linux-mandrake.com/en/updates/MDKSA-2000-045.php3" source="MANDRAKE">MDKSA-2000:045</ref>
      <ref url="http://www.linux-mandrake.com/en/updates/MDKSA-2000-040.php3" source="MANDRAKE">MDKSA-2000:040</ref>
      <ref url="http://www.debian.org/security/2000/20000902" source="DEBIAN">20000902 glibc: local root exploit</ref>
      <ref url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-028.0.txt" source="CALDERA">CSSA-2000-028.0</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93760201002154&amp;w=2" source="BUGTRAQ">19990917 A few bugs...</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0525.html" source="BUGTRAQ">20000906 [slackware-security]: glibc 2.1.3 vulnerabilities patched</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0509.html" source="BUGTRAQ">20000905 Conectiva Linux Security Announcement - glibc</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0436.html" source="BUGTRAQ">20000902 Conectiva Linux Security Announcement - glibc</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="glibc">
        <vers num="2.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0825" published="2000-11-14" name="CVE-2000-0825" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Ipswitch Imail 6.0 allows remote attackers to cause a denial of service via a large number of connections in which a long Host: header is sent, which causes a thread to crash.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q3/0071.html" source="WIN2KSEC" adv="1">20000817 Imail Web Service Remote DoS Attack v.2</ref>
      <ref url="http://xforce.iss.net/static/5475.php" source="XF">ipswitch-imail-remote-dos(5475)</ref>
      <ref url="http://www.securityfocus.com/bid/2011" source="BID">2011</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=96654521004571&amp;w=2" source="NTBUGTRAQ">20000817 Imail Web Service Remote DoS Attack v.2</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96659012127444&amp;w=2" source="BUGTRAQ">20000817 Imail Web Service Remote DoS Attack v.2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="imail">
        <vers num="6.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0826" published="2000-11-14" name="CVE-2000-0826" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in ddicgi.exe program in Mobius DocumentDirect for the Internet 1.2 allows remote attackers to execute arbitrary commands via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5210.php" source="XF" patch="1" adv="1">documentdirect-get-bo</ref>
      <ref url="http://www.securityfocus.com/bid/1657" source="BID" patch="1" adv="1">1657</ref>
      <ref url="http://www.atstake.com/research/advisories/2000/a090800-1.txt" source="ATSTAKE">A090800-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mobius" name="documentdirect_for_the_internet">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0827" published="2000-11-14" name="CVE-2000-0827" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the web authorization form of Mobius DocumentDirect for the Internet 1.2 allows remote attackers to cause a denial of service or execute arbitrary commands via a long username.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5211.php" source="XF" patch="1" adv="1">documentdirect-username-bo</ref>
      <ref url="http://www.securityfocus.com/bid/1657" source="BID" patch="1" adv="1">1657</ref>
      <ref url="http://www.atstake.com/research/advisories/2000/a090800-1.txt" source="ATSTAKE">A090800-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mobius" name="documentdirect_for_the_internet">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0828" published="2000-11-14" name="CVE-2000-0828" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in ddicgi.exe in Mobius DocumentDirect for the Internet 1.2 allows remote attackers to execute arbitrary commands via a long User-Agent parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5212.php" source="XF" patch="1" adv="1">documentdirect-user-agent-bo</ref>
      <ref url="http://www.securityfocus.com/bid/1657" source="BID" patch="1" adv="1">1657</ref>
      <ref url="http://www.atstake.com/research/advisories/2000/a090800-1.txt" source="ATSTAKE">A090800-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mobius" name="documentdirect_for_the_internet">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0829" published="2000-11-14" name="CVE-2000-0829" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The tmpwatch utility in Red Hat Linux forks a new process for each directory level, which allows local users to cause a denial of service by creating deeply nested directories in /tmp or /var/tmp/.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5217.php" source="XF" patch="1" adv="1">linux-tmpwatch-fork-dos</ref>
      <ref url="http://www.securityfocus.com/bid/1664" source="BID" patch="1" adv="1">1664</ref>
      <ref url="http://www.securityfocus.com/archive/1/81364" source="BUGTRAQ">20000909 tmpwatch: local DoS : fork()bomb as root</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-080.html" source="REDHAT">RHSA-2000:080</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="tmpwatch">
        <vers num="2.2" />
        <vers num="2.5.1" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0830" published="2000-11-14" name="CVE-2000-0830" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">annclist.exe in webTV for Windows allows remote attackers to cause a denial of service by via a large, malformed UDP packet to ports 22701 through 22705.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1671" source="BID" patch="1" adv="1">1671</ref>
      <ref url="http://xforce.iss.net/static/5216.php" source="XF" adv="1">webtv-udp-dos</ref>
      <ref url="http://www.securityfocus.com/archive/1/81852" source="BUGTRAQ">20000913 trivial DoS in webTV</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-074.asp" source="MS">MS00-074</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="webtv">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0831" published="2000-11-14" name="CVE-2000-0831" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Fastream FTP++ 2.0 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long username.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q3/0109.html" source="WIN2KSEC" patch="1" adv="1">20000912 DST2K0027: DoS in Faststream FTP++ 2.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fastream" name="ftp++_server">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0832" published="2000-11-14" name="CVE-2000-0832" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Htgrep CGI program allows remote attackers to read arbitrary files by specifying the full pathname in the hdr parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5476.php" source="XF">htgrep-cgi-view-files(5476)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0208.html" source="BUGTRAQ" adv="1">20000817 Htgrep CGI Arbitrary File Viewing Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oscar_nierstrasz" name="htgrep">
        <vers prev="1" num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0833" published="2000-11-14" name="CVE-2000-0833" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in WinSMTP 1.06f and 2.X allows remote attackers to cause a denial of service via a long (1) USER or (2) HELO command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5255.php" source="XF" adv="1">winsmtp-helo-bo(5255)</ref>
      <ref url="http://www.securityfocus.com/bid/1680" source="BID" adv="1">1680</ref>
      <ref url="http://www.securityfocus.com/archive/1/81693" source="BUGTRAQ">2000911 WinSMTPD remote exploit/DoS problem</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jack_de_winter" name="winsmtp">
        <vers num="1.6f" />
        <vers num="2.x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0834" published="2000-11-14" name="CVE-2000-0834" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Windows 2000 telnet client attempts to perform NTLM authentication by default, which allows remote attackers to capture and replay the NTLM challenge/response via a telnet:// URL that points to the malicious server, aka the "Windows 2000 Telnet Client NTLM Authentication" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1683" source="BID" patch="1" adv="1">1683</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS00-067.asp" source="MS" patch="1" adv="1">MS00-067</ref>
      <ref url="http://xforce.iss.net/static/5242.php" source="XF">win2k-telnet-ntlm-authentication</ref>
      <ref url="http://www.atstake.com/research/advisories/2000/a091400-1.txt" source="ATSTAKE">A091400-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0835" published="2000-11-14" name="CVE-2000-0835" modified="2010-01-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">search.dll Sambar ISAPI Search utility in Sambar Server 4.4 Beta 3 allows remote attackers to read arbitrary directories by specifying the directory in the query parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1684" source="BID" patch="1" adv="1">1684</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0175.html" source="BUGTRAQ">20000915 Sambar Server search CGI vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sambar" name="sambar_server">
        <vers num="4.3" />
        <vers num="4.4" edition="beta3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0836" published="2000-11-14" name="CVE-2000-0836" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in CamShot WebCam Trial2.6 allows remote attackers to execute arbitrary commands via a long Authorization header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5246.php" source="XF">camshot-password-bo</ref>
      <ref url="http://www.securityfocus.com/bid/1685" source="BID" adv="1">1685</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0176.html" source="BUGTRAQ" adv="1">20000915 [NEWS] Vulnerability in CamShot server (Authorization)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="broadgun_software" name="camshot_webcam">
        <vers num="2.6trial_version" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0837" published="2000-11-14" name="CVE-2000-0837" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">FTP Serv-U 2.5e allows remote attackers to cause a denial of service by sending a large number of null bytes.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5029.php" source="XF" patch="1" adv="1">servu-null-character-dos</ref>
      <ref url="http://www.securityfocus.com/archive/1/73843" source="BUGTRAQ" adv="1">20000804 FTP Serv-U 2.5e vulnerability.</ref>
      <ref url="http://www.securityfocus.com/bid/1543" source="BID">1543</ref>
    </refs>
    <vuln_soft>
      <prod vendor="deerfield" name="ftp_serv-u">
        <vers num="2.5e" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0838" published="2000-11-14" name="CVE-2000-0838" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Fastream FUR HTTP server 1.0b allows remote attackers to cause a denial of service via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5237.php" source="XF" adv="1">fur-get-dos(5237)</ref>
      <ref url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q3/0111.html" source="WIN2KSEC" adv="1">20000914 DST2K0028: DoS in FUR HTTP Server v1.0b</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fastream" name="fur_http_server">
        <vers num="1.0b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0839" published="2000-11-14" name="CVE-2000-0839" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WinCOM LPD 1.00.90 allows remote attackers to cause a denial of service via a large number of LPD options to the LPD port (515).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5258.php" source="XF" adv="1">wincom-lpd-dos(5258)</ref>
      <ref url="http://www.securityfocus.com/bid/1701" source="BID" adv="1">1701</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0212.html" source="BUGTRAQ">20000919 VIGILANTE-2000013: WinCOM LPD DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="wincom_lpd">
        <vers num="1.00.90" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0840" published="2000-11-14" name="CVE-2000-0840" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in XMail POP3 server before version 0.59 allows remote attackers to execute arbitrary commands via a long USER command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0001.html" source="BUGTRAQ" patch="1" adv="1">20000906 [NEWS] XMail vulnerable to a remotely exploitable buffer overflow (APOP, USER)</ref>
      <ref url="http://xforce.iss.net/static/5192.php" source="XF">xmail-long-user-bo</ref>
      <ref url="http://www.securityfocus.com/bid/1652" source="BID" adv="1">1652</ref>
    </refs>
    <vuln_soft>
      <prod vendor="davide_libenzi" name="xmail">
        <vers num="0.58" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0841" published="2000-11-14" name="CVE-2000-0841" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in XMail POP3 server before version 0.59 allows remote attackers to execute arbitrary commands via a long APOP command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0001.html" source="BUGTRAQ" patch="1" adv="1">20000906 [NEWS] XMail vulnerable to a remotely exploitable buffer overflow (APOP, USER)</ref>
      <ref url="http://xforce.iss.net/static/5191.php" source="XF" adv="1">xmail-long-apop-bo</ref>
      <ref url="http://www.securityfocus.com/bid/1652" source="BID">1652</ref>
    </refs>
    <vuln_soft>
      <prod vendor="davide_libenzi" name="xmail">
        <vers num="0.58" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0842" published="2000-11-14" name="CVE-2000-0842" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The search97cgi/vtopic" in the UnixWare 7 scohelphttp webserver allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1663" source="BID" adv="1">1663</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0086.html" source="BUGTRAQ" adv="1">20000911 SCO scohelhttp documentation webserver exposes local files</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="unixware">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0843" published="2000-11-14" name="CVE-2000-0843" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in pam_smb and pam_ntdom pluggable authentication modules (PAM) allow remote attackers to execute arbitrary commands via a login with a long user name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1666" source="BID" patch="1" adv="1">1666</ref>
      <ref url="http://www.debian.org/security/2000/20000911" source="DEBIAN" patch="1" adv="1">20000911 libpam-smb: remote root exploit </ref>
      <ref url="http://www.novell.com/linux/security/advisories/adv8_draht_pam_smb_txt.html" source="SUSE">20000913 pam_smb remotely exploitable buffer overflow</ref>
      <ref url="http://www.linux-mandrake.com/en/security/MDKSA-2000-047.php3" source="MANDRAKE">MDKSA-2000:047</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0114.html" source="BUGTRAQ">20000911 Conectiva Linux Security Announcement - pam_smb</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0073.html" source="BUGTRAQ">20000910 (SRADV00002) Remote root compromise through pam_smb and pam_ntdom</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dave_airlie" name="pam_smb">
        <vers num="1.1.5" />
      </prod>
      <prod vendor="luke_kenneth_casson_leighton" name="pam_ntdom">
        <vers num="0.23" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0844" published="2000-11-14" name="CVE-2000-0844" modified="2009-01-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1634" source="BID" patch="1" adv="1">1634</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0457.html" source="BUGTRAQ" patch="1" adv="1">20000904 UNIX locale format string vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5176" source="XF">unix-locale-format-string(5176)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-057.html" source="REDHAT">RHSA-2000:057</ref>
      <ref url="http://www.novell.com/linux/security/advisories/adv5_draht_glibc_txt.html" source="SUSE">20000906 glibc locale security problem</ref>
      <ref url="http://www.debian.org/security/2000/20000902" source="DEBIAN">20000902 glibc: local root exploit</ref>
      <ref url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-030.0.txt" source="CALDERA">CSSA-2000-030.0</ref>
      <ref url="http://archives.neohapsis.com/archives/tru64/2000-q4/0000.html" source="COMPAQ">SSRT0689U</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0427.html" source="AIXAPAR">IY13753</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0436.html" source="BUGTRAQ">20000902 Conectiva Linux Security Announcement - glibc</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20000901-01-P" source="SGI">20000901-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="caldera" name="openlinux_ebuilder">
        <vers num="3.0" />
      </prod>
      <prod vendor="immunix" name="immunix">
        <vers num="6.2" />
      </prod>
      <prod vendor="caldera" name="openlinux">
        <vers num="" />
      </prod>
      <prod vendor="caldera" name="openlinux_eserver">
        <vers num="2.3" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="4.0" />
        <vers num="4.0es" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="3.2" />
        <vers num="3.2.4" />
        <vers num="3.2.5" />
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
        <vers num="4.2" />
        <vers num="4.2.1" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.2" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="7.0" />
        <vers num="7.1" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.2" />
      </prod>
      <prod vendor="sgi" name="irix">
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.2m" />
        <vers num="6.5.3" />
        <vers num="6.5.3f" />
        <vers num="6.5.3m" />
        <vers num="6.5.4" />
        <vers num="6.5.6" />
        <vers num="6.5.7" />
        <vers num="6.5.8" />
      </prod>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="7.0" />
        <vers num="7.1" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.5.1" />
        <vers num="2.6" />
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
        <vers num="7.0" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="1.0" />
        <vers num="1.1" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux">
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0845" published="2000-11-14" name="CVE-2000-0845" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">kdebug daemon (kdebugd) in Digital Unix 4.0F allows remote attackers to read arbitrary files by specifying the full file name in the initialization packet.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0204.html" source="BUGTRAQ" patch="1" adv="1">20000918 [ENIGMA] Digital UNIX/Tru64 UNIX remote kdebug Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digital" name="unix">
        <vers num="4.0f" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0846" published="2000-11-14" name="CVE-2000-0846" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Darxite 0.4 and earlier allows a remote attacker to execute arbitrary commands via a long username or password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1598" source="BID" adv="1">1598</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0256.html" source="BUGTRAQ" adv="1">20000821 Darxite daemon remote exploit/DoS problem</ref>
      <ref url="http://xforce.iss.net/static/5134.php" source="XF">darxite-login-bo</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ashley_montanaro" name="darxite">
        <vers num="0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0847" published="2000-11-14" name="CVE-2000-0847" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in University of Washington c-client library (used by pine and other programs) allows remote attackers to execute arbitrary commands via a long X-Keywords header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1646" source="BID" adv="1">1646</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0437.html" source="BUGTRAQ" adv="1">20000901 More about UW c-client library</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5223" source="XF">c-client-dos(5223)</ref>
      <ref url="http://www.securityfocus.com/bid/1687" source="BID">1687</ref>
      <ref url="http://archives.neohapsis.com/archives/freebsd/2000-09/0108.html" source="FREEBSD">FreeBSD-SA-00:47.pine</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0425.html" source="BUGTRAQ">20000901 UW c-client library vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_washington" name="imap">
        <vers num="4.7b" />
        <vers num="4.7c" />
      </prod>
      <prod vendor="university_of_washington" name="pine">
        <vers num="4.20" />
        <vers num="4.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0848" published="2000-11-14" name="CVE-2000-0848" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in IBM WebSphere web application server (WAS) allows remote attackers to execute arbitrary commands via a long Host:  request header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1691" source="BID" patch="1" adv="1">1691</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0192.html" source="BUGTRAQ" patch="1" adv="1">20000915 WebSphere application server plugin issue &amp; vendor fix</ref>
      <ref url="http://www-4.ibm.com/software/webservers/appserv/doc/v3022/fxpklst.htm#Security" source="MISC">http://www-4.ibm.com/software/webservers/appserv/doc/v3022/fxpklst.htm#Security</ref>
      <ref url="http://xforce.iss.net/static/5252.php" source="XF">websphere-header-dos</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="3.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0849" published="2000-11-14" name="CVE-2000-0849" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Race condition in Microsoft Windows Media server allows remote attackers to cause a denial of service in the Windows Media Unicast Service via a malformed request, aka the "Unicast Service Race Condition" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1655" source="BID" patch="1" adv="1">1655</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-064.asp" source="MS" patch="1" adv="1">MS00-064</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5193" source="XF">unicast-service-dos(5193)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_media_services">
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0850" published="2000-11-14" name="CVE-2000-0850" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Netegrity SiteMinder before 4.11 allows remote attackers to bypass its authentication mechanism by appending "$/FILENAME.ext" (where ext is .ccc, .class, or .jpg) to the requested URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1681" source="BID" patch="1" adv="1">1681</ref>
      <ref url="http://xforce.iss.net/static/5230.php" source="XF" adv="1">siteminder-bypass-authentication</ref>
      <ref url="http://www.atstake.com/research/advisories/2000/a091100-1.txt" source="ATSTAKE" adv="1">A091100-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netegrity" name="siteminder">
        <vers num="3.6" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0851" published="2000-11-14" name="CVE-2000-0851" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in the Still Image Service in Windows 2000 allows local users to gain additional privileges via a long WM_USER message, aka the "Still Image Service Privilege Escalation" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1651" source="BID" patch="1" adv="1">1651</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-065.asp" source="MS" patch="1" adv="1">MS00-065</ref>
      <ref url="http://www.atstake.com/research/advisories/2000/a090700-1.txt" source="ATSTAKE">A090700-1</ref>
      <ref url="http://xforce.iss.net/static/5203.php" source="XF">w2k-still-image-service</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0852" published="2000-11-14" name="CVE-2000-0852" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple buffer overflows in eject on FreeBSD and possibly other OSes allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1686" source="BID" patch="1" adv="1">1686</ref>
      <ref url="http://xforce.iss.net/static/5248.php" source="XF" adv="1">freebsd-eject-port</ref>
      <ref url="http://www.osvdb.org/1559" source="OSVDB">1559</ref>
      <ref url="http://archives.neohapsis.com/archives/freebsd/2000-09/0110.html" source="FREEBSD">FreeBSD-SA-00:49</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" edition="alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0853" published="2000-11-14" name="CVE-2000-0853" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">YaBB Bulletin Board 9.1.2000 allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1668" source="BID" patch="1" adv="1">1668</ref>
      <ref url="http://xforce.iss.net/static/5254.php" source="XF" adv="1">yabb-file-access</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0072.html" source="BUGTRAQ" adv="1">20000909 YaBB 1.9.2000 Vulnerabilitie</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yabb" name="yabb">
        <vers num="2000-09-01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0854" published="2000-11-14" name="CVE-2000-0854" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">When a Microsoft Office 2000 document is launched, the directory of that document is first used to locate DLL's such as riched20.dll and msi.dll, which could allow an attacker to execute arbitrary commands by inserting a Trojan Horse DLL into the same directory as the document.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1699" source="BID" patch="1" adv="1">1699</ref>
      <ref url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q3/0117.html" source="WIN2KSEC" adv="1">20000918 Double clicking on MS Office documents from Windows Explorer may execute arbitrary programs in some cases</ref>
      <ref url="http://xforce.iss.net/static/5263.php" source="XF">office-dll-execution(5263)</ref>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0155.html" source="NTBUGTRAQ">20000921 Mitigators for possible exploit of Eudora via Guninski #21,2000</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0277.html" source="BUGTRAQ">20000922 Eudora + riched20.dll affects WinZip v8.0 as well</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2000" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0855" published="2000-11-14" name="CVE-2000-0855" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SunFTP build 9(1) allows remote attackers to cause a denial of service by connecting to the server and disconnecting before sending a newline.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1637" source="BID" adv="1">1637</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0408.html" source="BUGTRAQ" adv="1">20000901 [EXPL] SunFTP vulnerable to two Denial-of-Service attacks (long buffer, half-open)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xs4all_data" name="xs4all_data_sunftp">
        <vers num="1.0_build_9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0856" published="2000-11-14" name="CVE-2000-0856" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in SunFTP build 9(1) allows remote attackers to cause a denial of service or possibly execute arbitrary commands via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1638" source="BID" adv="1">1638</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0408.html" source="BUGTRAQ" adv="1">20000901 [EXPL] SunFTP vulnerable to two Denial-of-Service attacks (long buffer, half-open)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xs4all_data" name="xs4all_data_sunftp">
        <vers num="1.0_build_9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0857" published="2000-11-14" name="CVE-2000-0857" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The logging capability in muh 2.05d IRC server does not properly cleanse user-injected format strings, which allows remote attackers to cause a denial of service or execute arbitrary commands via a malformed nickname.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1665" source="BID" patch="1" adv="1">1665</ref>
      <ref url="http://xforce.iss.net/static/5215.php" source="XF">muh-log-dos</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0068.html" source="BUGTRAQ" adv="1">20000909 Re: format string bug in muh</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0067.html" source="BUGTRAQ" adv="1">20000909 format string bug in muh</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sebastian_kienzl" name="muh">
        <vers num="2.05d" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0858" published="2000-11-14" name="CVE-2000-0858" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Vulnerability in Microsoft Windows NT 4.0 allows remote attackers to cause a denial of service in IIS by sending it a series of malformed requests which cause INETINFO.EXE to fail, aka the "Invalid URL" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1642" source="BID" patch="1" adv="1">1642</ref>
      <ref url="http://www.securityfocus.com/archive/1/80413" source="BUGTRAQ" patch="1" adv="1">20000906 VIGILANTE-2000009: "Invalid URL" DoS</ref>
      <ref url="http://archives.neohapsis.com/archives/vendor/2000-q3/0065.html" source="MS" patch="1" adv="1">MS00-063</ref>
      <ref url="http://xforce.iss.net/static/5202.php" source="XF">iis-invald-url-dos</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0859" published="2000-11-14" name="CVE-2000-0859" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The web configuration server for NTMail V5 and V6 allows remote attackers to cause a denial of service via a series of partial HTTP requests.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1640" source="BID" patch="1" adv="1">1640</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0471.html" source="BUGTRAQ" patch="1" adv="1">20000904 VIGILANTE-2000008: NTMail Configuration Service DoS</ref>
      <ref url="http://xforce.iss.net/static/5182.php" source="XF">ntmail-incomplete-http-requests</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gordano" name="ntmail">
        <vers num="5.0" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0860" published="2000-11-14" name="CVE-2000-0860" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The file upload capability in PHP versions 3 and 4 allows remote attackers to read arbitrary files by setting hidden form fields whose names match the names of internal PHP script variables.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1649" source="BID" adv="1">1649</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0455.html" source="BUGTRAQ" adv="1">20000903 (SRADV00001) Arbitrary file disclosure through PHP file upload</ref>
      <ref url="http://xforce.iss.net/static/5190.php" source="XF">php-file-upload</ref>
      <ref url="http://cvsweb.php.net/viewcvs.cgi/php4/main/rfc1867.c.diff?r1=1.38%3Aphp_4_0_2&amp;tr1=1.1&amp;r2=text&amp;tr2=1.45&amp;diff_format=u" source="CONFIRM">http://cvsweb.php.net/viewcvs.cgi/php4/main/rfc1867.c.diff?r1=1.38%3Aphp_4_0_2&amp;tr1=1.1&amp;r2=text&amp;tr2=1.45&amp;diff_format=u</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0150.html" source="MANDRAKE">MDKSA-2000:048</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0477.html" source="BUGTRAQ">20000904 Re: [PHP-DEV] RE: (SRADV00001) Arbitrary file disclosure through PHP file upload</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="2.0b10" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0861" published="2000-11-14" name="CVE-2000-0861" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Mailman 1.1 allows list administrators to execute arbitrary commands via shell metacharacters in the %(listname) macro expansion.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1667" source="BID" patch="1" adv="1">1667</ref>
      <ref url="http://archives.neohapsis.com/archives/freebsd/2000-09/0112.html" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-00:51</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0040.html" source="BUGTRAQ" patch="1" adv="1">20000907 Mailman 1.1 + external archiver vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5493" source="XF">mailman-execute-external-commands(5493)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="mailman">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0862" published="2000-11-14" name="CVE-2000-0862" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Vulnerability in an administrative interface utility for Allaire Spectra 1.0.1 allows remote attackers to read and modify sensitive configuration information.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/vendor/2000-q3/0059.html" source="ALLAIRE" adv="1">ASB00-23</ref>
      <ref url="http://xforce.iss.net/static/5466.php" source="XF">allaire-spectra-admin-access</ref>
    </refs>
    <vuln_soft>
      <prod vendor="allaire" name="spectra">
        <vers num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0863" published="2000-11-14" name="CVE-2000-0863" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in listmanager earlier than 2.105.1 allows local users to gain additional privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/freebsd/2000-09/0111.html" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-00:50</ref>
      <ref url="http://xforce.iss.net/static/5503.php" source="XF">listmanager-port-bo</ref>
    </refs>
    <vuln_soft>
      <prod vendor="listmanager" name="linux">
        <vers num="2.100" />
        <vers num="2.101" />
        <vers num="2.102" />
        <vers num="2.103" />
        <vers num="2.104" />
        <vers num="2.105.1" />
        <vers prev="1" num="2.96" />
        <vers num="2.97" />
        <vers num="2.98" />
        <vers num="2.99" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0864" published="2000-11-14" name="CVE-2000-0864" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">Race condition in the creation of a Unix domain socket in GNOME esound 0.2.19 and earlier allows a local user to change the permissions of arbitrary files and directories, and gain additional privileges, via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1659" source="BID" patch="1" adv="1">1659</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-077.html" source="REDHAT">RHSA-2000:077</ref>
      <ref url="http://www.novell.com/linux/security/advisories/esound_daemon_race_condition.html" source="SUSE">20001012 esound daemon race condition</ref>
      <ref url="http://www.debian.org/security/2000/20001008" source="DEBIAN">20001008 esound: race condition</ref>
      <ref url="http://archives.neohapsis.com/archives/freebsd/2000-08/0365.html" source="FREEBSD" adv="1">FreeBSD-SA-00:45</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0118.html" source="BUGTRAQ">20001006 Immunix OS Security Update for esound</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0095.html" source="BUGTRAQ">20000911 Patch for esound-0.2.19</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="esound">
        <vers num="0.2.19" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0865" published="2000-11-14" name="CVE-2000-0865" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in dvtermtype in Tridia Double Vision 3.07.00 allows local users to gain root privileges via a long terminal type argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1697" source="BID" patch="1" adv="1">1697</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0185.html" source="BUGTRAQ" patch="1" adv="1">20000916 Advisory: Tridia DoubleVision / SCO UnixWare</ref>
      <ref url="http://xforce.iss.net/static/5261.php" source="XF">doublevision-dvtermtype-bo</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tridia" name="doublevision">
        <vers num="3.07.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0866" published="2000-11-14" name="CVE-2000-0866" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Interbase 6 SuperServer for Linux allows an attacker to cause a denial of service via a query containing 0 bytes.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5205.php" source="XF">interbase-query-dos</ref>
      <ref url="http://www.securityfocus.com/bid/1654" source="BID" adv="1">1654</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0027.html" source="BUGTRAQ">20000907 SEGFAULTING Interbase 6 SS Linux</ref>
    </refs>
    <vuln_soft>
      <prod vendor="borland_software" name="interbase_superserver">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0867" published="2000-11-14" name="CVE-2000-0867" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Kernel logging daemon (klogd) in Linux does not properly cleanse user-injected format strings, which allows local users to gain root privileges by triggering malformed kernel messages.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5259.php" source="XF" adv="1">klogd-format-string</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0193.html" source="BUGTRAQ" adv="1">20000917 klogd format bug</ref>
      <ref url="http://www.turbolinux.com/pipermail/tl-security-announce/2000-September/000023.html" source="TURBO">TLSA2000022-2</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-061.html" source="REDHAT">RHSA-2000:061</ref>
      <ref url="http://www.osvdb.org/5824" source="OSVDB">5824</ref>
      <ref url="http://www.novell.com/linux/security/advisories/adv9_draht_syslogd_txt.html" source="SUSE">20000920 syslogd + klogd format string parsing error</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97726239017741&amp;w=2" source="BUGTRAQ">20000918 Conectiva Linux Security Announcement - sysklogd</ref>
      <ref url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2000:050" source="MANDRAKE">MDKSA-2000:050</ref>
      <ref url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2000-032.0.txt" source="CALDERA">CSSA-2000-032.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":slink" />
        <vers num="2.2" edition="" />
        <vers num="2.2" edition=":potato" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="7.0" />
        <vers num="7.1" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="5.2" />
        <vers num="6.2" />
      </prod>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0868" published="2000-11-14" name="CVE-2000-0868" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-bin-sdb/.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1658" source="BID" patch="1" adv="1">1658</ref>
      <ref url="http://www.atstake.com/research/advisories/2000/a090700-2.txt" source="ATSTAKE" patch="1" adv="1">A090700-2</ref>
      <ref url="http://archives.neohapsis.com/archives/linux/suse/2000-q3/0906.html" source="SUSE" patch="1" adv="1">20000907</ref>
      <ref url="http://xforce.iss.net/static/5197.php" source="XF">suse-apache-cgi-source-code</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="1.3.12" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="6.3" />
        <vers num="6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0869" published="2000-11-14" name="CVE-2000-0869" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary diretories via the PROPFIND HTTP request method.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1656" source="BID" patch="1" adv="1">1656</ref>
      <ref url="http://www.atstake.com/research/advisories/2000/a090700-3.txt" source="ATSTAKE" adv="1">A090700-3</ref>
      <ref url="http://archives.neohapsis.com/archives/linux/suse/2000-q3/0906.html" source="SUSE" adv="1">20000907</ref>
      <ref url="http://xforce.iss.net/static/5204.php" source="XF">apache-webdav-directory-listings</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="1.3.12" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="6.0" />
        <vers num="6.1" edition="alpha" />
        <vers num="6.2" />
        <vers num="6.3" edition="" />
        <vers num="6.3" edition=":ppc" />
        <vers num="6.3" edition="alpha" />
        <vers num="6.4" edition="" />
        <vers num="6.4" edition=":ppc" />
        <vers num="6.4" edition="alpha" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0870" published="2000-11-14" name="CVE-2000-0870" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in EFTP allows remote attackers to cause a denial of service via a long string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1675" source="BID" adv="1">1675</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0089.html" source="BUGTRAQ" adv="1">20000911[EXPL] EFTP vulnerable to two DoS attacks</ref>
      <ref url="http://xforce.iss.net/static/5219.php" source="XF">eftp-bo</ref>
      <ref url="http://www.osvdb.org/1555" source="OSVDB">1555</ref>
    </refs>
    <vuln_soft>
      <prod vendor="khamil_landross_and_zack_jones" name="eftp">
        <vers num="2.0.4.281" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0871" published="2000-11-14" name="CVE-2000-0871" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in EFTP allows remote attackers to cause a denial of service by sending a string that does not contain a newline, then disconnecting from the server.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1677" source="BID" adv="1">1677</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0089.html" source="BUGTRAQ" adv="1">20000911[EXPL] EFTP vulnerable to two DoS attacks</ref>
      <ref url="http://xforce.iss.net/static/5220.php" source="XF">eftp-newline-dos</ref>
      <ref url="http://www.osvdb.org/409" source="OSVDB">409</ref>
    </refs>
    <vuln_soft>
      <prod vendor="khamil_landross_and_zack_jones" name="eftp">
        <vers num="2.0.4.281" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0872" published="2000-11-14" name="CVE-2000-0872" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">explorer.php in PhotoAlbum 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5198.php" source="XF">phpphoto-dir-traverse</ref>
      <ref url="http://www.securityfocus.com/bid/1650" source="BID" adv="1">1650</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0015.html" source="BUGTRAQ" adv="1">20000906 PhotoAlbum 0.9.9 explorer.php Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nathan_purciful" name="phpphotoalbum">
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0873" published="2000-11-14" name="CVE-2000-0873" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">netstat in AIX 4.x.x does not properly restrict access to the -Zi option, which allows local users to clear network interface statistics and possibly hide evidence of unusual network activities.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1660" source="BID">1660</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0454.html" source="BUGTRAQ" adv="1">20000903 aix allows clearing the interface stats</ref>
      <ref url="http://xforce.iss.net/static/5214.php" source="XF">aix-clear-netstat</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.2" />
        <vers num="4.2.1" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0874" published="2000-11-14" name="CVE-2000-0874" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Eudora mail client includes the absolute path of the sender's host within a virtual card (VCF).</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5206.php" source="XF" adv="1">eudora-path-disclosure</ref>
      <ref url="http://www.securityfocus.com/bid/1653" source="BID" adv="1">1653</ref>
      <ref url="http://www.securityfocus.com/archive/1/80888" source="BUGTRAQ" adv="1">20000907 Eudora disclosure</ref>
      <ref url="http://www.osvdb.org/1545" source="OSVDB">1545</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qualcomm" name="eudora">
        <vers num="4.2" />
        <vers num="4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0875" published="2000-11-14" name="CVE-2000-0875" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WFTPD and WFTPD Pro 2.41 RC12 allows remote attackers to cause a denial of service by sending a long string of unprintable characters.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5194.php" source="XF" adv="1">wftpd-long-string-dos</ref>
      <ref url="http://www.wftpd.com/bug_gpf.htm" source="CONFIRM">http://www.wftpd.com/bug_gpf.htm</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0488.html" source="BUGTRAQ" adv="1">20000905 WFTPD/WFTPD Pro 2.41 RC12 vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="texas_imperial_software" name="wftpd">
        <vers num="2.34" />
        <vers num="2.4.1" />
        <vers num="2.4.1_rc11" />
        <vers num="2.4.1_rc12" />
        <vers num="2.40" />
      </prod>
      <prod vendor="texas_imperial_software" name="wftpd_pro">
        <vers num="2.41_rc12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0876" published="2000-11-14" name="CVE-2000-0876" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WFTPD and WFTPD Pro 2.41 RC12 allows remote attackers to obtain the full pathname of the server via a "%C" command, which generates an error message that includes the pathname.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/5829" source="OSVDB">5829</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0488.html" source="BUGTRAQ">20000905 WFTPD/WFTPD Pro 2.41 RC12 vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="texas_imperial_software" name="wftpd">
        <vers num="2.34" />
        <vers num="2.4.1" />
        <vers num="2.4.1_rc11" />
        <vers num="2.4.1_rc12" />
        <vers num="2.40" />
      </prod>
      <prod vendor="texas_imperial_software" name="wftpd_pro">
        <vers num="2.41_rc12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0877" published="2000-11-14" name="CVE-2000-0877" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">mailform.pl CGI script in MailForm 2.0 allows remote attackers to read arbitrary files by specifying the file name in the XX-attach_file parameter, which MailForm then sends to the attacker.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1670" source="BID" adv="1">1670</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0092.html" source="BUGTRAQ" adv="1">20000911 Unsafe passing of variables to mailform.pl in MailForm V2.0</ref>
      <ref url="http://xforce.iss.net/static/5224.php" source="XF">mailform-attach-file</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ranson_johnson" name="mailform">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0878" published="2000-11-14" name="CVE-2000-0878" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The mailto CGI script allows remote attacker to execute arbitrary commands via shell metacharacters in the emailadd form field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1669" source="BID" patch="1" adv="1">1669</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0088.html" source="BUGTRAQ" patch="1" adv="1">20000911 Fwd: Poor variable checking in mailto.cgi</ref>
      <ref url="http://xforce.iss.net/static/5241.php" source="XF">mailto-piped-address</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ranson_johnson" name="mailto_cgi_script">
        <vers prev="1" num="1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0879" published="2000-11-14" name="CVE-2000-0879" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">LPPlus programs dccsched, dcclpdser, dccbkst, dccshut, dcclpdshut, and dccbkstshut are installed setuid root and world executable, which allows arbitrary local users to start and stop various LPD services.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5199.php" source="XF">lpplus-permissions-dos</ref>
      <ref url="http://www.securityfocus.com/bid/1643" source="BID" adv="1">1643</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0531.html" source="BUGTRAQ" adv="1">20000906 Multiple Security Holes in LPPlus</ref>
    </refs>
    <vuln_soft>
      <prod vendor="plus_technologies" name="lpplus">
        <vers num="3.2.2" />
        <vers num="3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0880" published="2000-11-14" name="CVE-2000-0880" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">LPPlus creates the lpdprocess file with world-writeable permissions, which allows local users to kill arbitrary processes by specifying an alternate process ID and using the setuid dcclpdshut program to kill the process that was specified in the lpdprocess file.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5200.php" source="XF">lpplus-process-perms-dos</ref>
      <ref url="http://www.securityfocus.com/bid/1643" source="BID" adv="1">1643</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0531.html" source="BUGTRAQ" adv="1">20000906 Multiple Security Holes in LPPlus</ref>
    </refs>
    <vuln_soft>
      <prod vendor="plus_technologies" name="lpplus">
        <vers num="3.2.2" />
        <vers num="3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0881" published="2000-11-14" name="CVE-2000-0881" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The dccscan setuid program in LPPlus does not properly check if the user has the permissions to print the file that is specified to dccscan, which allows local users to print arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5201.php" source="XF">lpplus-dccscan-file-read</ref>
      <ref url="http://www.securityfocus.com/bid/1644" source="BID" adv="1">1644</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0531.html" source="BUGTRAQ" adv="1">20000906 Multiple Security Holes in LPPlus</ref>
    </refs>
    <vuln_soft>
      <prod vendor="plus_technologies" name="lpplus">
        <vers num="3.2.2" />
        <vers num="3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0882" published="2000-11-14" name="CVE-2000-0882" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Intel Express 500 series switches allow a remote attacker to cause a denial of service via a malformed ICMP packet, which causes the CPU to crash.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1647" source="BID" patch="1" adv="1">1647</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0533.html" source="BUGTRAQ" patch="1" adv="1">20000906 VIGILANTE-2000010: Intel Express Switch series 500 DoS #2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intel" name="express_510t">
        <vers num="2.63" />
        <vers num="2.64" />
      </prod>
      <prod vendor="intel" name="express_520t">
        <vers num="2.63" />
        <vers num="2.64" />
      </prod>
      <prod vendor="intel" name="express_550f">
        <vers num="2.63" />
        <vers num="2.64" />
      </prod>
      <prod vendor="intel" name="express_550t">
        <vers num="2.63" />
        <vers num="2.64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0883" published="2000-11-14" name="CVE-2000-0883" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The default configuration of mod_perl for Apache as installed on Mandrake Linux 6.1 through 7.1 sets the /perl/ directory to be browseable, which allows remote attackers to list the contents of that directory.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5257.php" source="XF" patch="1" adv="1">linux-mod-perl</ref>
      <ref url="http://www.securityfocus.com/bid/1678" source="BID" patch="1" adv="1">1678</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0111.html" source="MANDRAKE" patch="1" adv="1">MDKSA-2000:046</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="6.1" />
        <vers num="7.0" />
        <vers num="7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0884" published="2000-12-19" name="CVE-2000-0884" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Server Folder Traversal" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-078.asp" source="MS" patch="1" adv="1">MS00-078</ref>
      <ref url="http://xforce.iss.net/static/5377.php" source="XF">iis-unicode-translation</ref>
      <ref url="http://www.securityfocus.com/bid/1806" source="BID">1806</ref>
      <ref url="http://www.osvdb.org/436" source="OSVDB">436</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:44" source="OVAL" sig="1">oval:org.mitre.oval:def:44</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0885" published="2000-12-19" name="CVE-2000-0885" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflows in Microsoft Network Monitor (Netmon) allow remote attackers to execute arbitrary commands via a long Browser Name in a CIFS Browse Frame, a long SNMP community name, or a long username or filename in an SMB session, aka the "Netmon Protocol Parsing" vulnerability.  NOTE: It is highly likely that this candidate will be split into multiple candidates.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS00-083.asp" source="MS" patch="1" adv="1">MS00-083</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="systems_management_server">
        <vers num="1.2" />
        <vers num="2.0" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:enterprise" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0886" published="2000-12-19" name="CVE-2000-0886" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating system commands, aka the "Web Server File Request Parsing" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS00-086.asp" source="MS" patch="1" adv="1">MS00-086</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?mid=143604&amp;list=1&amp;fromthread=0&amp;end=2000-11-11&amp;threads=0&amp;start=2000-11-05&amp;" source="BUGTRAQ" adv="1">20001107 NSFOCUS SA2000-07 : Microsoft IIS 4.0/5.0 CGI File Name Inspection Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5470" source="XF">iis-invalid-filename-passing(5470)</ref>
      <ref url="http://www.securityfocus.com/bid/1912" source="BID">1912</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:191" source="OVAL" sig="1">oval:org.mitre.oval:def:191</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0887" published="2000-12-19" name="CVE-2000-0887" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">named in BIND 8.2 through 8.2.2-P6 allows remote attackers to cause a denial of service by making a compressed zone transfer (ZXFR) request and performing a name service query on an authoritative record that is not cached, aka the "zxfr bug."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2000-20.html" source="CERT">CA-2000-20</ref>
      <ref url="http://www.securityfocus.com/bid/1923" source="BID" patch="1" adv="1">1923</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000339" source="CONECTIVA" patch="1" adv="1">CLSA-2000:339</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5540" source="XF">bind-zxfr-dos(5540)</ref>
      <ref url="http://www.securityfocus.com/archive/1/143843" source="BUGTRAQ">20001107 BIND 8.2.2-P5 Possible DOS</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-107.html" source="REDHAT">RHSA-2000:107</ref>
      <ref url="http://www.debian.org/security/2000/20001112" source="DEBIAN">20001112 bind: remote Denial of Service</ref>
      <ref url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2000:067" source="MANDRAKE">MDKSA-2000:067</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000338" source="CONECTIVA">CLSA-2000:338</ref>
      <ref url="http://archives.neohapsis.com/archives/linux/suse/2000-q4/0657.html" source="SUSE">SuSE-SA:2000:45</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0217.html" source="BUGTRAQ">20001115 Trustix Security Advisory - bind and openssh (and modutils)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="bind">
        <vers num="8.2.2" edition="p5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0888" published="2000-12-19" name="CVE-2000-0888" modified="2005-10-12" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">named in BIND 8.2 through 8.2.2-P6 allows remote attackers to cause a denial of service by sending an SRV record to the server, aka the "srv bug."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2000-20.html" source="CERT" adv="1">CA-2000-20</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000339" source="CONECTIVA" patch="1" adv="1">CLSA-2000:339</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5814" source="XF">bind-srv-dos(5814)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-107.html" source="REDHAT">RHSA-2000:107</ref>
      <ref url="http://www.debian.org/security/2000/20001112" source="DEBIAN">20001112 bind: remote Denial of Service</ref>
      <ref url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2000:067" source="MANDRAKE">MDKSA-2000:067</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000338" source="CONECTIVA">CLSA-2000:338</ref>
      <ref url="http://archives.neohapsis.com/archives/linux/suse/2000-q4/0657.html" source="SUSE">SuSE-SA:2000:45</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0889" published="2001-02-12" name="CVE-2000-0889" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Two Sun security certificates have been compromised, which could allow attackers to insert malicious code such as applets and make it appear that it is signed by Sun.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2000-19.html" source="CERT" patch="1" adv="1">CA-2000-19</ref>
      <ref url="http://sunsolve.Sun.COM/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/198&amp;type=0&amp;nav=sec.sba" source="SUN" adv="1">00198</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0890" published="2001-02-16" name="CVE-2000-0890" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">periodic in FreeBSD 4.1.1 and earlier, and possibly other operating systems, allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/626919" source="CERT-VN" patch="1" adv="1">VU#626919</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6047" source="XF">periodic-temp-file-symlink(6047)</ref>
      <ref url="http://www.securityfocus.com/bid/2325" source="BID">2325</ref>
      <ref url="http://www.osvdb.org/1754" source="OSVDB">1754</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="6.2" edition="stable" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0891" published="2001-07-21" name="CVE-2000-0891" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">A default ECL in Lotus Notes before 5.02 allows remote attackers to execute arbitrary commands by attaching a malicious program in an email message that is automatically executed when the user opens the email.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/5962" source="CERT-VN" patch="1" adv="1">VU#5962</ref>
      <ref url="http://www.notes.net/R5FixList.nsf/Search%21SearchView&amp;Query=CBAT45TU9S" source="CONFIRM">http://www.notes.net/R5FixList.nsf/Search!SearchView&amp;Query=CBAT45TU9S</ref>
      <ref url="http://xforce.iss.net/static/5045.php" source="XF">lotus-notes-bypass-ecl(5045)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_notes">
        <vers prev="1" num="5.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0892" published="2001-07-21" name="CVE-2000-0892" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Some telnet clients allow remote telnet servers to request environment variables from the client that may contain sensitive information, or remote web servers to obtain the information via a telnet: URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/22404" source="CERT-VN" patch="1" adv="1">VU#22404</ref>
      <ref url="http://xforce.iss.net/static/6644.php" source="XF">telnet-obtain-env-variable(6644)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="u_win" name="u_win">
        <vers num="" />
      </prod>
      <prod vendor="caldera" name="openlinux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0893" published="2001-02-16" name="CVE-2000-0893" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The presence of the Distributed GL Daemon (dgld) service on port 5232 on SGI IRIX systems allows remote attackers to identify the target host as an SGI system.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/28027" source="CERT-VN" patch="1" adv="1">VU#28027</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0894" published="2001-02-12" name="CVE-2000-0894" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">HTTP server on the WatchGuard SOHO firewall does not properly restrict access to administrative functions such as password resets or rebooting, which allows attackers to cause a denial of service or conduct unauthorized activities.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/alerts/advise70.php" source="ISS" patch="1" adv="1">20001214 Multiple vulnerabilities in the WatchGuard SOHO Firewall</ref>
      <ref url="http://www.securityfocus.com/bid/2119" source="BID" patch="1" adv="1">2119</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5554" source="XF">watchguard-soho-web-auth(5554)</ref>
      <ref url="http://www.osvdb.org/4404" source="OSVDB">4404</ref>
    </refs>
    <vuln_soft>
      <prod vendor="watchguard" name="soho_firewall">
        <vers num="1.6" />
        <vers num="2.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0895" published="2001-02-12" name="CVE-2000-0895" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in HTTP server on the WatchGuard SOHO firewall allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/alerts/advise70.php" source="ISS" patch="1" adv="1">20001214 Multiple vulnerabilities in the WatchGuard SOHO Firewall</ref>
      <ref url="http://www.securityfocus.com/bid/2114" source="BID" patch="1" adv="1">2114</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5218" source="XF" adv="1">watchguard-soho-web-dos(5218)</ref>
      <ref url="http://www.osvdb.org/4403" source="OSVDB">4403</ref>
    </refs>
    <vuln_soft>
      <prod vendor="watchguard" name="soho_firewall">
        <vers num="1.6" />
        <vers num="2.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0896" published="2001-02-12" name="CVE-2000-0896" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WatchGuard SOHO firewall allows remote attackers to cause a denial of service via a flood of fragmented IP packets, which causes the firewall to drop connections and stop forwarding packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5749.php" source="XF" patch="1" adv="1">watchguard-soho-fragmented-packets</ref>
      <ref url="http://xforce.iss.net/alerts/advise70.php" source="ISS" patch="1" adv="1">20001214 Multiple vulnerabilities in the WatchGuard SOHO Firewall</ref>
      <ref url="http://www.securityfocus.com/bid/2113" source="BID" patch="1" adv="1">2113</ref>
      <ref url="http://www.osvdb.org/1690" source="OSVDB">1690</ref>
    </refs>
    <vuln_soft>
      <prod vendor="watchguard" name="soho_firewall">
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0897" published="2001-01-09" name="CVE-2000-0897" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Small HTTP Server 2.03 and earlier allows remote attackers to cause a denial of service by repeatedly requesting a URL that references a directory that does not contain an index.html file, which consumes memory that is not released after the request is completed.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1941" source="BID" patch="1" adv="1">1941</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97421834001092&amp;w=2" source="BUGTRAQ" adv="1">20001114 Vulnerabilites in SmallHTTP Server</ref>
      <ref url="http://home.lanck.net/mf/srv/index.htm" source="CONFIRM">http://home.lanck.net/mf/srv/index.htm</ref>
      <ref url="http://xforce.iss.net/static/5524.php" source="XF">small-http-nofile-dos(5524)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="max_feoktistov" name="small_http_server">
        <vers num="2.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0898" published="2001-01-09" name="CVE-2000-0898" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Small HTTP Server 2.01 does not properly process Server Side Includes (SSI) tags that contain null values, which allows local users, and possibly remote attackers, to cause the server to crash by inserting the SSI into an HTML file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97421834001092&amp;w=2" source="BUGTRAQ" adv="1">20001114 Vulnerabilites in SmallHTTP Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="max_feoktistov" name="small_http_server">
        <vers num="2.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0899" published="2001-01-09" name="CVE-2000-0899" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Small HTTP Server 2.01 allows remote attackers to cause a denial of service by connecting to the server and sending out multiple GET, HEAD, or POST requests and closing the connection before the server responds to the requests.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1942" source="BID" patch="1" adv="1">1942</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97421834001092&amp;w=2" source="BUGTRAQ" adv="1">20001114 Vulnerabilites in SmallHTTP Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="max_feoktistov" name="small_http_server">
        <vers num="2.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0900" published="2000-12-19" name="CVE-2000-0900" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in ssi CGI program in thttpd 2.19 and earlier allows remote attackers to read arbitrary files via a "%2e%2e" string, a variation of the .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5313.php" source="XF" patch="1" adv="1">acme-thttpd-ssi</ref>
      <ref url="http://www.securityfocus.com/bid/1737" source="BID" adv="1">1737</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0025.html" source="BUGTRAQ" adv="1">20001002 thttpd ssi: retrieval of arbitrary world-readable files</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:73.thttpd.asc" source="FREEBSD">FreeBSD-SA-00:73</ref>
    </refs>
    <vuln_soft>
      <prod vendor="acme_labs" name="thttpd">
        <vers num="2.16" />
        <vers num="2.17" />
        <vers num="2.18" />
        <vers num="2.19" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0901" published="2000-12-19" name="CVE-2000-0901" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Format string vulnerability in screen 3.9.5 and earlier allows local users to gain root privileges via format characters in the vbell_msg initialization variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5188.php" source="XF" patch="1" adv="1">screen-format-string</ref>
      <ref url="http://www.securityfocus.com/bid/1641" source="BID" patch="1" adv="1">1641</ref>
      <ref url="http://www.securityfocus.com/archive/1/80178" source="BUGTRAQ">20000905 screen 3.9.5 root vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-058.html" source="REDHAT">RHSA-2000:058</ref>
      <ref url="http://www.novell.com/linux/security/advisories/adv6_draht_screen_txt.html" source="SUSE">20000906 screen format string parsing security problem</ref>
      <ref url="http://www.linux-mandrake.com/en/updates/MDKSA-2000-044.php3" source="MANDRAKE">MDKSA-2000:044</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0530.html" source="BUGTRAQ">20000906 Screen-3.7.6 local compromise</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:46.screen.asc" source="FREEBSD">FreeBSD-SA-00:46</ref>
    </refs>
    <vuln_soft>
      <prod vendor="juergen" name="weigert_screen">
        <vers num="3.9.3" />
        <vers num="3.9.4" />
        <vers num="3.9.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0902" published="2000-12-19" name="CVE-2000-0902" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">getalbum.php in PhotoAlbum before 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5209.php" source="XF" adv="1">phpphotoalbum-getalbum-directory-traversal</ref>
      <ref url="http://www.securityfocus.com/archive/1/80858" source="BUGTRAQ">20000907 Re: PhotoAlbum 0.9.9 explorer.php Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nathan_purciful" name="phpphotoalbum">
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0903" published="2000-12-19" name="CVE-2000-0903" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Voyager web server 2.01B in the demo disks for QNX 405 allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1648" source="BID" adv="1">1648</ref>
      <ref url="http://www.securityfocus.com/archive/1/79956" source="BUGTRAQ" adv="1">20000901 Multiple QNX Voyager Issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qnx" name="voyager">
        <vers num="2.01b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0904" published="2000-12-19" name="CVE-2000-0904" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Voyager web server 2.01B in the demo disks for QNX 405 stores sensitive web client information in the .photon directory in the web document root, which allows remote attackers to obtain that information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1648" source="BID" adv="1">1648</ref>
      <ref url="http://www.securityfocus.com/archive/1/79956" source="BUGTRAQ" adv="1">20000901 Multiple QNX Voyager Issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qnx" name="voyager">
        <vers num="2.01b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0905" published="2000-12-19" name="CVE-2000-0905" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">QNX Embedded Resource Manager in Voyager web server 2.01B in the demo disks for QNX 405 allows remote attackers to read sensitive system statistics information via the embedded.html web page.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1648" source="BID" adv="1">1648</ref>
      <ref url="http://www.securityfocus.com/archive/1/79956" source="BUGTRAQ" adv="1">20000901 Multiple QNX Voyager Issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qnx" name="voyager">
        <vers num="2.01b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0906" published="2000-12-19" name="CVE-2000-0906" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Moreover.com cached_feed.cgi script version 4.July.00 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the category or format parameters.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5334.php" source="XF" patch="1" adv="1">moreover-cgi-dir-traverse</ref>
      <ref url="http://www.securityfocus.com/bid/1762" source="BID" patch="1" adv="1">1762</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0013.html" source="BUGTRAQ" patch="1" adv="1">20001002 Moreover Cached_Feed CGI Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moreover.com" name="cached_feed.cgi_script">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0907" published="2000-12-19" name="CVE-2000-0907" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">EServ 2.92 Build 2982 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via long HELO and MAIL FROM commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q3/0131.html" source="WIN2KSEC" patch="1" adv="1">20000925 DST2K0030: DoS in EServ 2.92 Build 2982</ref>
    </refs>
    <vuln_soft>
      <prod vendor="etype" name="eserv">
        <vers num="2.92" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0908" published="2000-12-19" name="CVE-2000-0908" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BrowseGate 2.80 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via long Authorization or Referer MIME headers in the HTTP request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5270.php" source="XF" patch="1" adv="1">browsegate-http-dos</ref>
      <ref url="http://www.securityfocus.com/bid/1702" source="BID" patch="1" adv="1">1702</ref>
      <ref url="http://www.netcplus.com/browsegate.htm#BGLatest" source="CONFIRM">http://www.netcplus.com/browsegate.htm#BGLatest</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96956211605302&amp;w=2" source="BUGTRAQ">20000921 DST2K0031: DoS in BrowseGate(Home) v2.80(H)</ref>
      <ref url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q3/0128.html" source="WIN2KSEC">20000921 DST2K0031: DoS in BrowseGate(Home) v2.80(H)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netcplus" name="browsegate">
        <vers num="2.80" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0909" published="2000-12-19" name="CVE-2000-0909" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the automatic mail checking component of Pine 4.21 and earlier allows remote attackers to execute arbitrary commands via a long From: header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1709" source="BID" patch="1" adv="1">1709</ref>
      <ref url="http://xforce.iss.net/static/5283.php" source="XF" adv="1">pine-check-mail-bo</ref>
      <ref url="http://www.securityfocus.com/archive/1/84901" source="BUGTRAQ">20000922  [ no subject ]</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-102.html" source="REDHAT">RHSA-2000:102</ref>
      <ref url="http://www.linux-mandrake.com/en/security/MDKSA-2000-073.php3" source="MANDRAKE">MDKSA-2000:073</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0441.html" source="BUGTRAQ">20001031 FW: Pine 4.30 now available</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:59.pine.asc" source="FREEBSD">FreeBSD-SA-00:59</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_washington" name="pine">
        <vers num="4.0.4" />
        <vers num="4.10" />
        <vers num="4.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0910" published="2000-12-19" name="CVE-2000-0910" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Horde library 1.02 allows attackers to execute arbitrary commands via shell metacharacters in the "from" address.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5278.php" source="XF" patch="1" adv="1">horde-imp-sendmail-command</ref>
      <ref url="http://www.securityfocus.com/bid/1674" source="BID" patch="1" adv="1">1674</ref>
      <ref url="http://www.debian.org/security/2000/20000910" source="DEBIAN" patch="1" adv="1">20000910 imp: remote compromise</ref>
      <ref url="http://ssl.coc-ag.de/sec/hordelib-1.2.0.frombug.patch" source="CONFIRM">http://ssl.coc-ag.de/sec/hordelib-1.2.0.frombug.patch</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0051.html" source="BUGTRAQ">20000908 horde library bug - unchecked from-address</ref>
    </refs>
    <vuln_soft>
      <prod vendor="horde" name="horde">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0911" published="2000-12-19" name="CVE-2000-0911" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IMP 2.2 and earlier allows attackers to read and delete arbitrary files by modifying the attachment_name hidden form variable, which causes IMP to send the file to the attacker as an attachment.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5227.php" source="XF" patch="1" adv="1">imp-attach-file</ref>
      <ref url="http://www.securityfocus.com/bid/1679" source="BID" patch="1" adv="1">1679</ref>
      <ref url="http://www.securityfocus.com/archive/1/82088" source="BUGTRAQ" patch="1" adv="1">20000912  (SRADV00003) Arbitrary file disclosure through IMP </ref>
    </refs>
    <vuln_soft>
      <prod vendor="horde" name="imp">
        <vers num="2.0" />
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0912" published="2000-12-19" name="CVE-2000-0912" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">MultiHTML CGI script allows remote attackers to read arbitrary files and possibly execute arbitrary commands by specifying the file name to the "multi" parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5285.php" source="XF" adv="1">http-cgi-multihtml</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0146.html" source="BUGTRAQ" adv="1">20000913 MultiHTML vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jcs_web_works" name="multihtml">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0913" published="2000-12-19" name="CVE-2000-0913" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">mod_rewrite in Apache 1.3.12 and earlier allows remote attackers to read arbitrary files if a RewriteRule directive is expanded to include a filename whose name contains a regular expression.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5310.php" source="XF" patch="1" adv="1">apache-rewrite-view-files</ref>
      <ref url="http://www.securityfocus.com/bid/1728" source="BID" patch="1" adv="1">1728</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-095.html" source="REDHAT">RHSA-2000:095</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-088.html" source="REDHAT">RHSA-2000:088</ref>
      <ref url="http://www.linux-mandrake.com/en/security/MDKSA-2000-060-2.php3?dis=7.1" source="MANDRAKE">MDKSA-2000:060</ref>
      <ref url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-035.0.txt" source="CALDERA">CSSA-2000-035.0</ref>
      <ref url="http://archives.neohapsis.com/archives/hp/2000-q4/0021.html" source="HP">HPSBUX0010-126</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0174.html" source="BUGTRAQ">20001011 Conectiva Linux Security Announcement - apache</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0352.html" source="BUGTRAQ">20000929 Security vulnerability in Apache mod_rewrite</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="0.8.11" />
        <vers num="0.8.14" />
        <vers num="1.0" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.5" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.3.11" edition="" />
        <vers num="1.3.11" edition=":win32" />
        <vers num="1.3.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0914" published="2000-12-19" name="CVE-2000-0914" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">OpenBSD 2.6 and earlier allows remote attackers to cause a denial of service by flooding the server with ARP requests.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5340.php" source="XF" patch="1" adv="1">bsd-arp-request-dos</ref>
      <ref url="http://www.securityfocus.com/bid/1759" source="BID" patch="1" adv="1">1759</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0078.html" source="BUGTRAQ" patch="1" adv="1">20001005 obsd_fun.c</ref>
      <ref url="http://www.osvdb.org/1592" source="OSVDB">1592</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0915" published="2000-12-19" name="CVE-2000-0915" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">fingerd in FreeBSD 4.1.1 allows remote attackers to read arbitrary files by specifying the target file name instead of a regular user name.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5385.php" source="XF" patch="1" adv="1">freebsd-fingerd-files</ref>
      <ref url="http://www.securityfocus.com/bid/1803" source="BID" patch="1" adv="1">1803</ref>
      <ref url="http://www.osvdb.org/433" source="OSVDB">433</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0017.html" source="BUGTRAQ">20001002 [sa2c@and.or.jp: bin/21704: enabling fingerd makes files world readable]</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:54.fingerd.asc" source="FREEBSD">FreeBSD-SA-00:54</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.1.1" edition="release" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0916" published="2000-12-19" name="CVE-2000-0916" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">FreeBSD 4.1.1 and earlier, and possibly other BSD-based OSes, uses an insufficient random number generator to generate initial TCP sequence numbers (ISN), which allows remote attackers to spoof TCP connections.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1766" source="BID" patch="1" adv="1">1766</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:52.tcp-iss.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-00:52</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0917" published="2000-12-19" name="CVE-2000-0917" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2000-22.html" source="CERT">CA-2000-22</ref>
      <ref url="http://xforce.iss.net/static/5287.php" source="XF" patch="1" adv="1">lprng-format-string</ref>
      <ref url="http://www.securityfocus.com/bid/1712" source="BID" patch="1" adv="1">1712</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-065.html" source="REDHAT">RHSA-2000:065</ref>
      <ref url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-033.0.txt" source="CALDERA">CSSA-2000-033.0</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0293.html" source="BUGTRAQ">20000925 Format strings: bug #2: LPRng</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:56.lprng.asc" source="FREEBSD">FreeBSD-SA-00:56</ref>
    </refs>
    <vuln_soft>
      <prod vendor="caldera" name="openlinux_ebuilder">
        <vers num="3.0" />
      </prod>
      <prod vendor="caldera" name="openlinux">
        <vers num="" />
      </prod>
      <prod vendor="caldera" name="openlinux_edesktop">
        <vers num="2.4" />
      </prod>
      <prod vendor="caldera" name="openlinux_eserver">
        <vers num="2.3" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.0" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="1.0" />
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0918" published="2000-12-19" name="CVE-2000-0918" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in kvt in KDE 1.1.2 may allow local users to execute arbitrary commands via a DISPLAY environmental variable that contains formatting characters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1700" source="BID" patch="1" adv="1">1700</ref>
      <ref url="http://www.securityfocus.com/archive/1/83914" source="BUGTRAQ" patch="1">20000919 kvt format bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="kvt">
        <vers num="1.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0919" published="2000-12-19" name="CVE-2000-0919" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in PHPix Photo Album 1.0.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5331.php" source="XF" adv="1">phpix-dir-traversal</ref>
      <ref url="http://www.securityfocus.com/bid/1773" source="BID" adv="1">1773</ref>
      <ref url="http://www.osvdb.org/472" source="OSVDB">472</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0117.html" source="BUGTRAQ">20001007 PHPix advisory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpix" name="phpix">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0920" published="2000-12-19" name="CVE-2000-0920" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in BOA web server 0.94.8.2 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack in the GET HTTP request that uses a "%2E" instead of a "."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5330.php" source="XF" patch="1" adv="1">boa-webserver-get-dir-traversal</ref>
      <ref url="http://www.securityfocus.com/bid/1770" source="BID" patch="1" adv="1">1770</ref>
      <ref url="http://www.debian.org/security/2000/20001009" source="DEBIAN">20001009 boa: exposes contents of local files</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0092.html" source="BUGTRAQ">20001006 Vulnerability in BOA web server v0.94.8.2</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:60.boa.asc" source="FREEBSD">FreeBSD-SA-00:60</ref>
    </refs>
    <vuln_soft>
      <prod vendor="boa" name="boa_webserver">
        <vers prev="1" num="0.94.8.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0921" published="2000-12-19" name="CVE-2000-0921" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Hassan Consulting shop.cgi shopping cart program allows remote attackers to read arbitrary files via a .. (dot dot) attack on the page parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5342.php" source="XF" patch="1" adv="1">hassan-shopping-cart-dir-traversal</ref>
      <ref url="http://www.securityfocus.com/bid/1777" source="BID" patch="1" adv="1">1777</ref>
      <ref url="http://www.osvdb.org/1596" source="OSVDB">1596</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0115.html" source="BUGTRAQ">20001007 Security Advisory: Hassan Consulting's shop.cgi Directory Traversal Vulnerability.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hassan_consulting" name="shopping_cart">
        <vers prev="1" num="1.18" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0922" published="2000-12-19" name="CVE-2000-0922" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Bytes Interactive Web Shopper shopping cart program (shopper.cgi) 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack on the newpage parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5351.php" source="XF" patch="1" adv="1">web-shopper-directory-traversal</ref>
      <ref url="http://www.securityfocus.com/bid/1776" source="BID" patch="1" adv="1">1776</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0120.html" source="BUGTRAQ">20001008 Security Advisory: Bytes Interactive's Web Shopper (shopper.cgi) Directory Traversal Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bytes_interactive" name="web_shopper">
        <vers num="1.0" />
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0923" published="2000-12-19" name="CVE-2000-0923" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">authenticate.cgi CGI program in Aplio PRO allows remote attackers to execute arbitrary commands via shell metacharacters in the password parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5333.php" source="XF" adv="1">uclinux-apliophone-bin-execute</ref>
      <ref url="http://www.securityfocus.com/bid/1784" source="BID" adv="1">1784</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0107.html" source="BUGTRAQ" adv="1">20001006 Fwd: APlio PRO web shell</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aplio" name="aplio_phone">
        <vers num="2.0.33_build1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0924" published="2000-12-19" name="CVE-2000-0924" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in search.cgi CGI script in Armada Master Index allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "catigory" parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1772" source="BID" adv="1">1772</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0141.html" source="BUGTRAQ" adv="1">20001009 Master Index traverse advisory</ref>
      <ref url="http://xforce.iss.net/static/5355.php" source="XF">master-index-directory-traversal</ref>
      <ref url="http://www.osvdb.org/461" source="OSVDB">461</ref>
    </refs>
    <vuln_soft>
      <prod vendor="armada_design" name="master_index">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0925" published="2000-12-19" name="CVE-2000-0925" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The default installation of SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) installs the _private directory with world readable permissions, which allows remote attackers to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1734" source="BID" patch="1" adv="1">1734</ref>
      <ref url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q4/0001.html" source="WIN2KSEC" patch="1" adv="1">20001002 DST2K0035: Credit card (customer) details exposed within CyberOff ice Shopping Cart v2</ref>
      <ref url="http://xforce.iss.net/static/5318.php" source="XF">cyberoffice-world-readable-directory</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97050819812055&amp;w=2" source="BUGTRAQ">20001002 DST2K0035: Credit card (customer) details exposed within CyberOff ice Shopping Cart v2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smartwin_technology" name="cyberoffice_shopping_cart">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0926" published="2000-12-19" name="CVE-2000-0926" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) allows remote attackers to modify price information by changing the "Price" hidden form variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1733" source="BID" patch="1" adv="1">1733</ref>
      <ref url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q4/0000.html" source="WIN2KSEC" patch="1" adv="1">20001002 DST2K0036: Price modification possible in CyberOffice Shopping Ca rt</ref>
      <ref url="http://xforce.iss.net/static/5319.php" source="XF">cyberoffice-price-modification</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97050627707128&amp;w=2" source="BUGTRAQ">20001002 DST2K0036: Price modification possible in CyberOffice Shopping Cart</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smartwin_technology" name="cyberoffice_shopping_cart">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0927" published="2000-12-19" name="CVE-2000-0927" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">WQuinn QuotaAdvisor 4.1 does not properly record file sizes if they are stored in alternative data streams, which allows users to bypass quota restrictions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5302.php" source="XF" adv="1">quotaadvisor-quota-bypass</ref>
      <ref url="http://www.securityfocus.com/bid/1724" source="BID" adv="1">1724</ref>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0173.html" source="NTBUGTRAQ">20000928 DST2K0037: QuotaAdvisor 4.1 by WQuinn is susceptible to alternati ve datastreams to bypass quotas.</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09//0331.html" source="BUGTRAQ">20000928 DST2K0037: QuotaAdvisor 4.1 by WQuinn is susceptible to alternati ve datastreams to bypass quotas.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wquinn" name="quotaadvisor">
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0928" published="2000-12-19" name="CVE-2000-0928" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">WQuinn QuotaAdvisor 4.1 allows users to list directories and files by running a report on the targeted shares.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1765" source="BID" adv="1">1765</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0091.html" source="BUGTRAQ" adv="1">20001006 DST2K0040: QuotaAdvisor 4.1 by WQuinn susceptible to any user bei ng able to list (not read) all files on any server running QuotaAdvisor.</ref>
      <ref url="http://xforce.iss.net/static/5327.php" source="XF">quotaadvisor-list-files</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wquinn" name="diskadvisor">
        <vers prev="1" num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0929" published="2000-12-19" name="CVE-2000-0929" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Windows Media Player 7 allows attackers to cause a denial of service in RTF-enabled email clients via an embedded OCX control that is not closed properly, aka the "OCX Attachment" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5309.php" source="XF" patch="1" adv="1">mediaplayer-outlook-dos</ref>
      <ref url="http://www.securityfocus.com/bid/1714" source="BID" patch="1" adv="1">1714</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-068.asp" source="MS" patch="1" adv="1">MS00-068</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97024839222747&amp;w=2" source="BUGTRAQ">20000929 Malformed Embedded Windows Media Player 7 "OCX Attachment"</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_media_player">
        <vers num="7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0930" published="2000-12-19" name="CVE-2000-0930" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Pegasus Mail 3.12 allows remote attackers to read arbitrary files via an embedded URL that calls the mailto: protocol with a -F switch.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1738" source="BID" patch="1" adv="1">1738</ref>
      <ref url="http://xforce.iss.net/static/5326.php" source="XF" adv="1">pegasus-file-forwarding</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0436.html" source="BUGTRAQ" adv="1">20001030 Pegasus Mail file reading vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0039.html" source="BUGTRAQ">20001003 Pegasus mail file reading vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="david_harris" name="pegasus_mail">
        <vers num="3.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0931" published="2000-12-19" name="CVE-2000-0931" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Pegasus Mail 3.11 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long email message containing binary data.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1750" source="BID" adv="1">1750</ref>
      <ref url="http://www.securityfocus.com/archive/1/137518" source="BUGTRAQ" adv="1">20001004 Another Pegasus Mail vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="david_harris" name="pegasus_mail">
        <vers num="3.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0932" published="2000-12-19" name="CVE-2000-0932" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">MAILsweeper for SMTP 3.x does not properly handle corrupt CDA documents in a ZIP file and hangs, which allows remote attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0181.html" source="NTBUGTRAQ">20000926 FW: DOS for Content Technologies' MAILsweeper for SMTP.</ref>
      <ref url="http://xforce.iss.net/static/5641.php" source="XF">mailsweeper-smtp-dos</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clearswift" name="mailsweeper_for_smtp">
        <vers num="3.x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0933" published="2000-12-19" name="CVE-2000-0933" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The Input Method Editor (IME) in the Simplified Chinese version of Windows 2000 does not disable access to privileged functionality that should normally be restricted, which allows local users to gain privileges, aka the "Simplified Chinese IME State Recognition" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5301.php" source="XF" patch="1" adv="1">win2k-simplified-chinese-ime</ref>
      <ref url="http://www.securityfocus.com/bid/1729" source="BID" patch="1" adv="1">1729</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-069.asp" source="MS" patch="1" adv="1">MS00-069</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0934" published="2000-12-19" name="CVE-2000-0934" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Glint in Red Hat Linux 5.2 allows local users to overwrite arbitrary files and cause a denial of service via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5271.php" source="XF" patch="1" adv="1">glint-symlink</ref>
      <ref url="http://www.securityfocus.com/bid/1703" source="BID" patch="1" adv="1">1703</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-062.html" source="REDHAT">RHSA-2000:062</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0935" published="2000-12-19" name="CVE-2000-0935" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows local users to overwrite arbitrary files via a symlink attack on the cgi.log file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1872" source="BID" patch="1" adv="1">1872</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0430.html" source="BUGTRAQ" patch="1" adv="1">20001030 Samba 2.0.7 SWAT vulnerabilities</ref>
      <ref url="http://xforce.iss.net/static/5443.php" source="XF" adv="1">samba-swat-logging-sym-link</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="2.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0936" published="2000-12-19" name="CVE-2000-0936" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Samba Web Administration Tool (SWAT) in Samba 2.0.7 installs the cgi.log logging file with world readable permissions, which allows local users to read sensitive information such as user names and passwords.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1874" source="BID" patch="1" adv="1">1874</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0430.html" source="BUGTRAQ" patch="1" adv="1">20001030 Samba 2.0.7 SWAT vulnerabilities</ref>
      <ref url="http://xforce.iss.net/static/5445.php" source="XF" adv="1">samba-swat-logfile-info</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="2.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0937" published="2000-12-19" name="CVE-2000-0937" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Samba Web Administration Tool (SWAT) in Samba 2.0.7 does not log login attempts in which the username is correct but the password is wrong, which allows remote attackers to conduct brute force password guessing attacks.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0430.html" source="BUGTRAQ" patch="1" adv="1">20001030 Samba 2.0.7 SWAT vulnerabilities</ref>
      <ref url="http://xforce.iss.net/static/5442.php" source="XF" adv="1">samba-swat-brute-force</ref>
      <ref url="http://www.securityfocus.com/bid/1873" source="BID" adv="1">1873</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="2.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0938" published="2000-12-19" name="CVE-2000-0938" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Samba Web Administration Tool (SWAT) in Samba 2.0.7 supplies a different error message when a valid username is provided versus an invalid name, which allows remote attackers to identify valid users on the server.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0430.html" source="BUGTRAQ" patch="1" adv="1">20001030 Samba 2.0.7 SWAT vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5442" source="XF">samba-swat-brute-force(5442)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="2.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0939" published="2000-12-19" name="CVE-2000-0939" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows remote attackers to cause a denial of service by repeatedly submitting a nonstandard URL in the GET HTTP request and forcing it to restart.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0430.html" source="BUGTRAQ" patch="1" adv="1">20001030 Samba 2.0.7 SWAT vulnerabilities</ref>
      <ref url="http://xforce.iss.net/static/5444.php" source="XF" adv="1">samba-swat-url-filename-dos</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="2.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0940" published="2000-12-19" name="CVE-2000-0940" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Metertek pagelog.cgi allows remote attackers to read arbitrary files via a .. (dot dot) attack on the "name" or "display" parameter.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5451.php" source="XF" adv="1">pagelog-cgi-dir-traverse</ref>
      <ref url="http://www.securityfocus.com/bid/1864" source="BID" adv="1">1864</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0422.html" source="BUGTRAQ" adv="1">20001029 Minor bug in Pagelog.cgi</ref>
    </refs>
    <vuln_soft>
      <prod vendor="metertek" name="pagelog.cgi">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0941" published="2000-12-19" name="CVE-2000-0941" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Kootenay Web KW Whois 1.0 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the "whois" parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5438.php" source="XF" patch="1" adv="1">kw-whois-meta</ref>
      <ref url="http://www.securityfocus.com/bid/1883" source="BID" patch="1" adv="1">1883</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0420.html" source="BUGTRAQ" patch="1" adv="1">20001029 Re: Remote command execution via KW Whois 1.0 (addition)</ref>
      <ref url="http://www.kootenayweb.bc.ca/scripts/whois.txt" source="MISC">http://www.kootenayweb.bc.ca/scripts/whois.txt</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0419.html" source="BUGTRAQ">20001029 Remote command execution via KW Whois 1.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kootenay_web_inc" name="kootenay_web_inc_whois">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0942" published="2000-12-19" name="CVE-2000-0942" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">The CiWebHitsFile component in Microsoft Indexing Services for Windows 2000 allows remote attackers to conduct a cross site scripting (CSS) attack via a CiRestriction parameter in a .htw request, aka the "Indexing Services Cross Site Scripting" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1861" source="BID" patch="1" adv="1">1861</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS00-084.asp" source="MS" patch="1" adv="1">MS00-084</ref>
      <ref url="http://xforce.iss.net/static/5441.php" source="XF" adv="1">iis-htw-cross-scripting</ref>
      <ref url="http://www.securityfocus.com/archive/1/141903" source="BUGTRAQ">20001028 IIS 5.0 cross site scripting vulnerability - using .htw</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="indexing_service">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0943" published="2000-12-19" name="CVE-2000-0943" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in bftp daemon (bftpd) 1.0.11 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long USER command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0397.html" source="BUGTRAQ" patch="1" adv="1">20001027 Potential Security Problem in bftpd-1.0.11</ref>
      <ref url="http://xforce.iss.net/static/5426.php" source="XF">bftpd-user-bo</ref>
      <ref url="http://www.securityfocus.com/bid/1858" source="BID">1858</ref>
    </refs>
    <vuln_soft>
      <prod vendor="max-wilhelm_bruker" name="bftpd">
        <vers num="1.0.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0944" published="2000-12-19" name="CVE-2000-0944" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">CGI Script Center News Update 1.1 does not properly validate the original news administration password during a password change operation, which allows remote attackers to modify the password without knowing the original password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5433.php" source="XF" adv="1">news-update-bypass-password</ref>
      <ref url="http://www.securityfocus.com/bid/1881" source="BID" adv="1">1881</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0402.html" source="BUGTRAQ" adv="1">20001027 CGI-Bug: News Update 1.1 administration password bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cgi_script_center" name="news_update">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0945" published="2000-12-19" name="CVE-2000-0945" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The web configuration interface for Catalyst 3500 XL switches allows remote attackers to execute arbitrary commands without authentication when the enable password is not set, via a URL containing the /exec/ directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1846" source="BID" patch="1" adv="1">1846</ref>
      <ref url="http://xforce.iss.net/static/5415.php" source="XF" adv="1">cisco-catalyst-remote-commands(5415)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0380.html" source="BUGTRAQ" adv="1">20001026 Advisory def-2000-02: Cisco Catalyst remote command execution</ref>
      <ref url="http://www.osvdb.org/444" source="OSVDB">444</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0194.html" source="BUGTRAQ">20001113 Re: 3500XL</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="catalyst_3500_xl">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0946" published="2000-12-19" name="CVE-2000-0946" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Compaq Easy Access Keyboard software 1.3 does not properly disable access to custom buttons when the screen is locked, which could allow an attacker to gain privileges or execute programs without authorization.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q4/0023.html" source="NTBUGTRAQ" patch="1" adv="1">20001012 Security issue with Compaq Easy Access Keyboard software</ref>
      <ref url="http://www5.compaq.com/support/files/desktops/us/revision/1723.html" source="CONFIRM">http://www5.compaq.com/support/files/desktops/us/revision/1723.html</ref>
      <ref url="http://xforce.iss.net/static/5718.php" source="XF">compaq-ea-elevate-privileges</ref>
      <ref url="http://www.osvdb.org/5831" source="OSVDB">5831</ref>
    </refs>
    <vuln_soft>
      <prod vendor="compaq" name="easy_access_keyboard_software">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0947" published="2000-12-19" name="CVE-2000-0947" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in cfd daemon in GNU CFEngine before 1.6.0a11 allows attackers to execute arbitrary commands via format characters in the CAUTH command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1757" source="BID" patch="1" adv="1">1757</ref>
      <ref url="http://www.linux-mandrake.com/en/security/MDKSA-2000-061.php3?dis=7.1" source="MANDRAKE" patch="1" adv="1">MDKSA-2000:061</ref>
      <ref url="http://xforce.iss.net/static/5630.php" source="XF">cfengine-cfd-format-string</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0004.html" source="BUGTRAQ">20001002 Very probable remote root vulnerability in cfengine</ref>
      <ref url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-013.txt.asc" source="NETBSD">NetBSD-SA2000-013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="cfengine">
        <vers num="1.5" />
        <vers num="1.5.3-4" />
        <vers num="1.6" edition="a10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0948" published="2000-12-19" name="CVE-2000-0948" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">GnoRPM before 0.95 allows local users to modify arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5317.php" source="XF" patch="1" adv="1">gnorpm-temp-symlink</ref>
      <ref url="http://www.securityfocus.com/bid/1761" source="BID" patch="1" adv="1">1761</ref>
      <ref url="http://www.securityfocus.com/archive/1/136866" source="BUGTRAQ">20001002 GnoRPM local /tmp vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-072.html" source="REDHAT">RHSA-2000:072</ref>
      <ref url="http://www.linux-mandrake.com/en/security/MDKSA-2000-055.php3?dis=7.0" source="MANDRAKE">MDKSA-2000:055</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0184.html" source="BUGTRAQ">20001011 Immunix OS Security Update for gnorpm package</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0043.html" source="BUGTRAQ">20001003 Conectiva Linux Security Announcement - gnorpm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="gnorpm">
        <vers prev="1" num="0.94" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0949" published="2000-12-19" name="CVE-2000-0949" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user to execute arbitrary commands via the -g option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5311.php" source="XF" patch="1" adv="1">traceroute-heap-overflow</ref>
      <ref url="http://www.securityfocus.com/bid/1739" source="BID" patch="1" adv="1">1739</ref>
      <ref url="http://www.turbolinux.com/pipermail/tl-security-announce/2000-October/000025.html" source="TURBO">TLSA2000023-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-078.html" source="REDHAT">RHSA-2000:078</ref>
      <ref url="http://www.linux-mandrake.com/en/security/MDKSA-2000-053.php3?dis=7.1" source="MANDRAKE">MDKSA-2000:053</ref>
      <ref url="http://www.debian.org/security/2000/20001013" source="DEBIAN">20001013 traceroute: local root exploit</ref>
      <ref url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-034.0.txt" source="CALDERA">CSSA-2000-034.0</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0357.html" source="BUGTRAQ">20000930 Conectiva Linux Security Announcement - traceroute</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0344.html" source="BUGTRAQ">20000928 Very interesting traceroute flaw</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lbl" name="lbl_traceroute">
        <vers num="1.4a5" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0950" published="2000-12-19" name="CVE-2000-0950" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in x-gw in TIS Firewall Toolkit (FWTK) allows local users to execute arbitrary commands via a malformed display name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5420.php" source="XF" patch="1" adv="1">tisfwtk-xgw-execute-code</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0376.html" source="BUGTRAQ" patch="1" adv="1">20001026 FWTK x-gw Security Advisory [GSA2000-01]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tis" name="internet_firewall_toolkit">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0951" published="2000-12-19" name="CVE-2000-0951" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">A misconfiguration in IIS 5.0 with Index Server enabled and the Index property set allows remote attackers to list directories in the web root via a Web Distributed Authoring and Versioning (WebDAV) search.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5335.php" source="XF" patch="1" adv="1">iis-index-dir-traverse</ref>
      <ref url="http://www.securityfocus.com/bid/1756" source="BID" patch="1" adv="1">1756</ref>
      <ref url="http://www.microsoft.com/technet/support/kb.asp?ID=272079" source="MSKB">Q272079</ref>
      <ref url="http://www.atstake.com/research/advisories/2000/a100400-1.txt" source="ATSTAKE">A100400-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0952" published="2000-12-19" name="CVE-2000-0952" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">global.cgi CGI program in Global 3.55 and earlier on NetBSD allows remote attackers to execute arbitrary commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5424.php" source="XF" patch="1" adv="1">global-execute-remote-commands</ref>
      <ref url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-014.txt.asc" source="NETBSD" patch="1" adv="1">NetBSD-SA2000-014</ref>
      <ref url="http://www.osvdb.org/6486" source="OSVDB">6486</ref>
    </refs>
    <vuln_soft>
      <prod vendor="shigio_yamaguchi" name="global">
        <vers num="3.55" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0953" published="2000-12-19" name="CVE-2000-0953" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Shambala Server 4.5 allows remote attackers to cause a denial of service by opening then closing a connection.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5345.php" source="XF" adv="1">shambala-connection-dos</ref>
      <ref url="http://www.securityfocus.com/bid/1778" source="BID" adv="1">1778</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0134.html" source="BUGTRAQ" adv="1">20001009 Shambala 4.5 vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="evolvable_corporation" name="shambala_server">
        <vers num="4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0954" published="2000-12-19" name="CVE-2000-0954" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Shambala Server 4.5 stores passwords in plaintext, which could allow local users to obtain the passwords and compromise the server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5346.php" source="XF" adv="1">shambala-password-plaintext</ref>
      <ref url="http://www.securityfocus.com/bid/1771" source="BID" adv="1">1771</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0134.html" source="BUGTRAQ" adv="1">20001009 Shambala 4.5 vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="evolvable_corporation" name="shambala_server">
        <vers num="4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0955" published="2000-12-19" name="CVE-2000-0955" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cisco Virtual Central Office 4000 (VCO/4K) uses weak encryption to store usernames and passwords in the SNMP MIB, which allows an attacker who knows the community name to crack the password and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5425.php" source="XF" patch="1" adv="1">cisco-vco-snmp-passwords</ref>
      <ref url="http://www.securityfocus.com/bid/1885" source="BID" patch="1" adv="1">1885</ref>
      <ref url="http://www.atstake.com/research/advisories/2000/a102600-1.txt" source="ATSTAKE" patch="1" adv="1">A102600-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="virtual_central_office_4000">
        <vers prev="1" num="5.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0956" published="2000-12-19" name="CVE-2000-0956" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">cyrus-sasl before 1.5.24 in Red Hat Linux 7.0 does not properly verify the authorization for a local user, which could allow the users to bypass specified access restrictions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5427.php" source="XF" patch="1" adv="1">cyrus-sasl-gain-access</ref>
      <ref url="http://www.securityfocus.com/bid/1875" source="BID" patch="1" adv="1">1875</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-094.html" source="REDHAT" patch="1" adv="1">RHSA-2000:094</ref>
    </refs>
    <vuln_soft>
      <prod vendor="carnegie_mellon_university" name="cyrus-sasl">
        <vers num="1.5.24" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0957" published="2000-12-19" name="CVE-2000-0957" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The pluggable authentication module for mysql (pam_mysql) before 0.4.7 does not properly cleanse user input when constructing SQL statements, which allows attackers to obtain plaintext passwords or hashes.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5447.php" source="XF" patch="1" adv="1">pammysql-auth-input</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0374.html" source="BUGTRAQ" patch="1" adv="1">20001026 (SRADV00004) Remote and local vulnerabilities in pam_mysql</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pam_mysql" name="pam_mysql">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0958" published="2000-12-19" name="CVE-2000-0958" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">HotJava Browser 3.0 allows remote attackers to access the DOM of a web page by opening a javascript: URL in a named window.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5428.php" source="XF" patch="1" adv="1">hotjava-browser-dom-access</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0349.html" source="BUGTRAQ" patch="1" adv="1">20001025 HotJava Browser 3.0 JavaScript security vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="hotjava_browser">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0959" published="2000-12-19" name="CVE-2000-0959" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">glibc2 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environmental variables when a program is spawned from a setuid program, which could allow local users to overwrite files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5299.php" source="XF" adv="1">glibc-unset-symlink</ref>
      <ref url="http://www.securityfocus.com/bid/1719" source="BID" adv="1">1719</ref>
      <ref url="http://www.securityfocus.com/archive/1/85028" source="BUGTRAQ">20000926 ld.so bug - LD_DEBUG_OUTPUT follows symlinks</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="glibc">
        <vers num="2.1.3.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0960" published="2000-12-19" name="CVE-2000-0960" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The POP3 server in Netscape Messaging Server 4.15p1 generates different error messages for incorrect user names versus incorrect passwords, which allows remote attackers to determine valid users on the system and harvest email addresses for spam abuse.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5364.php" source="XF" adv="1">netscape-messaging-email-verify</ref>
      <ref url="http://www.securityfocus.com/bid/1787" source="BID" adv="1">1787</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97138100426121&amp;w=2" source="BUGTRAQ">20001011 Netscape Messaging server 4.15 poor error strings</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="messaging_server">
        <vers num="4.15" edition="patch1" />
        <vers num="4.15" edition="patch2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0961" published="2000-12-19" name="CVE-2000-0961" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in IMAP server in Netscape Messaging Server 4.15 Patch 2 allows local users to execute arbitrary commands via a long LIST command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5292.php" source="XF" adv="1">netscape-messaging-list-dos</ref>
      <ref url="http://www.securityfocus.com/bid/1721" source="BID" adv="1">1721</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0334.html" source="BUGTRAQ">20000928 commercial products and security [ + new bug ]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="messaging_server">
        <vers num="4.0" />
      </prod>
      <prod vendor="netscape" name="netscape_messaging_server_multiplexor">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0962" published="2000-12-19" name="CVE-2000-0962" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The IPSEC implementation in OpenBSD 2.7 does not properly handle empty AH/ESP packets, which allows remote attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1723" source="BID" patch="1" adv="1">1723</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0299.html" source="BUGTRAQ" patch="1" adv="1">20000925 Nmap Protocol Scanning DoS against OpenBSD IPSEC</ref>
      <ref url="http://xforce.iss.net/static/5634.php" source="XF">openbsd-nmap-dos</ref>
      <ref url="http://www.osvdb.org/1574" source="OSVDB">1574</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0963" published="2000-12-19" name="CVE-2000-0963" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in ncurses library allows local users to execute arbitrary commands via long environmental information such as TERM or TERMINFO_DIRS.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1142" source="BID" patch="1" adv="1">1142</ref>
      <ref url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-036.0.txt" source="CALDERA" patch="1" adv="1">CSSA-2000-036.0</ref>
      <ref url="http://www.securityfocus.com/archive/1/138550" source="BUGTRAQ">20001009 ncurses buffer overflows</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/44487" source="XF">gnu-ncurses-term-terminfodirs-bo(44487)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="immunix" name="immunix">
        <vers num="6.2" />
        <vers num="7.0_beta" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.4" />
        <vers num="3.5.1" />
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.1.1" edition="stable" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="6.2" edition="" />
        <vers num="6.2" edition=":alpha" />
        <vers num="6.2" edition=":sparc" />
        <vers num="6.2" edition=":i386" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0964" published="2000-12-19" name="CVE-2000-0964" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the web administration service for the HiNet LP5100 IP-phone allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5298.php" source="XF" adv="1">hinet-ipphone-get-bo</ref>
      <ref url="http://www.securityfocus.com/bid/1727" source="BID" adv="1">1727</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0336.html" source="BUGTRAQ">20000928 Another thingy.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="siemens" name="hinet_lp">
        <vers num="5100.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0965" published="2000-12-19" name="CVE-2000-0965" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The NSAPI plugins for TGA and the Java Servlet proxy in HP-UX VVOS 10.24 and 11.04 allows an attacker to cause a denial of service (high CPU utilization).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5361.php" source="XF" patch="1" adv="1">hp-virtualvault-nsapi-dos</ref>
      <ref url="http://archives.neohapsis.com/archives/hp/2000-q4/0012.html" source="HP" patch="1" adv="1">HPSBUX0010-124</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="vvos">
        <vers num="10.24" />
        <vers num="11.04" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0966" published="2000-12-19" name="CVE-2000-0966" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflows in lpspooler in the fileset PrinterMgmt.LP-SPOOL of HP-UX 11.0 and earlier allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5379.php" source="XF" patch="1" adv="1">hp-lpspooler-bo</ref>
      <ref url="http://archives.neohapsis.com/archives/hp/2000-q4/0020.html" source="HP" patch="1" adv="1">HPSBUX0010-125</ref>
      <ref url="http://www.osvdb.org/7244" source="OSVDB">7244</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.00" />
        <vers num="11.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0967" published="2000-12-19" name="CVE-2000-0967" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands by triggering error messages that are improperly written to the error logs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5359.php" source="XF" patch="1" adv="1">php-logging-format-string</ref>
      <ref url="http://www.securityfocus.com/bid/1786" source="BID" patch="1" adv="1">1786</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-095.html" source="REDHAT">RHSA-2000:095</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-088.html" source="REDHAT">RHSA-2000:088</ref>
      <ref url="http://www.linux-mandrake.com/en/security/MDKSA-2000-062.php3?dis=7.1" source="MANDRAKE">MDKSA-2000:062</ref>
      <ref url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-037.0.txt" source="CALDERA">CSSA-2000-037.0</ref>
      <ref url="http://www.atstake.com/research/advisories/2000/a101200-1.txt" source="ATSTAKE">A101200-1</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0204.html" source="BUGTRAQ">20001012 Conectiva Linux Security Announcement - mod_php3</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:75.php.asc" source="FREEBSD">FreeBSD-SA-00:75</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="3.0" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0968" published="2000-12-19" name="CVE-2000-0968" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Half Life dedicated server before build 3104 allows remote attackers to execute arbitrary commands via a long rcon command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5375.php" source="XF" patch="1" adv="1">halflife-server-changelevel-bo</ref>
      <ref url="http://www.securityfocus.com/bid/1799" source="BID" patch="1" adv="1">1799</ref>
      <ref url="http://www.securityfocus.com/archive/1/141060" source="BUGTRAQ">20001024 Tamandua Sekure Labs Security Advisory 2000-01</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0409.html" source="BUGTRAQ">20001027 Re: Half Life dedicated server Patch</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0254.html" source="BUGTRAQ">20001016 Half-Life Dedicated Server Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="valve_software" name="half-life_dedicated_server">
        <vers prev="1" num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0969" published="2000-12-19" name="CVE-2000-0969" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in Half Life dedicated server build 3104 and earlier allows remote attackers to execute arbitrary commands by injecting format strings into the changelevel command, via the system console or rcon.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5413.php" source="XF" patch="1" adv="1">halflife-rcon-format-string</ref>
      <ref url="http://www.securityfocus.com/archive/1/141060" source="BUGTRAQ">20001024 Tamandua Sekure Labs Security Advisory 2000-01</ref>
      <ref url="http://www.osvdb.org/6983" source="OSVDB">6983</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0409.html" source="BUGTRAQ">20001027 Re: Half Life dedicated server Patch</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0254.html" source="BUGTRAQ">20001016 Half-Life Dedicated Server Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="valve_software" name="half-life_dedicated_server">
        <vers num="3.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0970" published="2000-12-19" name="CVE-2000-0970" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">IIS 4.0 and 5.0 .ASP pages send the same Session ID cookie for secure and insecure web sessions, which could allow remote attackers to hijack the secure web session of the user if that user moves to an insecure session, aka the "Session ID Cookie Marking" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5396.php" source="XF" patch="1" adv="1">session-cookie-remote-retrieval</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-080.asp" source="MS" patch="1" adv="1">MS00-080</ref>
      <ref url="http://www.osvdb.org/7265" source="OSVDB">7265</ref>
      <ref url="http://www.acrossecurity.com/aspr/ASPR-2000-07-22-1-PUB.txt" source="MISC">http://www.acrossecurity.com/aspr/ASPR-2000-07-22-1-PUB.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0971" published="2000-12-19" name="CVE-2000-0971" modified="2009-04-03" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Avirt Mail 4.0 and 4.2 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long "RCPT TO" or "MAIL FROM" command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5398.php" source="XF" adv="1">avirt-rcpt-to-dos</ref>
      <ref url="http://xforce.iss.net/static/5397.php" source="XF" adv="1">avirt-mail-from-dos</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0301.html" source="BUGTRAQ" adv="1">20001023 Avirt Mail 4.x DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avirt" name="avirt_mail_server">
        <vers num="4.0" />
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-0972" published="2000-12-19" name="CVE-2000-0972" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">HP-UX 11.00 crontab allows local users to read arbitrary files via the -e option by creating a symlink to the target file during the crontab session, quitting the session, and reading the error messages that crontab generates.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5410.php" source="XF" adv="1">hp-crontab-read-files</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0317.html" source="BUGTRAQ" adv="1">20001020 [ Hackerslab bug_paper ] HP-UX crontab temporary file symbolic link vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.20" />
        <vers num="11.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0973" published="2000-12-19" name="CVE-2000-0973" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in curl earlier than 6.0-1.1, and curl-ssl earlier than 6.0-1.2, allows remote attackers to execute arbitrary commands by forcing a long error message to be generated.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5374.php" source="XF" patch="1" adv="1">curl-error-bo</ref>
      <ref url="http://www.securityfocus.com/bid/1804" source="BID" patch="1" adv="1">1804</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0331.html" source="REDHAT">RHBA-2000:092-01</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:72.curl.asc" source="FREEBSD">FreeBSD-SA-00:72</ref>
    </refs>
    <vuln_soft>
      <prod vendor="daniel_stenberg" name="curl">
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.1beta" />
        <vers num="6.3" />
        <vers num="6.4" />
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="7.2" />
        <vers num="7.2.1" />
        <vers num="7.3" />
        <vers num="7.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0974" published="2000-12-19" name="CVE-2000-0974" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">GnuPG (gpg) 1.0.3 does not properly check all signatures of a file containing multiple documents, which allows an attacker to modify contents of all documents but the first without detection.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5386.php" source="XF" patch="1" adv="1">gnupg-message-modify</ref>
      <ref url="http://www.securityfocus.com/bid/1797" source="BID" patch="1" adv="1">1797</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-089.html" source="REDHAT">RHSA-2000:089</ref>
      <ref url="http://www.osvdb.org/1608" source="OSVDB">1608</ref>
      <ref url="http://www.debian.org/security/2000/20001111" source="DEBIAN">20001111 gnupg: incorrect signature verification</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000334" source="CONECTIVA">CLSA-2000:334</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0361.html" source="BUGTRAQ">20001025 Immunix OS Security Update for gnupg package</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0201.html" source="BUGTRAQ">20001011 GPG 1.0.3 doesn't detect modifications to files with multiple signatures</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:67.gnupg.asc" source="FREEBSD">FreeBSD-SA-00:67</ref>
      <ref url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2000-038.0.txt" source="CALDERA">CSSA-2000-038.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="privacy_guard">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0975" published="2000-12-19" name="CVE-2000-0975" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in apexec.pl in Anaconda Foundation Directory allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0210.html" source="BUGTRAQ" adv="1">20001012 Anaconda Advisory</ref>
      <ref url="http://xforce.iss.net/static/5750.php" source="XF">anaconda-apexec-directory-traversal</ref>
      <ref url="http://www.osvdb.org/435" source="OSVDB">435</ref>
    </refs>
    <vuln_soft>
      <prod vendor="anaconda_partners" name="foundation_directory">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0976" published="2000-12-19" name="CVE-2000-0976" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in xlib in XFree 3.3.x possibly allows local users to execute arbitrary commands via a long DISPLAY environment variable or a -display command line parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1805" source="BID" adv="1">1805</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0211.html" source="BUGTRAQ" adv="1">20001012 another Xlib buffer overflow</ref>
      <ref url="http://www.iss.net/security_center/static/5751.php" source="XF">xfree-xlib-bo(5751)</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20020502-01-I" source="SGI">20020502-01-I</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xfree86_project" name="xlib">
        <vers num="3.3x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0977" published="2000-12-19" name="CVE-2000-0977" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">mailfile.cgi CGI program in MailFile 1.10 allows remote attackers to read arbitrary files by specifying the target file name in the "filename" parameter in a POST request, which is then sent by email to the address specified in the "email" parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1807" source="BID" adv="1">1807</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0172.html" source="BUGTRAQ" adv="1">20001011 Mail File POST Vulnerability</ref>
      <ref url="http://xforce.iss.net/static/5358.php" source="XF">mailfile-post-file-read</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oatmeal_studios" name="mail_file">
        <vers num="1.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0978" published="2000-12-19" name="CVE-2000-0978" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">bbd server in Big Brother System and Network Monitor before 1.5c2 allows remote attackers to execute arbitrary commands via the "&amp;" shell metacharacter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1779" source="BID" patch="1" adv="1">1779</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0162.html" source="BUGTRAQ" patch="1" adv="1">20001010 Big Brother Systems and Network Monitor vulnerability</ref>
      <ref url="http://xforce.iss.net/static/5719.php" source="XF">bb4-netmon-execute-commands</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bb4" name="big_brother_network_monitor">
        <vers num="1.5c2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0979" published="2000-12-19" name="CVE-2000-0979" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">File and Print Sharing service in Windows 95, Windows 98, and Windows Me does not properly check the password for a file share, which allows remote attackers to bypass share access controls by sending a 1-byte password that matches the first character of the real password, aka the "Share Level Password" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5395.php" source="XF" patch="1" adv="1">win9x-share-level-password</ref>
      <ref url="http://www.securityfocus.com/bid/1780" source="BID" patch="1" adv="1">1780</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS00-072.asp" source="MS" patch="1" adv="1">MS00-072</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97147777618139&amp;w=2" source="BUGTRAQ">20001012 NSFOCUS SA2000-05: Microsoft Windows 9x NETBIOS password</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:996" source="OVAL" sig="1">oval:org.mitre.oval:def:996</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_95">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0980" published="2000-12-19" name="CVE-2000-0980" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">NMPI (Name Management Protocol on IPX) listener in Microsoft NWLink does not properly filter packets from a broadcast address, which allows remote attackers to cause a broadcast storm and flood the network.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5357.php" source="XF" patch="1" adv="1">win-nmpi-packet-dos</ref>
      <ref url="http://www.securityfocus.com/bid/1781" source="BID" patch="1" adv="1">1781</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS00-073.asp" source="MS" patch="1" adv="1">MS00-073</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_95">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0981" published="2000-12-19" name="CVE-2000-0981" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">MySQL Database Engine uses a weak authentication method which leaks information that could be used by a remote attacker to recover the password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5409.php" source="XF" patch="1" adv="1">mysql-authentication</ref>
      <ref url="http://www.mysql.com/documentation/mysql/commented/manual.php?section=Security" source="CONFIRM">http://www.mysql.com/documentation/mysql/commented/manual.php?section=Security</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0318.html" source="BUGTRAQ">20001023 [CORE SDI ADVISORY] MySQL weak authentication</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="3.20" />
        <vers num="3.21" />
        <vers num="3.22" />
        <vers num="3.23" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0982" published="2000-12-19" name="CVE-2000-0982" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Internet Explorer before 5.5 forwards cached user credentials for a secure web site to insecure pages on the same web site, which could allow remote attackers to obtain the credentials by monitoring connections to the web server, aka the "Cached Web Credentials" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5367.php" source="XF" patch="1" adv="1">ie-cache-info</ref>
      <ref url="http://www.securityfocus.com/bid/1793" source="BID" patch="1" adv="1">1793</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS00-076.asp" source="MS" patch="1" adv="1">MS00-076</ref>
      <ref url="http://www.acrossecurity.com/aspr/ASPR-2000-07-22-2-PUB.txt" source="MISC">http://www.acrossecurity.com/aspr/ASPR-2000-07-22-2-PUB.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="4.1" />
        <vers num="5.0" />
        <vers num="5.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0983" published="2000-12-19" name="CVE-2000-0983" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft NetMeeting with Remote Desktop Sharing enabled allows remote attackers to cause a denial of service (CPU utilization) via a sequence of null bytes to the NetMeeting port, aka the "NetMeeting Desktop Sharing" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5368.php" source="XF" patch="1" adv="1">netmeeting-desktop-sharing-dos</ref>
      <ref url="http://www.securityfocus.com/bid/1798" source="BID" patch="1" adv="1">1798</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q273854" source="MSKB">Q273854</ref>
      <ref url="http://www.securityfocus.com/archive/1/140341" source="BUGTRAQ">20001018 Denial of Service attack against computers running Microsoft NetMeeting</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-077.asp" source="MS">MS00-077</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="netmeeting">
        <vers num="3.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0984" published="2000-12-19" name="CVE-2000-0984" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The HTTP server in Cisco IOS 12.0 through 12.1 allows local users to cause a denial of service (crash and reload) via a URL containing a "?/" string.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1838" source="BID" patch="1" adv="1">1838</ref>
      <ref url="http://www.cisco.com/warp/public/707/ioshttpserverquery-pub.shtml" source="CISCO" patch="1" adv="1">20001025 Cisco IOS HTTP Server Query Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5412" source="XF">cisco-ios-query-dos(5412)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.0t" />
        <vers num="12.0w5" />
        <vers num="12.0xa" />
        <vers num="12.0xe" />
        <vers num="12.0xh" />
        <vers num="12.0xj" />
        <vers num="12.1aa" />
        <vers num="12.1da" />
        <vers num="12.1db" />
        <vers num="12.1dc" />
        <vers num="12.1ec" />
        <vers num="12.1t" />
        <vers num="12.1xa" />
        <vers num="12.1xb" />
        <vers num="12.1xc" />
        <vers num="12.1xd" />
        <vers num="12.1xe" />
        <vers num="12.1xf" />
        <vers num="12.1xg" />
        <vers num="12.1xh" />
        <vers num="12.1xi" />
        <vers num="12.1xj" />
        <vers num="12.1xl" />
        <vers num="12.1xp" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0985" published="2000-12-19" name="CVE-2000-0985" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in All-Mail 1.1 allows remote attackers to execute arbitrary commands via a long "MAIL FROM" or "RCPT TO" command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1789" source="BID" patch="1" adv="1">1789</ref>
      <ref url="http://www.atstake.com/research/advisories/2000/a101200-2.txt" source="ATSTAKE" patch="1" adv="1">A101200-2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nevis_systems" name="all-mail">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0986" published="2000-12-19" name="CVE-2000-0986" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in Oracle 8.1.5 applications such as names, namesctl, onrsd, osslogin, tnslsnr, tnsping, trcasst, and trcroute possibly allow local users to gain privileges via a long ORACLE_HOME environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5390.php" source="XF" patch="1" adv="1">oracle-home-bo</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0294.html" source="BUGTRAQ" adv="1">20001020 [ Hackerslab bug_paper ] Linux ORACLE 8.1.5 vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="oracle8i">
        <vers num="8.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0987" published="2000-12-19" name="CVE-2000-0987" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in oidldapd in Oracle 8.1.6 allow local users to gain privileges via a long "connect" command line parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5401.php" source="XF" patch="1" adv="1">oracle-oidldap-bo</ref>
      <ref url="http://www.securityfocus.com/archive/1/140709" source="BUGTRAQ" adv="1">20001020 In response to posting 10/18/2000 vulnerability in Oracle Internet Directory in Oracle 8.1.6</ref>
      <ref url="http://www.securityfocus.com/archive/1/140340" source="BUGTRAQ">20001018 vulnerability in Oracle Internet Directory in Oracle 8.1.6</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="internet_directory">
        <vers num="2.0.6" />
      </prod>
      <prod vendor="oracle" name="oracle8i">
        <vers num="8.1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0988" published="2000-12-19" name="CVE-2000-0988" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">WinU 1.0 through 5.1 has a backdoor password that allows remote attackers to gain access to its administrative interface and modify configuration.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5376.php" source="XF" patch="1" adv="1">winu-backdoor</ref>
      <ref url="http://www.securityfocus.com/bid/1801" source="BID" patch="1" adv="1">1801</ref>
      <ref url="http://www.bardon.com/pwdcrack.htm" source="CONFIRM">http://www.bardon.com/pwdcrack.htm</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0238.html" source="BUGTRAQ">20001013 WinU Backdoor passwords!!!!</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bardon_data_systems" name="winu">
        <vers prev="1" num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0989" published="2000-12-19" name="CVE-2000-0989" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Intel InBusiness eMail Station 1.04.87 POP service allows remote attackers to cause a denial of service and possibly execute commands via a long username.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5414.php" source="XF" adv="1">intel-email-username-bo</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0293.html" source="BUGTRAQ" adv="1">20001020 DoS in Intel corporation 'InBusiness eMail Station'</ref>
      <ref url="http://www.osvdb.org/6488" source="OSVDB">6488</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intel" name="inbusiness_email_station">
        <vers num="1.4.87" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0990" published="2000-12-19" name="CVE-2000-0990" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">cmd5checkpw 0.21 and earlier allows remote attackers to cause a denial of service via an "SMTP AUTH" command with an unknown username.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5382.php" source="XF" patch="1" adv="1">cmd5checkpw-qmail-bypass-authentication</ref>
      <ref url="http://www.securityfocus.com/bid/1809" source="BID" patch="1" adv="1">1809</ref>
      <ref url="http://members.elysium.pl/brush/cmd5checkpw/changes.html" source="CONFIRM">http://members.elysium.pl/brush/cmd5checkpw/changes.html</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0258.html" source="BUGTRAQ" adv="1">20001016 Authentication failure in cmd5checkpw 0.21</ref>
    </refs>
    <vuln_soft>
      <prod vendor="krzysztof_dabrowski" name="cmd5checkpw">
        <vers num="0.20" />
        <vers num="0.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0991" published="2000-12-19" name="CVE-2000-0991" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Hilgraeve, Inc. HyperTerminal client on Windows 98, ME, and 2000 allows remote attackers to execute arbitrary commands via a long telnet URL, aka the "HyperTerminal Buffer Overflow" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5387.php" source="XF" patch="1" adv="1">win-hyperterminal-telnet-bo</ref>
      <ref url="http://www.securityfocus.com/bid/1815" source="BID" patch="1" adv="1">1815</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-079.asp" source="MS" patch="1" adv="1">MS00-079</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hilgraeve" name="hyperterminal">
        <vers prev="1" num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-0992" published="2000-12-19" name="CVE-2000-0992" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in scp in sshd 1.2.xx allows a remote malicious scp server to overwrite arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1742" source="BID" patch="1" adv="1">1742</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0359.html" source="BUGTRAQ" adv="1">20000930 scp file transfer hole</ref>
      <ref url="http://xforce.iss.net/static/5312.php" source="XF">scp-overwrite-files</ref>
      <ref url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2000:057" source="MANDRAKE">MDKSA-2000:057</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openssh">
        <vers num="1.2" />
        <vers num="1.2.3" />
      </prod>
      <prod vendor="ssh" name="ssh">
        <vers num="1.2.14" />
        <vers num="1.2.15" />
        <vers num="1.2.16" />
        <vers num="1.2.17" />
        <vers num="1.2.18" />
        <vers num="1.2.19" />
        <vers num="1.2.20" />
        <vers num="1.2.21" />
        <vers num="1.2.22" />
        <vers num="1.2.23" />
        <vers num="1.2.24" />
        <vers num="1.2.25" />
        <vers num="1.2.26" />
        <vers num="1.2.27" />
        <vers num="1.2.28" />
        <vers num="1.2.29" />
        <vers num="1.2.30" />
        <vers num="1.2.31" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0993" published="2000-12-19" name="CVE-2000-0993" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in pw_error function in BSD libutil library allows local users to gain root privileges via a malformed password in commands such as chpass or passwd.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5339.php" source="XF" patch="1" adv="1">bsd-libutil-format</ref>
      <ref url="http://www.securityfocus.com/bid/1744" source="BID" patch="1" adv="1">1744</ref>
      <ref url="http://www.openbsd.org/errata27.html#pw_error" source="OPENBSD">20001003 A format string vulnerability exists in the pw_error(3) function.</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97068555106135&amp;w=2" source="BUGTRAQ">20001004 Re: OpenBSD Security Advisory</ref>
      <ref url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-015.txt.asc" source="NETBSD">NetBSD-SA2000-015</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:58.chpass.asc" source="FREEBSD">FreeBSD-SA-00:58</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="3.5" />
        <vers num="4.0" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.6" />
        <vers num="2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0994" published="2000-12-19" name="CVE-2000-0994" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in OpenBSD fstat program (and possibly other BSD-based operating systems) allows local users to gain root privileges via the PWD environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5338.php" source="XF" patch="1" adv="1">bsd-fstat-format</ref>
      <ref url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch" source="MISC" patch="1">ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch</ref>
      <ref url="http://www.securityfocus.com/bid/1746" source="BID" adv="1">1746</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97068555106135&amp;w=2" source="BUGTRAQ">20001004 Re: OpenBSD Security Advisory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.6" />
        <vers num="2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0995" published="2000-12-19" name="CVE-2000-0995" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in OpenBSD yp_passwd program (and possibly other BSD-based operating systems) allows attackers to gain root privileges a malformed name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch" source="MISC" patch="1">ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch</ref>
      <ref url="http://xforce.iss.net/static/5635.php" source="XF">bsd-yp-passwd-format</ref>
      <ref url="http://www.osvdb.org/6125" source="OSVDB">6125</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0996" published="2000-12-19" name="CVE-2000-0996" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in OpenBSD su program (and possibly other BSD-based operating systems) allows local attackers to gain root privileges via a malformed shell.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch" source="MISC" patch="1">ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch</ref>
      <ref url="http://xforce.iss.net/static/5636.php" source="XF">bsd-su-format</ref>
      <ref url="http://www.osvdb.org/6124" source="OSVDB">6124</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0997" published="2000-12-19" name="CVE-2000-0997" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerabilities in eeprom program in OpenBSD, NetBSD, and possibly other operating systems allows local attackers to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5337.php" source="XF" patch="1" adv="1">bsd-eeprom-format</ref>
      <ref url="http://www.securityfocus.com/bid/1752" source="BID" patch="1" adv="1">1752</ref>
      <ref url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch" source="MISC">ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.6" />
        <vers num="2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0998" published="2000-12-11" name="CVE-2000-0998" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in top program allows local attackers to gain root privileges via the "kill" or "renice" function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1895" source="BID" patch="1" adv="1">1895</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:62.top.v1.1.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-00:62</ref>
      <ref url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch" source="MISC">ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.5" edition="stable" />
        <vers num="3.5.1" edition="release" />
        <vers num="3.5.1" edition="stable" />
        <vers num="4.0" edition="alpha" />
        <vers num="4.1" />
        <vers num="4.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-0999" published="2000-12-11" name="CVE-2000-0999" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerabilities in OpenBSD ssh program (and possibly other BSD-based operating systems) allow attackers to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch" source="MISC" patch="1" adv="1">ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openssh">
        <vers num="4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1000" published="2000-12-11" name="CVE-2000-1000" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Format string vulnerability in AOL Instant Messenger (AIM) 4.1.2010 allows remote attackers to cause a denial of service and possibly execute arbitrary commands by transferring a file whose name includes format characters.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5314.php" source="XF" adv="1">aim-file-transfer-dos</ref>
      <ref url="http://www.securityfocus.com/bid/1747" source="BID" adv="1">1747</ref>
      <ref url="http://www.securityfocus.com/archive/1/137374" source="BUGTRAQ" adv="1">20001003 AOL Instant Messenger DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aol" name="instant_messenger">
        <vers num="4.1.2010" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1001" published="2000-12-11" name="CVE-2000-1001" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">add_2_basket.asp in Element InstantShop allows remote attackers to modify price information via the "price" hidden form variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97240616129614&amp;w=2" source="BUGTRAQ" adv="1">20001024 Price modification in Element InstantShop</ref>
      <ref url="http://xforce.iss.net/static/5402.php" source="XF">instantshop-modify-price</ref>
      <ref url="http://www.osvdb.org/6487" source="OSVDB">6487</ref>
    </refs>
    <vuln_soft>
      <prod vendor="element_n.v" name="element_instantshop">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1002" published="2000-12-11" name="CVE-2000-1002" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">POP3 daemon in Stalker CommuniGate Pro 3.3.2 generates different error messages for invalid usernames versus invalid passwords, which allows remote attackers to determine valid email addresses on the server for SPAM attacks.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5363.php" source="XF" adv="1">communigate-email-verify</ref>
      <ref url="http://www.securityfocus.com/bid/1792" source="BID" adv="1">1792</ref>
      <ref url="http://www.securityfocus.com/archive/1/139523" source="BUGTRAQ" adv="1">20001012 Re: Netscape Messaging server 4.15 poor error strings</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stalker" name="communigate_pro">
        <vers num="3.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-1003" published="2000-12-11" name="CVE-2000-1003" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">NETBIOS client in Windows 95 and Windows 98 allows a remote attacker to cause a denial of service by changing a file sharing service to return an unknown driver type, which causes the client to crash.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5370.php" source="XF" patch="1" adv="1">win-netbios-driver-type-dos</ref>
      <ref url="http://www.securityfocus.com/bid/1794" source="BID" adv="1">1794</ref>
      <ref url="http://www.securityfocus.com/archive/1/139511" source="BUGTRAQ">20001012 NSFOCUS SA2000-04: Microsoft Win9x client driver type comparing vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_95">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1004" published="2000-12-11" name="CVE-2000-1004" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Format string vulnerability in OpenBSD photurisd allows local users to execute arbitrary commands via a configuration file directory name that contains formatting characters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5336.php" source="XF" patch="1" adv="1">bsd-photurisd-format</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97068555106135&amp;w=2" source="BUGTRAQ" adv="1">20001004 Re: OpenBSD Security Advisory</ref>
      <ref url="http://www.osvdb.org/6123" source="OSVDB">6123</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.6" />
        <vers num="2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1005" published="2000-12-11" name="CVE-2000-1005" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in html_web_store.cgi and web_store.cgi CGI programs in eXtropia WebStore allows remote attackers to read arbitrary files via a .. (dot dot) attack on the page parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5347.php" source="XF" patch="1" adv="1">extropia-webstore-fileread</ref>
      <ref url="http://www.securityfocus.com/bid/1774" source="BID" patch="1" adv="1">1774</ref>
      <ref url="http://www.securityfocus.com/archive/1/138495" source="BUGTRAQ">20001009 Security Advisory : eXtropia WebStore (web_store.cgi) Directory Traversal Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="extropia" name="extropia_webstore">
        <vers num="1.0" />
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1006" published="2000-12-11" name="CVE-2000-1006" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Exchange Server 5.5 does not properly handle a MIME header with a blank charset specified, which allows remote attackers to cause a denial of service via a charset="" command, aka the "Malformed MIME Header" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5448.php" source="XF" patch="1" adv="1">ms-exchange-mime-dos</ref>
      <ref url="http://www.securityfocus.com/bid/1869" source="BID" patch="1" adv="1">1869</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-082.asp" source="MS" patch="1" adv="1">MS00-082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1007" published="2000-12-11" name="CVE-2000-1007" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">I-gear 3.5.7 and earlier does not properly process log entries in which a URL is longer than 255 characters, which allows an attacker to cause reporting errors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q4/0048.html" source="NTBUGTRAQ" patch="1" adv="1">20001025 I-gear 3.5.x for Microsoft Proxy logging vulnerability + temporary fix.</ref>
      <ref url="http://xforce.iss.net/static/5791.php" source="XF">igear-invalid-log(5791)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="i-gear">
        <vers num="3.5" />
        <vers num="3.5.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1008" published="2000-12-11" name="CVE-2000-1008" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">PalmOS 3.5.2 and earlier uses weak encryption to store the user password, which allows attackers with physical access to the Palm device to decrypt the password and gain access to the device.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1715" source="BID" patch="1" adv="1">1715</ref>
      <ref url="http://www.atstake.com/research/advisories/2000/a092600-1.txt" source="ATSTAKE" patch="1" adv="1">A092600-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="palm" name="palm_os">
        <vers prev="1" num="3.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1009" published="2000-12-11" name="CVE-2000-1009" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">dump in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which allows local users to obtain root privileges by modifying the RSH variable to point to a Trojan horse program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1871" source="BID" patch="1" adv="1">1871</ref>
      <ref url="http://xforce.iss.net/static/5437.php" source="XF" adv="1">linux-dump-execute-code</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0438.html" source="BUGTRAQ">20001030 Redhat 6.2 dump command executes external program with suid priviledge.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="6.2" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1010" published="2000-12-11" name="CVE-2000-1010" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in talkd in OpenBSD and possibly other BSD-based OSes allows remote attackers to execute arbitrary commands via a user name that contains format characters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5344.php" source="XF" patch="1" adv="1">linux-talkd-overwrite-root</ref>
      <ref url="http://www.securityfocus.com/bid/1764" source="BID" patch="1" adv="1">1764</ref>
      <ref url="http://www.securityfocus.com/archive/1/137890" source="BUGTRAQ" adv="1">20001006 talkd [WAS: Re: OpenBSD Security Advisory]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.6" />
        <vers num="2.7" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" edition="" />
        <vers num="5.2" edition=":sparc" />
        <vers num="5.2" edition=":i386" />
        <vers num="5.2" edition=":alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1011" published="2000-12-11" name="CVE-2000-1011" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in catopen() function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to gain root privileges via a long environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:53.catopen.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-00:53</ref>
      <ref url="http://xforce.iss.net/static/5638.php" source="XF">freebsd-catopen-bo</ref>
      <ref url="http://www.osvdb.org/6070" source="OSVDB">6070</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="3.5" />
        <vers num="3.5.1" />
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.2" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1012" published="2000-12-11" name="CVE-2000-1012" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The catopen function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to read arbitrary files via the LANG environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:53.catopen.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-00:53</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="3.5" />
        <vers num="3.5.1" />
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.2" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1013" published="2000-12-11" name="CVE-2000-1013" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The setlocale function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to read arbitrary files via the LANG environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:53.catopen.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-00:53</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="3.5" />
        <vers num="3.5.1" />
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.2" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1014" published="2000-12-11" name="CVE-2000-1014" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in the search97.cgi CGI script in SCO help http server for Unixware 7 allows remote attackers to execute arbitrary commands via format characters in the queryText parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5291.php" source="XF" patch="1" adv="1">unixware-scohelp-format</ref>
      <ref url="http://www.securityfocus.com/bid/1717" source="BID" patch="1" adv="1">1717</ref>
      <ref url="http://www.osvdb.org/3240" source="OSVDB">3240</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0325.html" source="BUGTRAQ">20000927 Unixware SCOhelp http server format string vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="unixware">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1015" published="2000-12-11" name="CVE-2000-1015" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The default configuration of Slashcode before version 2.0 Alpha has a default administrative password, which allows remote attackers to gain Slashcode priviliges and possibly execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5306.php" source="XF" patch="1" adv="1">slashcode-default-admin-passwords</ref>
      <ref url="http://www.securityfocus.com/bid/1731" source="BID" patch="1" adv="1">1731</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0366.html" source="BUGTRAQ" patch="1" adv="1">20000929 Default admin password with Slashcode.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="open_source_development_network" name="slashcode">
        <vers prev="1" num="1.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1016" published="2000-12-11" name="CVE-2000-1016" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The default configuration of Apache (httpd.conf) on SuSE 6.4 includes an alias for the /usr/doc directory, which allows remote attackers to read package documentation and obtain system configuration information via an HTTP request for the /doc/packages URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5276.php" source="XF" patch="1" adv="1">suse-installed-packages-exposed</ref>
      <ref url="http://www.securityfocus.com/bid/1707" source="BID" patch="1" adv="1">1707</ref>
      <ref url="http://www.securityfocus.com/archive/1/84360" source="BUGTRAQ">20000921 httpd.conf in Suse 6.4</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="suse_linux">
        <vers num="6.3" />
        <vers num="6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1017" published="2000-12-11" name="CVE-2000-1017" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Webteachers Webdata allows remote attackers with valid Webdata accounts to read arbitrary files by posting a request to import the file into the WebData database.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1732" source="BID" patch="1" adv="1">1732</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0032.html" source="BUGTRAQ" patch="1" adv="1">20001003 Update to DST2K0039: Webteachers Webdata: Importing files lower t han web root possible in to database</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0007.html" source="BUGTRAQ">20001002 DST2K0039: Webteachers Webdata: Importing files lower than web ro ot possible in to database</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webteacher" name="webdata">
        <vers prev="1" num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-1018" published="2000-12-11" name="CVE-2000-1018" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">shred 1.0 file wiping utility does not properly open a file for overwriting or flush its buffers, which prevents shred from properly replacing the file's data and allows local users to recover the file.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1788" source="BID" patch="1" adv="1">1788</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97131166004145&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20001011 Shred v1.0 Fix</ref>
      <ref url="http://xforce.iss.net/static/5722.php" source="XF">shred-recover-files</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97119799515246&amp;w=2" source="BUGTRAQ">20001010 Shred 1.0 Bug Report</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mendel_cooper" name="shred">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1019" published="2000-12-11" name="CVE-2000-1019" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Search engine in Ultraseek 3.1 and 3.1.10 (aka Inktomi Search) allows remote attackers to cause a denial of service via a malformed URL.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5439.php" source="XF" patch="1" adv="1">ultraseek-malformed-url-dos</ref>
      <ref url="http://www.securityfocus.com/bid/1866" source="BID" patch="1" adv="1">1866</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97301487015664&amp;w=2" source="BUGTRAQ">20001030 Ultraseek 3.1.x Remote DoS Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="inktomi" name="search_software">
        <vers num="3.0" />
        <vers num="3.1.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1020" published="2000-12-11" name="CVE-2000-1020" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap overflow in Worldclient in Mdaemon 3.1.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5250.php" source="XF" patch="1" adv="1">mdaemon-url-dos</ref>
      <ref url="http://www.securityfocus.com/bid/1689" source="BID" patch="1" adv="1">1689</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96925269716274&amp;w=2" source="BUGTRAQ">20000917 VIGILANTE-2000012: Mdaemon Web Services Heap Overflow DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alt-n" name="mdaemon">
        <vers num="3.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1021" published="2000-12-11" name="CVE-2000-1021" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap overflow in WebConfig in Mdaemon 3.1.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1689" source="BID" patch="1" adv="1">1689</ref>
      <ref url="http://xforce.iss.net/static/5250.php" source="XF">mdaemon-url-dos</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96925269716274&amp;w=2" source="BUGTRAQ">20000917 VIGILANTE-2000012: Mdaemon Web Services Heap Overflow DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alt-n" name="mdaemon">
        <vers num="3.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1022" published="2000-12-11" name="CVE-2000-1022" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The mailguard feature in Cisco Secure PIX Firewall 5.2(2) and earlier does not properly restrict access to SMTP commands, which allows remote attackers to execute restricted commands by sending a DATA command before sending the restricted commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5277.php" source="XF" patch="1" adv="1">cisco-pix-smtp-filtering</ref>
      <ref url="http://www.securityfocus.com/bid/1698" source="BID" patch="1" adv="1">1698</ref>
      <ref url="http://www.cisco.com/warp/public/707/PIXfirewallSMTPfilter-pub.shtml" source="CISCO">20001005 Cisco Secure PIX Firewall Mailguard Vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0241.html" source="BUGTRAQ">20000920 Re: Cisco PIX Firewall (smtp content filtering hack) - Version 4.2(1) not exploitable</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0222.html" source="BUGTRAQ">20000919 Cisco PIX Firewall (smtp content filtering hack)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="pix_firewall">
        <vers num="4.2(1)" />
        <vers num="4.2(2)" />
        <vers num="4.2(5)" />
        <vers num="4.3" />
        <vers num="4.4(4)" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1023" published="2000-12-11" name="CVE-2000-1023" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Alabanza Control Panel does not require passwords to access administrative commands, which allows remote attackers to modify domain name information via the nsManager.cgi CGI program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1710" source="BID" patch="1" adv="1">1710</ref>
      <ref url="http://xforce.iss.net/static/5284.php" source="XF">alabanza-unauthorized-access</ref>
      <ref url="http://www.securityfocus.com/archive/1/84766" source="BUGTRAQ">20000924 Major Vulnerability in Alabanza Control Panel</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alabanza" name="control_panel">
        <vers prev="1" num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1024" published="2000-12-11" name="CVE-2000-1024" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">eWave ServletExec 3.0C and earlier does not restrict access to the UploadServlet Java/JSP servlet, which allows remote attackers to upload files and execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1876" source="BID" patch="1" adv="1">1876</ref>
      <ref url="http://xforce.iss.net/static/5450.php" source="XF">ewave-servletexec-file-upload</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97306581513537&amp;w=2" source="BUGTRAQ">20001101 Unify eWave ServletExec upload</ref>
    </refs>
    <vuln_soft>
      <prod vendor="unify" name="ewave_servletexec">
        <vers num="3.0c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1025" published="2000-12-11" name="CVE-2000-1025" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">eWave ServletExec JSP/Java servlet engine, versions 3.0C and earlier, allows remote attackers to cause a denial of service via a URL that contains the "/servlet/" string, which invokes the ServletExec servlet and causes an exception if the servlet is already running.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1868" source="BID" patch="1" adv="1">1868</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97295224226042&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20001030 Unify eWave ServletExec DoS</ref>
      <ref url="http://xforce.iss.net/static/5435.php" source="XF">ewave-servletexec-dos</ref>
    </refs>
    <vuln_soft>
      <prod vendor="unify" name="ewave_servletexec">
        <vers num="3.0c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1026" published="2000-12-11" name="CVE-2000-1026" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in LBNL tcpdump allow remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1870" source="BID" patch="1" adv="1">1870</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5480" source="XF">tcpdump-afs-packet-overflow(5480)</ref>
      <ref url="http://archives.neohapsis.com/archives/linux/suse/2000-q4/0681.html" source="SUSE">SuSE-SA:2000:46</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:61.tcpdump.v1.1.asc" source="FREEBSD">FreeBSD-SA-00:61</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lbl" name="tcpdump">
        <vers num="3.4" />
        <vers num="3.4a6" />
        <vers num="3.5" />
        <vers num="3.5_alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1027" published="2000-12-11" name="CVE-2000-1027" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco Secure PIX Firewall 5.2(2) allows remote attackers to determine the real IP address of a target FTP server by flooding the server with PASV requests, which includes the real IP address in the response when passive mode is established.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1877" source="BID" adv="1">1877</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97059440000367&amp;w=2" source="BUGTRAQ" adv="1">20001003 Cisco PIX Firewall allow external users to discover internal IPs</ref>
      <ref url="http://xforce.iss.net/static/5646.php" source="XF">cisco-pix-reveal-address</ref>
      <ref url="http://www.osvdb.org/1623" source="OSVDB">1623</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="pix_firewall">
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1028" published="2000-12-11" name="CVE-2000-1028" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in cu program in HP-UX 11.0 may allow local users to gain privileges via a long -l command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1886" source="BID" patch="1" adv="1">1886</ref>
      <ref url="http://www.securityfocus.com/archive/1/142792" source="BUGTRAQ">20001102 HPUX cu -l option buffer overflow vulnerabilit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.20" />
        <vers num="11.00" />
        <vers num="9.00" />
        <vers num="9.01" />
        <vers num="9.04" />
        <vers num="9.05" />
        <vers num="9.06" />
        <vers num="9.07" />
        <vers num="9.08" />
        <vers num="9.09" />
        <vers num="9.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1029" published="2000-12-11" name="CVE-2000-1029" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in host command allows a remote attacker to execute arbitrary commands via a long response to an AXFR query.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1887" source="BID" patch="1" adv="1">1887</ref>
      <ref url="http://www.securityfocus.com/archive/1/141660" source="BUGTRAQ" adv="1">20001027 old version of host command vulnearbility</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="bind">
        <vers num="8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1030" published="2000-12-11" name="CVE-2000-1030" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CS&amp;T CorporateTime for the Web returns different error messages for invalid usernames and invalid passwords, which allows remote attackers to determine valid usernames on the server.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1888" source="BID" adv="1">1888</ref>
      <ref url="http://www.securityfocus.com/archive/1/142672" source="BUGTRAQ">20001031 Re: Samba 2.0.7 SWAT vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="csandt" name="corporatetime_for_the_web">
        <vers prev="1" num="2.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1031" published="2000-12-11" name="CVE-2000-1031" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in dtterm in HP-UX 11.0 and HP Tru64 UNIX 4.0f through 5.1a allows local users to execute arbitrary code via a long -tn option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/320067" source="CERT-VN">VU#320067</ref>
      <ref url="http://www.securityfocus.com/bid/1889" source="BID" patch="1" adv="1">1889</ref>
      <ref url="http://archives.neohapsis.com/archives/hp/2000-q4/0034.html" source="HP" patch="1" adv="1">HPSBUX0011-128</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5461" source="XF">hp-dtterm(5461)</ref>
      <ref url="http://www.securityfocus.com/archive/1/75188" source="BUGTRAQ">20000810 Re: Possible vulnerability in HPUX ( Add vulnerability List )</ref>
      <ref url="http://www.securityfocus.com/archive/1/290115" source="BUGTRAQ">20020902 Happy Labor Day from Snosoft</ref>
      <ref url="http://wwss1pro.compaq.com/support/reference_library/viewdocument.asp?source=SRB0039W.xml&amp;dt=11" source="HP">SSRT2275</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2002-q3/1203.html" source="FULLDISC">20020919 iDEFENSE OSF1/Tru64 3.x vuln clarification</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2002-q3/1203.html" source="FULLDISC">20020919 iDEFENSE OSF1/Tru64 3.x vuln clarification</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.10" />
        <vers num="10.20" />
        <vers num="10.24" />
        <vers num="11.00" />
        <vers num="11.4" />
      </prod>
      <prod vendor="hp" name="tru64">
        <vers num="4.0f" edition="pk8" />
        <vers num="4.0g" edition="pk4" />
        <vers num="5.0a" />
        <vers num="5.1" />
        <vers num="5.1a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1032" published="2000-12-11" name="CVE-2000-1032" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The client authentication interface for Check Point Firewall-1 4.0 and earlier generates different error messages for invalid usernames versus invalid passwords, which allows remote attackers to identify valid usernames on the firewall.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1890" source="BID" patch="1" adv="1">1890</ref>
      <ref url="http://www.securityfocus.com/archive/1/142808" source="BUGTRAQ" adv="1">20001101 Re: Samba 2.0.7 SWAT vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5816" source="XF">fw1-login-response(5816)</ref>
      <ref url="http://www.osvdb.org/1632" source="OSVDB">1632</ref>
    </refs>
    <vuln_soft>
      <prod vendor="checkpoint" name="firewall-1">
        <vers num="3.0" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1033" published="2000-12-11" name="CVE-2000-1033" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Serv-U FTP Server allows remote attackers to bypass its anti-hammering feature by first logging on as a valid user (possibly anonymous) and then attempting to guess the passwords of other users.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5436.php" source="XF" adv="1">ftp-servu-brute-force</ref>
      <ref url="http://www.securityfocus.com/bid/1860" source="BID" adv="1">1860</ref>
      <ref url="http://www.securityfocus.com/archive/1/141905" source="BUGTRAQ">20001029 Brute Forcing FTP Servers with enabled anti-hammering (anti brute-force) modus</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cat_soft" name="serv-u">
        <vers num="2.5x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1034" published="2000-12-11" name="CVE-2000-1034" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the System Monitor ActiveX control in Windows 2000 allows remote attackers to execute arbitrary commands via a long LogFileName parameter in HTML source code, aka the "ActiveX Parameter Validation" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1899" source="BID" patch="1" adv="1">1899</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS00-085.asp" source="MS" patch="1" adv="1">MS00-085</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5467" source="XF">system-monitor-activex-bo(5467)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97349782305448&amp;w=2" source="BUGTRAQ">20001106 System Monitor ActiveX Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1035" published="2000-12-11" name="CVE-2000-1035" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflows in TYPSoft FTP Server 0.78 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long USER, PASS, or CWD command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.synnergy.net/Archives/Advisories/dethy/typsoft-ftpd.txt" source="MISC">http://www.synnergy.net/Archives/Advisories/dethy/typsoft-ftpd.txt</ref>
      <ref url="http://www.securityfocus.com/bid/1690" source="BID" adv="1">1690</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96879389027478&amp;w=2" source="BUGTRAQ">20000912 TYPSoft FTP Server remote DoS Problem</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typsoft" name="typsoft">
        <vers num="0.7x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1036" published="2000-12-11" name="CVE-2000-1036" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Extent RBS ISP web server allows remote attackers to read sensitive information via a .. (dot dot) attack on the Image parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5275.php" source="XF" patch="1" adv="1">rbs-isp-directory-traversal</ref>
      <ref url="http://www.securityfocus.com/bid/1704" source="BID" patch="1" adv="1">1704</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0252.html" source="BUGTRAQ" patch="1" adv="1">20000920 Extent RBS directory Transversal.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="extent_technologies" name="rbs_isp">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1037" published="2000-12-11" name="CVE-2000-1037" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Check Point Firewall-1 session agent 3.0 through 4.1 generates different error messages for invalid user names versus invalid passwords, which allows remote attackers to determine valid usernames and guess a password via a brute force attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1662" source="BID" adv="1">1662</ref>
      <ref url="http://www.securityfocus.com/archive/1/76389" source="BUGTRAQ" adv="1">20000815 Firewall-1 session agent 3.0 -> 4.1, dictionnary and brute force attack</ref>
    </refs>
    <vuln_soft>
      <prod vendor="checkpoint" name="firewall-1">
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1038" published="2000-12-11" name="CVE-2000-1038" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The web administration interface for IBM AS/400 Firewall allows remote attackers to cause a denial of service via an empty GET request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://as400service.rochester.ibm.com/n_dir/nas4apar.NSF/5ec6cdc6ab42894a862568f90073c74a/9ce636030a58807186256955003d128d?OpenDocument" source="CONFIRM" patch="1" adv="1">http://as400service.rochester.ibm.com/n_dir/nas4apar.NSF/5ec6cdc6ab42894a862568f90073c74a/9ce636030a58807186256955003d128d?OpenDocument</ref>
      <ref url="http://xforce.iss.net/static/5266.php" source="XF" adv="1">as400-firewall-dos</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=SA90544&amp;apar=only" source="AIXAPAR">SA90544</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="as400_firewall">
        <vers num="r440" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1039" published="2001-01-09" name="CVE-2000-1039" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Various TCP/IP stacks and network applications allow remote attackers to cause a denial of service by flooding a target host with TCP connection attempts and completing the TCP/IP handshake without maintaining the connection state on the attacker host, aka the "NAPTHA" class of vulnerabilities.  NOTE: this candidate may change significantly as the security community discusses the technical nature of NAPTHA and learns more about the affected applications. This candidate is at a higher level of abstraction than is typical for CVE.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2000-21.html" source="CERT" patch="1" adv="1">CA-2000-21</ref>
      <ref url="http://www.securityfocus.com/bid/2022" source="BID" patch="1" adv="1">2022</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS00-091.asp" source="MS" patch="1" adv="1">MS00-091</ref>
      <ref url="http://razor.bindview.com/publish/advisories/adv_NAPTHA.html" source="BINDVIEW">20001130 The NAPTHA DoS vulnerabilities</ref>
      <ref url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q4/0105.html" source="WIN2KSEC">20001204 NAPTHA Advisory Updated - BindView RAZOR</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_95">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1040" published="2000-12-11" name="CVE-2000-1040" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in logging function of ypbind 3.3, while running in debug mode, leaks file descriptors and allows an attacker to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1820" source="BID" patch="1" adv="1">1820</ref>
      <ref url="http://xforce.iss.net/static/5394.php" source="XF">ypbind-printf-format-string</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-086.html" source="REDHAT">RHSA-2000:086</ref>
      <ref url="http://www.linux-mandrake.com/en/security/MDKSA-2000-064.php3?dis=7.1" source="MANDRAKE">MDKSA-2000:064</ref>
      <ref url="http://www.debian.org/security/2000/20001014" source="DEBIAN">20001014 nis: local exploit</ref>
      <ref url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-039.0.txt" source="CALDERA">CSSA-2000-039.0</ref>
      <ref url="http://archives.neohapsis.com/archives/linux/suse/2000-q4/0262.html" source="SUSE">SuSE-SA:2000:042</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0429.html" source="BUGTRAQ">20001030 Trustix Security Advisory - ping gnupg ypbind</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0356.html" source="BUGTRAQ">20001025 Immunix OS Security Update for ypbind package</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="suse_linux">
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1041" published="2000-12-11" name="CVE-2000-1041" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in ypbind 3.3 possibly allows an attacker to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.linux-mandrake.com/en/security/MDKSA-2000-064.php3?dis=7.1" source="MANDRAKE" patch="1" adv="1">MDKSA-2000:064</ref>
      <ref url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-039.0.txt" source="CALDERA" patch="1" adv="1">CSSA-2000-039.0</ref>
      <ref url="http://archives.neohapsis.com/archives/linux/suse/2000-q4/0262.html" source="SUSE" patch="1" adv="1">SuSE-SA:2000:042</ref>
      <ref url="http://xforce.iss.net/static/5759.php" source="XF">ypbind-remote-bo</ref>
    </refs>
    <vuln_soft>
      <prod vendor="swen_thuemmler" name="ypbind">
        <vers num="3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1042" published="2000-12-11" name="CVE-2000-1042" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in ypserv in Mandrake Linux 7.1 and earlier, and possibly other Linux operating systems, allows an attacker to gain root privileges when ypserv is built without a vsyslog() function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.linux-mandrake.com/en/security/MDKSA-2000-064.php3?dis=7.1" source="MANDRAKE" patch="1" adv="1">MDKSA-2000:064</ref>
      <ref url="http://xforce.iss.net/static/5730.php" source="XF">linux-ypserv-bo</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="6.1" />
        <vers num="7.0" />
        <vers num="7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1043" published="2000-12-11" name="CVE-2000-1043" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in ypserv in Mandrake Linux 7.1 and earlier, and possibly other Linux operating systems, allows an attacker to gain root privileges when ypserv is built without a vsyslog() function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.linux-mandrake.com/en/security/MDKSA-2000-064.php3?dis=7.1" source="MANDRAKE" patch="1" adv="1">MDKSA-2000:064</ref>
      <ref url="http://xforce.iss.net/static/5731.php" source="XF">linux-ypserv-format-string</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="6.1" />
        <vers num="7.0" />
        <vers num="7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1044" published="2000-12-11" name="CVE-2000-1044" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in ypbind-mt in SuSE SuSE-6.2, and possibly other Linux operating systems, allows an attacker to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1820" source="BID" patch="1" adv="1">1820</ref>
      <ref url="http://archives.neohapsis.com/archives/linux/suse/2000-q4/0262.html" source="SUSE" patch="1" adv="1">SuSE-SA:2000:042</ref>
      <ref url="http://xforce.iss.net/static/5394.php" source="XF">ypbind-printf-format-string</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="suse_linux">
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-1045" published="2000-12-11" name="CVE-2000-1045" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">nss_ldap earlier than 121, when run with nscd (name service caching daemon), allows remote attackers to cause a denial of service via a flood of LDAP requests.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1863" source="BID" patch="1" adv="1">1863</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-024.html" source="REDHAT" patch="1" adv="1">RHSA-2000:024</ref>
      <ref url="http://www.linux-mandrake.com/en/security/MDKSA-2000-066-1.php3" source="MANDRAKE" patch="1" adv="1">MDKSA-2000-066</ref>
      <ref url="http://xforce.iss.net/static/5449.php" source="XF">nssldap-nscd-dos</ref>
    </refs>
    <vuln_soft>
      <prod vendor="padl_software" name="nss_ldap">
        <vers num="build_105" />
        <vers num="build_113" />
        <vers num="build_85" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1046" published="2000-12-11" name="CVE-2000-1046" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in the ESMTP service of Lotus Domino 5.0.2c and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via long (1) "RCPT TO," (2) "SAML FROM," or (3) "SOML FROM" commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0093.html" source="BUGTRAQ" patch="1" adv="1">20000911 Advisory Code: VIGILANTE-2000011 Lotus Domino ESMTP Service Buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lotus" name="domino">
        <vers num="5.0.2a" />
        <vers num="5.0.2c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1047" published="2000-12-11" name="CVE-2000-1047" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in SMTP service of Lotus Domino 5.0.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long ENVID keyword in the "MAIL FROM" command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1905" source="BID" patch="1" adv="1">1905</ref>
      <ref url="http://www.securityfocus.com/archive/1/143071" source="BUGTRAQ" patch="1" adv="1">20001103 [SAFER] Buffer overflow in Lotus Domino SMTP Server</ref>
      <ref url="http://xforce.iss.net/static/5488.php" source="XF">lotus-domino-smtp-envid(5488)</ref>
      <ref url="http://www.osvdb.org/442" source="OSVDB">442</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lotus" name="domino_enterprise_server">
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.2b" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
      </prod>
      <prod vendor="lotus" name="domino_mail_server">
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.2b" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1048" published="2000-12-11" name="CVE-2000-1048" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the logfile service of Wingate 4.1 Beta A and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack via an HTTP GET request that uses encoded characters in the URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5373.php" source="XF" patch="1" adv="1">wingate-view-files</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0245.html" source="BUGTRAQ" adv="1">20001016 Wingate 4.1 Beta A vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qbik" name="wingate">
        <vers num="2.1" />
        <vers num="3.0" />
        <vers num="4.0.1" />
        <vers num="4.1_beta_a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1049" published="2000-12-11" name="CVE-2000-1049" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Allaire JRun 3.0 http servlet server allows remote attackers to cause a denial of service via a URL that contains a long string of "." characters.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5452.php" source="XF" patch="1" adv="1">allaire-jrun-servlet-dos</ref>
      <ref url="http://www.allaire.com/handlers/index.cfm?ID=18085&amp;Method=Full" source="ALLAIRE" patch="1" adv="1">ASB00-030</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97310314724964&amp;w=2" source="BUGTRAQ">20001101 Allaire's JRUN DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macromedia" name="jrun">
        <vers num="3.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1050" published="2000-12-11" name="CVE-2000-1050" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Allaire JRun 3.0 http servlet server allows remote attackers to directly access the WEB-INF directory via a URL request that contains an extra "/" in the beginning of the request (aka the "extra leading slash").</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5407.php" source="XF" patch="1" adv="1">allaire-jrun-webinf-access</ref>
      <ref url="http://www.allaire.com/handlers/index.cfm?ID=17966&amp;Method=Full" source="ALLAIRE" patch="1" adv="1">ASB00-027</ref>
      <ref url="http://www.osvdb.org/500" source="OSVDB">500</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97236316510117&amp;w=2" source="BUGTRAQ">20001023 Allaire's JRUN Unauthenticated Access to WEB-INF directory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macromedia" name="jrun">
        <vers num="3.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1051" published="2000-12-11" name="CVE-2000-1051" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Allaire JRun 2.3 server allows remote attackers to read arbitrary files via the SSIFilter servlet.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5405.php" source="XF" patch="1" adv="1">allaire-jrun-ssifilter-url</ref>
      <ref url="http://www.allaire.com/handlers/index.cfm?ID=17968&amp;Method=Full" source="ALLAIRE" patch="1" adv="1">ASB00-028</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97236692714978&amp;w=2" source="BUGTRAQ">20001023 Allaire JRUN 2.3 Arbitrary File Retrieval</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macromedia" name="jrun">
        <vers num="2.3.x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1052" published="2000-12-11" name="CVE-2000-1052" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Allaire JRun 2.3 server allows remote attackers to obtain source code for executable content by directly calling the SSIFilter servlet.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97236692714978&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20001023 Allaire JRUN 2.3 Arbitrary File Retrieval</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macromedia" name="jrun">
        <vers num="2.3.x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1053" published="2000-12-11" name="CVE-2000-1053" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Allaire JRun 2.3.3 server allows remote attackers to compile and execute JSP code by inserting it via a cross-site scripting (CSS) attack and directly calling the com.livesoftware.jrun.plugins.JSP JSP servlet.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5406.php" source="XF" patch="1" adv="1">allaire-jrun-jsp-execute</ref>
      <ref url="http://www.allaire.com/handlers/index.cfm?ID=17969&amp;Method=Full" source="ALLAIRE" patch="1" adv="1">ASB00-029</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97236125107957&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20001023 Allaire JRUN 2.3 Remote command execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macromedia" name="jrun">
        <vers num="2.3.x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1054" published="2000-12-11" name="CVE-2000-1054" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in CSAdmin module in CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a large packet.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5272.php" source="XF" patch="1" adv="1">ciscosecure-csadmin-bo</ref>
      <ref url="http://www.securityfocus.com/bid/1705" source="BID" patch="1" adv="1">1705</ref>
      <ref url="http://www.cisco.com/warp/public/707/csecureacsnt-pub.shtml" source="CISCO" patch="1" adv="1">20000921 Multiple Vulnerabilities in CiscoSecure ACS for Windows NT Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="secure_access_control_server">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":windows_nt" />
        <vers num="2.3(3)" edition="" />
        <vers num="2.3(3)" edition=":windows_nt" />
        <vers num="2.4(2)" edition="" />
        <vers num="2.4(2)" edition=":windows_nt" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1055" published="2000-12-11" name="CVE-2000-1055" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a large TACACS+ packet.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5273.php" source="XF" patch="1" adv="1">ciscosecure-tacacs-dos</ref>
      <ref url="http://www.securityfocus.com/bid/1706" source="BID" patch="1" adv="1">1706</ref>
      <ref url="http://www.cisco.com/warp/public/707/csecureacsnt-pub.shtml" source="CISCO" patch="1" adv="1">20000921 Multiple Vulnerabilities in CiscoSecure ACS for Windows NT Server</ref>
      <ref url="http://www.osvdb.org/1569" source="OSVDB">1569</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="secure_access_control_server">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":windows_nt" />
        <vers num="2.3(3)" edition="" />
        <vers num="2.3(3)" edition=":windows_nt" />
        <vers num="2.4(2)" edition="" />
        <vers num="2.4(2)" edition=":windows_nt" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1056" published="2000-12-11" name="CVE-2000-1056" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to bypass LDAP authentication on the server if the LDAP server allows null passwords.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5274.php" source="XF" patch="1" adv="1">ciscosecure-ldap-bypass-authentication</ref>
      <ref url="http://www.securityfocus.com/bid/1708" source="BID" patch="1" adv="1">1708</ref>
      <ref url="http://www.cisco.com/warp/public/707/csecureacsnt-pub.shtml" source="CISCO" patch="1" adv="1">20000921 Multiple Vulnerabilities in CiscoSecure ACS for Windows NT Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="secure_access_control_server">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":windows_nt" />
        <vers num="2.3(3)" edition="" />
        <vers num="2.3(3)" edition=":windows_nt" />
        <vers num="2.4(2)" edition="" />
        <vers num="2.4(2)" edition=":windows_nt" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1057" published="2000-12-11" name="CVE-2000-1057" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Vulnerabilities in database configuration scripts in HP OpenView Network Node Manager (NNM) 6.1 and earlier allows local users to gain privileges, possibly via insecure permissions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5229.php" source="XF" patch="1" adv="1">hp-openview-nnm-scripts</ref>
      <ref url="http://www.securityfocus.com/bid/1682" source="BID" patch="1" adv="1">1682</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0140.html" source="HP" patch="1" adv="1">HPSBUX0009-120</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="4.11" edition="" />
        <vers num="4.11" edition=":solaris" />
        <vers num="4.11" edition=":hp_ux" />
        <vers num="5.01" edition="" />
        <vers num="5.01" edition=":solaris" />
        <vers num="5.01" edition=":hp_ux" />
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":solaris" />
        <vers num="6.1" edition=":hp_ux_11.x" />
        <vers num="6.1" edition=":hp_ux_10.x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1058" published="2000-12-11" name="CVE-2000-1058" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in OverView5 CGI program in HP OpenView Network Node Manager (NNM) 6.1 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, in the SNMP service (snmp.exe), aka the "Java SNMP MIB Browser Object ID parsing problem."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5282.php" source="XF" patch="1" adv="1">openview-nmm-snmp-bo</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97004856403173&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20000926 DST2K0014: BufferOverrun in HP Openview Network Node Manager v6.1 (Round2)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0274.html" source="HP" patch="1" adv="1">HPSBUX0009-121</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="4.11" />
        <vers num="5.01" />
        <vers num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1059" published="2000-12-11" name="CVE-2000-1059" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The default configuration of the Xsession file in Mandrake Linux 7.1 and 7.0 bypasses the Xauthority access control mechanism with an "xhost + localhost" command, which allows local users to sniff X Windows events and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5305.php" source="XF" patch="1" adv="1">xinitrc-bypass-xauthority</ref>
      <ref url="http://www.securityfocus.com/bid/1735" source="BID" patch="1" adv="1">1735</ref>
      <ref url="http://www.securityfocus.com/archive/1/136495" source="BUGTRAQ">20000929 Mandrake 7.1 bypasses Xauthority X session security.</ref>
      <ref url="http://www.linux-mandrake.com/en/security/MDKSA-2000-052.php3" source="MANDRAKE">MDKSA-2000:052</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="7.0" />
        <vers num="7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1060" published="2000-12-11" name="CVE-2000-1060" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The default configuration of XFCE 3.5.1 bypasses the Xauthority access control mechanism with an "xhost + localhost" command in the xinitrc program, which allows local users to sniff X Windows traffic and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5305.php" source="XF" patch="1" adv="1">xinitrc-bypass-xauthority</ref>
      <ref url="http://www.securityfocus.com/bid/1736" source="BID" patch="1" adv="1">1736</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0022.html" source="BUGTRAQ">20001002 Local vulnerability in XFCE 3.5.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xfree86_project" name="xfce">
        <vers num="3.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1061" published="2000-12-11" name="CVE-2000-1061" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Microsoft Virtual Machine (VM) in Internet Explorer 4.x and 5.x allows an unsigned applet to create and use ActiveX controls, which allows a remote attacker to bypass Internet Explorer's security settings and execute arbitrary commands via a malicious web page or email, aka the "Microsoft VM ActiveX Component" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS00-075.asp" source="MS" patch="1" adv="1">MS00-075</ref>
      <ref url="http://xforce.iss.net/static/5127.php" source="XF">java-vm-applet</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.x" />
        <vers num="5.x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1062" published="2000-12-11" name="CVE-2000-1062" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in the FTP service in HP JetDirect printer card Firmware x.08.20 and earlier allows remote attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5353.php" source="XF" patch="1" adv="1">hp-jetdirect-firmware-dos</ref>
      <ref url="http://www.securityfocus.com/bid/1775" source="BID" patch="1" adv="1">1775</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97119729613778&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20001010 VIGILANTE-2000014: HP Jetdirect multiple DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="jetdirect">
        <vers num="x.08.04" />
        <vers num="x.08.05" />
        <vers num="x.08.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1063" published="2000-12-11" name="CVE-2000-1063" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in the Telnet service in HP JetDirect printer card Firmware x.08.20 and earlier allows remote attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5353.php" source="XF" patch="1" adv="1">hp-jetdirect-firmware-dos</ref>
      <ref url="http://www.securityfocus.com/bid/1775" source="BID" patch="1" adv="1">1775</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97119729613778&amp;w=2" source="BUGTRAQ">20001010 VIGILANTE-2000014: HP Jetdirect multiple DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="jetdirect">
        <vers num="x.08.04" />
        <vers num="x.08.05" />
        <vers num="x.08.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1064" published="2000-12-11" name="CVE-2000-1064" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in the LPD service in HP JetDirect printer card Firmware x.08.20 and earlier allows remote attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5353.php" source="XF" patch="1" adv="1">hp-jetdirect-firmware-dos</ref>
      <ref url="http://www.securityfocus.com/bid/1775" source="BID" patch="1" adv="1">1775</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97119729613778&amp;w=2" source="BUGTRAQ">20001010 VIGILANTE-2000014: HP Jetdirect multiple DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="jetdirect">
        <vers num="x.08.04" />
        <vers num="x.08.05" />
        <vers num="x.08.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1065" published="2000-12-11" name="CVE-2000-1065" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Vulnerability in IP implementation of HP JetDirect printer card Firmware x.08.20 and earlier allows remote attackers to cause a denial of service (printer crash) via a malformed packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5354.php" source="XF" patch="1" adv="1">hp-jetdirect-ip-implementation</ref>
      <ref url="http://www.securityfocus.com/bid/1775" source="BID" patch="1" adv="1">1775</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97119729613778&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20001010 VIGILANTE-2000014: HP Jetdirect multiple DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="jetdirect">
        <vers num="x.08.04" />
        <vers num="x.08.05" />
        <vers num="x.08.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1066" published="2000-12-11" name="CVE-2000-1066" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The getnameinfo function in FreeBSD 4.1.1 and earlier, and possibly other operating systems, allows a remote attacker to cause a denial of service via a long DNS hostname.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1894" source="BID" patch="1" adv="1">1894</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:63.getnameinfo.asc" source="FREEBSD">FreeBSD-SA-00:63</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.0" edition="alpha" />
        <vers num="4.1" />
        <vers num="4.1.1" edition="release" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1068" published="2000-12-11" name="CVE-2000-1068" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">pollit.cgi in Poll It 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the poll_options parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97236719315352&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20001023 Re: Poll It v2.0 cgi (again)</ref>
      <ref url="http://www.cgi-world.com/pollit.html" source="CONFIRM">http://www.cgi-world.com/pollit.html</ref>
      <ref url="http://xforce.iss.net/static/5792.php" source="XF">pollit-polloptions-execute-commands</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cgi-world" name="poll_it">
        <vers num="2.0" />
      </prod>
      <prod vendor="cgi-world" name="poll_it_pro">
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1069" published="2000-12-11" name="CVE-2000-1069" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">pollit.cgi in Poll It 2.01 and earlier allows remote attackers to access administrative functions without knowing the real password by specifying the same value to the entered_password and admin_password parameters.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5419.php" source="XF" patch="1" adv="1">pollit-admin-password-var</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97236719315352&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20001023 Re: Poll It v2.0 cgi (again)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cgi-world" name="poll_it">
        <vers num="2.0" />
        <vers num="2.01" />
      </prod>
      <prod vendor="cgi-world" name="poll_it_pro">
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1070" published="2000-12-11" name="CVE-2000-1070" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">pollit.cgi in Poll It 2.01 and earlier uses data files that are located under the web document root, which allows remote attackers to access sensitive or private information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97236719315352&amp;w=2" source="BUGTRAQ" adv="1">20001023 Re: Poll It v2.0 cgi (again)</ref>
      <ref url="http://xforce.iss.net/static/5794.php" source="XF">pollit-webroot-gain-access</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cgi-world" name="poll_it">
        <vers num="2.0" />
        <vers num="2.01" />
      </prod>
      <prod vendor="cgi-world" name="poll_it_pro">
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1071" published="2000-12-11" name="CVE-2000-1071" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The GUI installation for iCal 2.1 Patch 2 disables access control for the X server using an "xhost +" command, which allows remote attackers to monitor X Windows events and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.atstake.com/research/advisories/2000/a100900-1.txt" source="ATSTAKE" patch="1" adv="1">A100900-1</ref>
      <ref url="http://www.securityfocus.com/bid/1767" source="BID">1767</ref>
      <ref url="http://xforce.iss.net/static/5752.php" source="XF">ical-xhost-gain-privileges</ref>
      <ref url="http://www.osvdb.org/7213" source="OSVDB">7213</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="iplanet_ical">
        <vers num="2.1" edition="patch2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1072" published="2000-12-11" name="CVE-2000-1072" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">iCal 2.1 Patch 2 installs many files with world-writeable permissions, which allows local users to modify the iCal configuration and execute arbitrary commands by replacing the iplncal.sh program with a Trojan horse.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1768" source="BID" patch="1" adv="1">1768</ref>
      <ref url="http://www.atstake.com/research/advisories/2000/a100900-1.txt" source="ATSTAKE" patch="1" adv="1">A100900-1</ref>
      <ref url="http://xforce.iss.net/static/5756.php" source="XF">ical-iplncal-gain-access</ref>
      <ref url="http://www.osvdb.org/7212" source="OSVDB">7212</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="iplanet_ical">
        <vers num="2.1" edition="patch2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1073" published="2000-12-11" name="CVE-2000-1073" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">csstart program in iCal 2.1 Patch 2 searches for the cshttpd program in the current working directory, which allows local users to gain root privileges by creating a Trojan Horse cshttpd program in a directory and calling csstart from that directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1769" source="BID" patch="1" adv="1">1769</ref>
      <ref url="http://www.atstake.com/research/advisories/2000/a100900-1.txt" source="ATSTAKE" patch="1" adv="1">A100900-1</ref>
      <ref url="http://xforce.iss.net/static/5757.php" source="XF">ical-csstart-gain-access</ref>
      <ref url="http://www.osvdb.org/7210" source="OSVDB">7210</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="iplanet_ical">
        <vers num="2.1" edition="patch2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1074" published="2000-12-11" name="CVE-2000-1074" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">csstart program in iCal 2.1 Patch 2 uses relative pathnames to install the libsocket and libnsl libraries, which could allow the icsuser account to gain root privileges by creating a Trojan Horse library in the current or parent directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1769" source="BID" patch="1" adv="1">1769</ref>
      <ref url="http://www.atstake.com/research/advisories/2000/a100900-1.txt" source="ATSTAKE" patch="1" adv="1">A100900-1</ref>
      <ref url="http://xforce.iss.net/static/5757.php" source="XF">ical-csstart-gain-access</ref>
      <ref url="http://www.osvdb.org/7209" source="OSVDB">7209</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="iplanet_ical">
        <vers num="2.1" edition="patch2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1075" published="2000-12-11" name="CVE-2000-1075" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in iPlanet Certificate Management System 4.2 and Directory Server 4.12 allows remote attackers to read arbitrary files via a .. (dot dot) attack in the Agent, End Entity, or Administrator services.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1839" source="BID" patch="1" adv="1">1839</ref>
      <ref url="http://xforce.iss.net/static/5421.php" source="XF" adv="1">iplanet-netscape-directory-traversal</ref>
      <ref url="http://www.iplanet.com/downloads/patches/0122.html" source="CONFIRM">http://www.iplanet.com/downloads/patches/0122.html</ref>
      <ref url="http://www.osvdb.org/486" source="OSVDB">486</ref>
      <ref url="http://www.osvdb.org/4086" source="OSVDB">4086</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0383.html" source="BUGTRAQ">20001026 [CORE SDI ADVISORY] iPlanet Certificate Management System 4.2 path traversal bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="directory_server">
        <vers num="4.12" />
      </prod>
      <prod vendor="sun" name="iplanet_certificate_management_system">
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1076" published="2000-12-11" name="CVE-2000-1076" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Netscape (iPlanet) Certificate Management System 4.2 and Directory Server 4.12 stores the administrative password in plaintext, which could allow local and possibly remote attackers to gain administrative privileges on the server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5422.php" source="XF" adv="1">iplanet-netscape-plaintext-password</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0383.html" source="BUGTRAQ">20001026 [CORE SDI ADVISORY] iPlanet Certificate Management System 4.2 path traversal bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="directory_server">
        <vers num="4.12" />
      </prod>
      <prod vendor="sun" name="iplanet_certificate_management_system">
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1077" published="2000-12-11" name="CVE-2000-1077" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the SHTML logging functionality of iPlanet Web Server 4.x allows remote attackers to execute arbitrary commands via a long filename with a .shtml extension.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/141435" source="BUGTRAQ" patch="1" adv="1">20001026 Buffer overflow in iPlanet Web Server 4 server side SHTML parsing module</ref>
      <ref url="http://xforce.iss.net/static/5446.php" source="XF" adv="1">iplanet-web-server-shtml-bo</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iplanet" name="iplanet_web_server">
        <vers num="4.x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1078" published="2000-12-11" name="CVE-2000-1078" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ICQ Web Front HTTPd allows remote attackers to cause a denial of service by requesting a URL that contains a "?" character.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5332.php" source="XF" adv="1">icq-webfront-url-dos</ref>
      <ref url="http://www.securityfocus.com/archive/1/138332" source="BUGTRAQ" adv="1">20001007 ICQ WebFront HTTPd DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mirabilis" name="icq_web_front">
        <vers num="windows_9x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1079" published="2000-08-29" name="CVE-2000-1079" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Interactions between the CIFS Browser Protocol and NetBIOS as implemented in Microsoft Windows 95, 98, NT, and 2000 allow remote attackers to modify dynamic NetBIOS name cache entries via a spoofed Browse Frame Request in a unicast or UDP broadcast datagram.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5168.php" source="XF" patch="1" adv="1">win-netbios-corrupt-cache</ref>
      <ref url="http://www.securityfocus.com/bid/1620" source="BID" patch="1" adv="1">1620</ref>
      <ref url="http://www.nai.com/research/covert/advisories/045.asp" source="NAI">20000829 Windows NetBIOS Unsolicited Cache Corruption</ref>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0116.html" source="NTBUGTRAQ">20000829 Re: [COVERT-2000-10] Windows NetBIOS Unsolicited Cache Corruption</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1079" source="OVAL" sig="1">oval:org.mitre.oval:def:1079</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_95">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1080" published="2000-11-01" name="CVE-2000-1080" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Quake 1 (quake1) and ProQuake 1.01 and earlier allow remote attackers to cause a denial of service via a malformed (empty) UDP packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1900" source="BID" patch="1" adv="1">1900</ref>
      <ref url="http://proquake.ai.mit.edu/" source="CONFIRM">http://proquake.ai.mit.edu/</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97318797630246&amp;w=2" source="BUGTRAQ" adv="1">20001102 dos on quake1 servers</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5527" source="XF">quake-empty-udp-dos(5527)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="id_software" name="quake">
        <vers num="1.9" />
      </prod>
      <prod vendor="j._p._grossman" name="proquake">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1081" published="2001-01-09" name="CVE-2000-1081" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2030" source="BID" patch="1" adv="1">2030</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-092.asp" source="MS" patch="1" adv="1">MS00-092</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97570878710037&amp;w=2" source="ATSTAKE">20001201 Microsoft SQL Server extended stored procedure vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:231" source="OVAL" sig="1">oval:org.mitre.oval:def:231</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="data_engine">
        <vers num="1.0" />
        <vers num="2000" />
      </prod>
      <prod vendor="microsoft" name="sql_server">
        <vers num="2000" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1082" published="2001-01-09" name="CVE-2000-1082" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The xp_enumresultset function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2031" source="BID" patch="1" adv="1">2031</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-092.asp" source="MS" patch="1" adv="1">MS00-092</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97570878710037&amp;w=2" source="ATSTAKE">20001201 Microsoft SQL Server extended stored procedure vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="data_engine">
        <vers num="1.0" />
        <vers num="2000" />
      </prod>
      <prod vendor="microsoft" name="sql_server">
        <vers num="2000" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-1083" published="2001-01-09" name="CVE-2000-1083" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The xp_showcolv function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2038" source="BID" patch="1" adv="1">2038</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-092.asp" source="MS" patch="1" adv="1">MS00-092</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97570878710037&amp;w=2" source="ATSTAKE">20001201 Microsoft SQL Server extended stored procedure vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="data_engine">
        <vers num="1.0" />
        <vers num="2000" />
      </prod>
      <prod vendor="microsoft" name="sql_server">
        <vers num="2000" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1084" published="2001-01-09" name="CVE-2000-1084" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The xp_updatecolvbm function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2039" source="BID" patch="1" adv="1">2039</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-092.asp" source="MS" patch="1" adv="1">MS00-092</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97570878710037&amp;w=2" source="ATSTAKE">20001201 Microsoft SQL Server extended stored procedure vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="data_engine">
        <vers num="1.0" />
        <vers num="2000" />
      </prod>
      <prod vendor="microsoft" name="sql_server">
        <vers num="2000" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1085" published="2001-01-09" name="CVE-2000-1085" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The xp_peekqueue function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2040" source="BID" patch="1" adv="1">2040</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-092.asp" source="MS" patch="1" adv="1">MS00-092</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97570884410184&amp;w=2" source="ATSTAKE">20001201 SQL Server 2000 Extended Stored Procedure Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="data_engine">
        <vers num="1.0" />
        <vers num="2000" />
      </prod>
      <prod vendor="microsoft" name="sql_server">
        <vers num="2000" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1086" published="2001-01-09" name="CVE-2000-1086" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The xp_printstatements function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2041" source="BID" patch="1" adv="1">2041</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-092.asp" source="MS" patch="1" adv="1">MS00-092</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97570884410184&amp;w=2" source="ATSTAKE">20001201 SQL Server 2000 Extended Stored Procedure Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="data_engine">
        <vers num="1.0" />
        <vers num="2000" />
      </prod>
      <prod vendor="microsoft" name="sql_server">
        <vers num="2000" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1087" published="2001-01-09" name="CVE-2000-1087" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The xp_proxiedmetadata function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2042" source="BID" patch="1" adv="1">2042</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-092.asp" source="MS" patch="1" adv="1">MS00-092</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97570884410184&amp;w=2" source="ATSTAKE">20001201 SQL Server 2000 Extended Stored Procedure Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="data_engine">
        <vers num="1.0" />
        <vers num="2000" />
      </prod>
      <prod vendor="microsoft" name="sql_server">
        <vers num="2000" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1088" published="2001-01-09" name="CVE-2000-1088" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2043" source="BID" patch="1" adv="1">2043</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-092.asp" source="MS" patch="1" adv="1">MS00-092</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97570884410184&amp;w=2" source="ATSTAKE">20001201 SQL Server 2000 Extended Stored Procedure Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="data_engine">
        <vers num="1.0" />
        <vers num="2000" />
      </prod>
      <prod vendor="microsoft" name="sql_server">
        <vers num="2000" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1089" published="2001-01-09" name="CVE-2000-1089" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Phone Book Service allows local users to execute arbitrary commands, aka the "Phone Book Service Buffer Overflow" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.stake.com/research/advisories/2000/a120400-1.txt" source="ATSTAKE" patch="1" adv="1">A120400-1</ref>
      <ref url="http://www.securityfocus.com/bid/2048" source="BID" patch="1" adv="1">2048</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS00-094.asp" source="MS" patch="1" adv="1">MS00-094</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5623" source="XF">phone-book-service-bo(5623)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1090" published="2001-02-12" name="CVE-2000-1090" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft IIS for Far East editions 4.0 and 5.0 allows remote attackers to read source code for parsed pages via a malformed URL that uses the lead-byte of a double-byte character.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2100" source="BID" patch="1" adv="1">2100</ref>
      <ref url="http://xforce.iss.net/static/5729.php" source="XF" adv="1">microsoft-iis-file-disclosure</ref>
      <ref url="http://www.nsfocus.com/english/homepage/sa_08.htm" source="MISC" adv="1">http://www.nsfocus.com/english/homepage/sa_08.htm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":" />
        <vers num="4.0" edition="::far_east" />
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":" />
        <vers num="5.0" edition="::far_east" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1092" published="2001-01-09" name="CVE-2000-1092" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">loadpage.cgi CGI program in EZshopper 3.0 and 2.0 allows remote attackers to list and read files in the EZshopper data directory by inserting a "/" in front of the target filename in the "file" parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5740.php" source="XF">ezshopper-cgi-file-disclosure(5740)</ref>
      <ref url="http://www.securityfocus.com/bid/2109" source="BID" adv="1">2109</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97676270729984&amp;w=2" source="BUGTRAQ">20001213 NSFOCUS SA2000-09 : AHG EZshopper Loadpage.cgi File List</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alex_heiphetz_group" name="ezshopper">
        <vers num="2.0" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1093" published="2001-01-09" name="CVE-2000-1093" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in AOL Instant Messenger before 4.3.2229 allows remote attackers to execute arbitrary commands via a long "goim" command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.atstake.com/research/advisories/2000/a121200-1.txt" source="ATSTAKE" patch="1" adv="1">A121200-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aol" name="instant_messenger">
        <vers num="2.0_n" />
        <vers num="2.5.1366" />
        <vers num="2.5.1598" />
        <vers num="3.0.1470" />
        <vers num="3.0_n" />
        <vers num="3.5.1635" />
        <vers num="3.5.1670" />
        <vers num="3.5.1808" />
        <vers num="3.5.1856" />
        <vers num="4.0" />
        <vers num="4.1.2010" />
        <vers num="4.2.1193" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1094" published="2001-01-09" name="CVE-2000-1094" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in AOL Instant Messenger (AIM) before 4.3.2229 allows remote attackers to execute arbitrary commands via a "buddyicon" command with a long "src" argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.atstake.com/research/advisories/2000/a121200-1.txt" source="ATSTAKE" patch="1" adv="1">A121200-1</ref>
      <ref url="http://www.osvdb.org/1692" source="OSVDB">1692</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97683774417132&amp;w=2" source="BUGTRAQ">20001214 Re: AIM &amp; @stake's advisory</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97668265628917&amp;w=2" source="BUGTRAQ">20001213 Administrivia &amp; AOL IM Advisory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aol" name="instant_messenger">
        <vers num="2.0_n" />
        <vers num="2.5.1366" />
        <vers num="2.5.1598" />
        <vers num="3.0.1470" />
        <vers num="3.0_n" />
        <vers num="3.5.1635" />
        <vers num="3.5.1670" />
        <vers num="3.5.1808" />
        <vers num="3.5.1856" />
        <vers num="4.0" />
        <vers num="4.1.2010" />
        <vers num="4.2.1193" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1095" published="2001-01-09" name="CVE-2000-1095" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">modprobe in the modutils 2.3.x package on Linux systems allows a local user to execute arbitrary commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1936" source="BID" patch="1" adv="1">1936</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-108.html" source="REDHAT" patch="1" adv="1">RHSA-2000:108</ref>
      <ref url="http://xforce.iss.net/static/5516.php" source="XF">linux-modprobe-execute-code</ref>
      <ref url="http://www.linux-mandrake.com/en/security/MDKSA-2000-071-1.php3?dis=7.1" source="MANDRAKE">MDKSA-2000:071</ref>
      <ref url="http://www.debian.org/security/2000/20001120" source="DEBIAN">20001120 modutils: local exploit</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000340" source="CONECTIVA">CLSA-2000:340</ref>
      <ref url="http://archives.neohapsis.com/archives/linux/suse/2000-q4/0596.html" source="SUSE">SuSE-SA:2000:44</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0179.html" source="BUGTRAQ">20001112 RedHat 7.0 (and SuSE): modutils + netkit = root compromise. (fwd)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="immunix" name="immunix">
        <vers num="6.2" />
        <vers num="7.0_beta" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="5.1" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="7.2" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.0" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="6.4" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-1096" published="2001-01-09" name="CVE-2000-1096" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">crontab by Paul Vixie uses predictable file names for a temporary file and does not properly ensure that the file is owned by the user executing the crontab -e command, which allows local users with write access to the crontab spool directory to execute arbitrary commands by creating world-writeable temporary files and modifying them while the victim is editing the file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1960" source="BID" patch="1" adv="1">1960</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5543" source="XF">vixie-cron-execute-commands(5543)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0237.html" source="BUGTRAQ">20001116 vixie cron...</ref>
    </refs>
    <vuln_soft>
      <prod vendor="paul_vixie" name="vixie_cron">
        <vers num="3.0_pl1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1097" published="2001-01-09" name="CVE-2000-1097" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The web server for the SonicWALL SOHO firewall allows remote attackers to cause a denial of service via a long username in the authentication page.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2013" source="BID" patch="1" adv="1">2013</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0406.html" source="BUGTRAQ" adv="1">20001129 DoS in Sonicwall SOHO firewall</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5596" source="XF">sonicwall-soho-dos(5596)</ref>
      <ref url="http://www.osvdb.org/1667" source="OSVDB">1667</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0435.html" source="BUGTRAQ">20001201 FW: SonicWALL SOHO Vulnerability (fwd)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sonicwall" name="soho_firewall">
        <vers num="4.0.0" />
        <vers num="5.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1098" published="2001-01-09" name="CVE-2000-1098" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The web server for the SonicWALL SOHO firewall allows remote attackers to cause a denial of service via an empty GET or POST request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0435.html" source="BUGTRAQ" patch="1">20001201 FW: SonicWALL SOHO Vulnerability (fwd)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0439.html" source="BUGTRAQ" adv="1">20001201 Re: DoS in Sonicwall SOHO firewall</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sonicwall" name="soho_firewall">
        <vers num="4.0.0" />
        <vers num="5.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1099" published="2001-01-09" name="CVE-2000-1099" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Java Runtime Environment in Java Development Kit (JDK) 1.2.2_05 and earlier can allow an untrusted Java class to call into a disallowed class, which could allow an attacker to escape the Java sandbox and conduct unauthorized activities.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/199&amp;type=0&amp;nav=sec.sba" source="SUN" patch="1" adv="1">00199</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5605" source="XF">jdk-untrusted-java-class(5605)</ref>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0011-132" source="HP">HPSBUX0011-132</ref>
      <ref url="http://www.osvdb.org/7255" source="OSVDB">7255</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers prev="1" num="1.1.6" edition="update7" />
        <vers prev="1" num="1.1.7b" edition="update5" />
        <vers prev="1" num="1.1.8" edition="update10" />
        <vers prev="1" num="1.1.8" edition="update2" />
        <vers prev="1" num="1.2.1" edition="update3" />
        <vers prev="1" num="1.2.2" edition="update4" />
        <vers prev="1" num="1.2.2" edition="update5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1100" published="2001-01-09" name="CVE-2000-1100" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The default configuration for PostACI webmail system installs the /includes/global.inc configuration file within the web root, which allows remote attackers to read sensitive information such as database usernames and passwords via a direct HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2029" source="BID" patch="1" adv="1">2029</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0433.html" source="BUGTRAQ" patch="1" adv="1">20001130 PostACI Webmail Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trlinux" name="postaci_webmail">
        <vers num="1.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1101" published="2001-01-09" name="CVE-2000-1101" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Winsock FTPd (WFTPD) 3.00 and 2.41 with the "Restrict to home directory" option enabled allows local users to escape the home directory via a "/../" string, a variation of the .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2005" source="BID" patch="1" adv="1">2005</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0386.html" source="BUGTRAQ" patch="1" adv="1">20001127 Vulnerability in Winsock FTPD 2.41/3.00 (Pro)</ref>
      <ref url="http://www.iss.net/security_center/static/5608.php" source="XF">wftpd-dir-traverse(5608)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="texas_imperial_software" name="wftpd">
        <vers num="2.41_rc14" edition="" />
        <vers num="2.41_rc14" edition=":pro" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1102" published="2001-01-09" name="CVE-2000-1102" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PTlink IRCD 3.5.3 and PTlink Services 1.8.1 allow remote attackers to cause a denial of service (server crash) via "mode +owgscfxeb" and "oper" commands.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2008" source="BID" patch="1" adv="1">2008</ref>
      <ref url="http://www.securityfocus.com/archive/1/147115" source="BUGTRAQ" adv="1">20001126 Vulnerablity in PTlink3.5.3ircd + PTlink.Services.1.8.1...</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ptlink" name="ptlink_irc_services">
        <vers num="1.8.1" />
      </prod>
      <prod vendor="ptlink" name="ptlink_ircd">
        <vers num="3.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1103" published="2001-01-09" name="CVE-2000-1103" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">rcvtty in BSD 3.0 and 4.0 does not properly drop privileges before executing a script, which allows local attackers to gain privileges by specifying an alternate Trojan horse script on the command line.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2009" source="BID" adv="1">2009</ref>
      <ref url="http://www.securityfocus.com/archive/1/147120" source="BUGTRAQ" adv="1">20001127 BSDi 3.0/4.0 rcvtty gid=tty exploit... (mh package)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bsdi" name="bsd_os">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="4.0" />
        <vers num="4.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1104" published="2001-01-09" name="CVE-2000-1104" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client.  The client then executes those scripts in the same context as the trusted site.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-060.asp" source="MS" patch="1" adv="1">MS00-060</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1105" published="2001-01-09" name="CVE-2000-1105" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The ixsso.query ActiveX Object is marked as safe for scripting, which allows malicious web site operators to embed a script that remotely determines the existence of files on visiting Windows 2000 systems that have Indexing Services enabled.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1933" source="BID" patch="1" adv="1">1933</ref>
      <ref url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q4/0074.html" source="WIN2KSEC" patch="1" adv="1">20001110 IE 5.x Win2000 Indexing service vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/144270" source="BUGTRAQ">20001110 IE 5.x Win2000 Indexing service vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="indexing_service">
        <vers num="" edition=":windows_2000" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1106" published="2001-01-09" name="CVE-2000-1106" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Trend Micro InterScan VirusWall creates an "Intscan" share to the "InterScan" directory with permissions that grant Full Control permissions to the Everyone group, which allows attackers to gain privileges by modifying the VirusWall programs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2014" source="BID" patch="1" adv="1">2014</ref>
      <ref url="http://www.securityfocus.com/archive/1/147563" source="BUGTRAQ" patch="1" adv="1">20001128 TrendMicro InterScan VirusWall shared folder problem</ref>
      <ref url="http://xforce.iss.net/static/5606.php" source="XF">interscan-viruswall-unauth-access</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0016.html" source="BUGTRAQ">20001201 Responding to BugTraq ID 2014 - "Trend Micro InterScan VirusWall Shared Directory Vulnerability"</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="interscan_viruswall">
        <vers prev="1" num="3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1107" published="2001-01-09" name="CVE-2000-1107" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">in.identd ident server in SuSE Linux 6.x and 7.0 allows remote attackers to cause a denial of service via a long request, which causes the server to access a NULL pointer and crash.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2015" source="BID" patch="1" adv="1">2015</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0387.html" source="BUGTRAQ" patch="1" adv="1">20001128 SuSE Linux 6.x 7.0 Ident buffer overflow</ref>
      <ref url="http://xforce.iss.net/static/5590.php" source="XF">linux-ident-bo</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="suse_linux">
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1108" published="2001-01-09" name="CVE-2000-1108" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">cons.saver in Midnight Commander (mc) 4.5.42 and earlier does not properly verify if an output file descriptor is a TTY, which allows local users to corrupt files by creating a symbolic link to the target file, calling mc, and specifying that link as a TTY argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1945" source="BID" patch="1" adv="1">1945</ref>
      <ref url="http://www.debian.org/security/2000/20001125" source="DEBIAN" patch="1" adv="1">20001125 mc: local DoS</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5519" source="XF">midnight-commander-conssaver-symlink(5519)</ref>
      <ref url="http://www.linux-mandrake.com/en/security/MDKSA-2000-078.php3" source="MANDRAKE">MDKSA-2000:078</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0192.html" source="BUGTRAQ">20001113 Problems with cons.saver</ref>
    </refs>
    <vuln_soft>
      <prod vendor="midnight_commander" name="midnight_commander">
        <vers num="4.5.42" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1109" published="2001-01-09" name="CVE-2000-1109" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Midnight Commander (mc) 4.5.51 and earlier does not properly process malformed directory names when a user opens a directory, which allows other local users to gain privileges by creating directories that contain special characters followed by the commands to be executed.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2016" source="BID" adv="1">2016</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0373.html" source="BUGTRAQ" adv="1">20001127 Midnight Commander</ref>
      <ref url="http://xforce.iss.net/static/5929.php" source="XF">midnight-commander-elevate-privileges(5929)</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2001_011_mc.html" source="SUSE">SuSE-SA:2001:11</ref>
      <ref url="http://www.debian.org/security/2001/dsa-036" source="DEBIAN">DSA-036</ref>
    </refs>
    <vuln_soft>
      <prod vendor="midnight_commander" name="midnight_commander">
        <vers num="4.5.40" />
        <vers num="4.5.41" />
        <vers num="4.5.42" />
        <vers num="4.5.43" />
        <vers num="4.5.44" />
        <vers num="4.5.45" />
        <vers num="4.5.46" />
        <vers num="4.5.47" />
        <vers num="4.5.48" />
        <vers num="4.5.49" />
        <vers num="4.5.50" />
        <vers num="4.5.51" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1110" published="2001-01-09" name="CVE-2000-1110" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">document.d2w CGI program in the IBM Net.Data db2www package allows remote attackers to determine the physical path of the web server by sending a nonexistent command to the program.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2017" source="BID" adv="1">2017</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0384.html" source="BUGTRAQ" adv="1">20001128 IBM Net.Data Local Path Disclosure Vulnerability?</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="net.data">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1111" published="2001-01-09" name="CVE-2000-1111" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Telnet Service for Windows 2000 Professional does not properly terminate incomplete connection attempts, which allows remote attackers to cause a denial of service by connecting to the server and not providing any input.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2018" source="BID" adv="1">2018</ref>
      <ref url="http://www.securityfocus.com/archive/1/147914" source="BUGTRAQ" adv="1">20001129 Windows 2000 Telnet Service DoS </ref>
      <ref url="http://xforce.iss.net/static/5598.php" source="XF">win2k-telnet-dos(5598)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1112" published="2001-01-09" name="CVE-2000-1112" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Microsoft Windows Media Player 7 executes scripts in custom skin (.WMS) files, which could allow remote attackers to gain privileges via a skin that contains a malicious script, aka the ".WMS Script Execution" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1976" source="BID" patch="1" adv="1">1976</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS00-090.asp" source="MS" patch="1" adv="1">MS00-090</ref>
      <ref url="http://xforce.iss.net/static/5575.php" source="XF">mediaplayer-wms-script-exe</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_media_player">
        <vers num="6.4" />
        <vers num="7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1113" published="2001-01-09" name="CVE-2000-1113" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Windows Media Player allows remote attackers to execute arbitrary commands via a malformed Active Stream Redirector (.ASX) file, aka the ".ASX Buffer Overrun" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1980" source="BID" patch="1" adv="1">1980</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS00-090.asp" source="MS" patch="1" adv="1">MS00-090</ref>
      <ref url="http://xforce.iss.net/static/5574.php" source="XF">mediaplayer-asx-bo</ref>
      <ref url="http://www.atstake.com/research/advisories/2000/a112300-1.txt" source="ATSTAKE">A112300-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_media_player">
        <vers num="6.4" />
        <vers num="7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1114" published="2001-01-09" name="CVE-2000-1114" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unify ServletExec AS v3.0C allows remote attackers to read source code for JSP pages via an HTTP request that ends with characters such as ".", or "+", or "%20".</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1970" source="BID" patch="1" adv="1">1970</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0285.html" source="BUGTRAQ" patch="1" adv="1">20001121 Disclosure of JSP source code with ServletExec AS v3.0c + web ins tance</ref>
    </refs>
    <vuln_soft>
      <prod vendor="unify" name="ewave_servletexec">
        <vers num="3.0" />
        <vers num="3.0c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1115" published="2001-01-09" name="CVE-2000-1115" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in remote web administration component (webprox.dll) of 602Pro LAN SUITE before 2000.0.1.33 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1979" source="BID" patch="1" adv="1">1979</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0299.html" source="BUGTRAQ" patch="1" adv="1">20001122 602Pro Lan Suite Web Admin Overflow</ref>
      <ref url="http://www.software602.com/products/ls/support/newbuild.html" source="CONFIRM">http://www.software602.com/products/ls/support/newbuild.html</ref>
      <ref url="http://xforce.iss.net/static/5583.php" source="XF">software602-lan-suite-bo</ref>
    </refs>
    <vuln_soft>
      <prod vendor="software602" name="602pro_lan_suite">
        <vers prev="1" num="2000a_2000.0.1.32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1116" published="2001-01-09" name="CVE-2000-1116" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in TransSoft Broker FTP Server before 4.3.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5388.php" source="XF" patch="1" adv="1">broker-ftp-username-dos</ref>
      <ref url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q4/0041.html" source="WIN2KSEC">20001018 TransSoft's Broker FTP Server 3.x &amp; 4.x Remote DoS attack Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="transsoft" name="broker_ftp_server">
        <vers num="3.0" />
        <vers num="3.0_build_1" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1117" published="2001-01-09" name="CVE-2000-1117" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Extended Control List (ECL) feature of the Java Virtual Machine (JVM) in Lotus Notes Client R5 allows malicious web site operators to determine the existence of files on the client by measuring delays in the execution of the getSystemResource method.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1994" source="BID" adv="1">1994</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0341.html" source="BUGTRAQ">20001124 Security Hole in ECL Feature of Java VM Embedded in Lotus Notes Client R5</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_notes">
        <vers num="r5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1118" published="2001-01-09" name="CVE-2000-1118" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">24Link 1.06 web server allows remote attackers to bypass access restrictions by prepending strings such as "/+/" or "/." to the HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0369.html" source="BUGTRAQ" patch="1" adv="1">20001127 24Link Webserver</ref>
    </refs>
    <vuln_soft>
      <prod vendor="24link" name="24link">
        <vers num="1.06" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1119" published="2001-01-09" name="CVE-2000-1119" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in setsenv command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands via a long "x=" argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2032" source="BID" patch="1" adv="1">2032</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97569466809056&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20001201 Fixed local AIX V43 vulnerabilities </ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5621" source="XF">aix-setsenv-bo(5621)</ref>
      <ref url="http://www.osvdb.org/1676" source="OSVDB">1676</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY10721&amp;apar=only" source="AIXAPAR">IY10721</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY08812&amp;apar=only" source="AIXAPAR">IY08812</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.2" />
        <vers num="4.2.1" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1120" published="2001-01-09" name="CVE-2000-1120" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in digest command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2033" source="BID" patch="1" adv="1">2033</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97569466809056&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20001201 Fixed local AIX V43 vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5620" source="XF">aix-digest-bo(5620)</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY08287&amp;apar=only" source="AIXAPAR">IY08287</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY08143&amp;apar=only" source="AIXAPAR">IY08143</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.2" />
        <vers num="4.2.1" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1121" published="2001-01-09" name="CVE-2000-1121" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in enq command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a long -M argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2034" source="BID" patch="1" adv="1">2034</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97569466809056&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20001201 Fixed local AIX V43 vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5619" source="XF">aix-enq-bo(5619)</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY08287&amp;apar=only" source="AIXAPAR">IY08287</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY08143&amp;apar=only" source="AIXAPAR">IY08143</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.2" />
        <vers num="4.2.1" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1122" published="2001-01-09" name="CVE-2000-1122" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in setclock command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a long argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2035" source="BID" patch="1" adv="1">2035</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97569466809056&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20001201 Fixed local AIX V43 vulnerabilities</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY07831&amp;apar=only" source="AIXAPAR">IY07831</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY07790&amp;apar=only" source="AIXAPAR">IY07790</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.2" />
        <vers num="4.2.1" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1123" published="2001-01-09" name="CVE-2000-1123" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in pioout command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2036" source="BID" patch="1" adv="1">2036</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97569466809056&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20001201 Fixed local AIX V43 vulnerabilities</ref>
      <ref url="http://xforce.iss.net/static/5617.php" source="XF">aix-pioout-bo</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY12638&amp;apar=only" source="AIXAPAR">IY12638</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1124" published="2001-01-09" name="CVE-2000-1124" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in piobe command in IBM AIX 4.3.x allows local users to gain privileges via long environmental variables.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2037" source="BID" patch="1" adv="1">2037</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97569466809056&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20001201 Fixed local AIX V43 vulnerabilities</ref>
      <ref url="http://xforce.iss.net/static/5616.php" source="XF">aix-piobe-bo(5616)</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY12638&amp;apar=only" source="AIXAPAR">IY12638</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1125" published="2001-01-09" name="CVE-2000-1125" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">restore 0.4b15 and earlier in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which allows local users to obtain root privileges by modifying the RSH variable to point to a Trojan horse program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1914" source="BID" adv="1">1914</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97336034309944&amp;w=2" source="BUGTRAQ" adv="1">20001104 Redhat 6.2 restore exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="6.2" />
        <vers num="6.2e" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1126" published="2001-01-09" name="CVE-2000-1126" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Vulnerability in auto_parms and set_parms in HP-UX 11.00 and earlier allows remote attackers to execute arbitrary commands or cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1954" source="BID" patch="1" adv="1">1954</ref>
      <ref url="http://www.securityfocus.com/advisories/2850" source="HP" patch="1" adv="1">HPSBUX0011-130</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5655" source="OVAL">oval:org.mitre.oval:def:5655</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.01" />
        <vers num="10.10" />
        <vers num="10.20" />
        <vers num="10.24" />
        <vers num="11.00" />
        <vers num="11.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-1127" published="2001-01-09" name="CVE-2000-1127" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">registrar in the HP resource monitor service allows local users to read and modify arbitrary files by renaming the original registrar.log log file and creating a symbolic link to the target file, to which registrar appends log information and sets the permissions to be world readable.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1919" source="BID" patch="1" adv="1">1919</ref>
      <ref url="http://www.securityfocus.com/archive/1/143845" source="BUGTRAQ" patch="1" adv="1">20001108 HP-UX 10.20 resource monitor service</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1128" published="2001-01-09" name="CVE-2000-1128" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The default configuration of McAfee VirusScan 4.5 does not quote the ImagePath variable, which improperly sets the search path and allows local users to place a Trojan horse "common.exe" program in the C:\Program Files directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1920" source="BID" patch="1" adv="1">1920</ref>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q4/0073.html" source="NTBUGTRAQ" patch="1" adv="1">20001103 Elevation of Privileges Exploit with McAfee VirusScan 4.5</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcafee" name="virusscan">
        <vers num="4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1129" published="2001-01-09" name="CVE-2000-1129" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">McAfee WebShield SMTP 4.5 allows remote attackers to cause a denial of service via a malformed recipient field.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1999" source="BID" patch="1" adv="1">1999</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0324.html" source="BUGTRAQ" adv="1">20001123 McAfee WebShield SMTP vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="network_associates" name="webshield_smtp">
        <vers num="4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1130" published="2001-01-09" name="CVE-2000-1130" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">McAfee WebShield SMTP 4.5 allows remote attackers to bypass email content filtering rules by including Extended ASCII characters in name of the attachment.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1993" source="BID" adv="1">1993</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0324.html" source="BUGTRAQ" adv="1">20001123 McAfee WebShield SMTP vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="network_associates" name="webshield_smtp">
        <vers num="4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1131" published="2001-01-09" name="CVE-2000-1131" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Bill Kendrick web site guestbook (GBook) allows remote attackers to execute arbitrary commands via shell metacharacters in the _MAILTO form variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1940" source="BID" patch="1" adv="1">1940</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0144.html" source="BUGTRAQ" adv="1">20001110 [hacksware] gbook.cgi remote command execution vulnerability</ref>
      <ref url="http://xforce.iss.net/static/5509.php" source="XF">gbook-cgi-remote-execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bill_kendrick" name="gbook.cgi">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1132" published="2001-01-09" name="CVE-2000-1132" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">DCForum cgforum.cgi CGI script allows remote attackers to read arbitrary files, and delete the program itself, via a malformed "forum" variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1951" source="BID" patch="1" adv="1">1951</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0218.html" source="BUGTRAQ" patch="1" adv="1">20001114 Cgisecurity.com advisory on dcforum</ref>
      <ref url="http://www.dcscripts.com/dcforum/dcfNews/124.html#1" source="CONFIRM">http://www.dcscripts.com/dcforum/dcfNews/124.html#1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5533" source="XF">dcforum-cgi-view-files(5533)</ref>
      <ref url="http://www.osvdb.org/1646" source="OSVDB">1646</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dcscripts" name="dcforum">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1133" published="2001-01-09" name="CVE-2000-1133" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Authentix Authentix100 allows remote attackers to bypass authentication by inserting a . (dot) into the URL for a protected directory.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1907" source="BID" patch="1" adv="1">1907</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97362374200478&amp;w=2" source="BUGTRAQ" adv="1">20001107 Explanation Authentix Input Validation Error</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97353881829760&amp;w=2" source="BUGTRAQ">20001106 Authentix Security Advisory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="flicks_software" name="authentix">
        <vers num="5.1c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1134" published="2001-01-09" name="CVE-2000-1134" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing &lt;&lt; redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/10277" source="CERT-VN">VU#10277</ref>
      <ref url="http://www.securityfocus.com/bid/2006" source="BID" patch="1" adv="1">2006</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:76.tcsh-csh.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-00:76</ref>
      <ref url="http://www.securityfocus.com/bid/1926" source="BID">1926</ref>
      <ref url="http://www.securityfocus.com/archive/1/146657" source="BUGTRAQ">20001128  /bin/sh creates insecure tmp files</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-121.html" source="REDHAT">RHSA-2000:121</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-117.html" source="REDHAT">RHSA-2000:117</ref>
      <ref url="http://www.linux-mandrake.com/en/security/MDKSA-2000-075.php3" source="MANDRAKE">MDKSA-2000:075</ref>
      <ref url="http://www.linux-mandrake.com/en/security/MDKSA-2000-069.php3" source="MANDRAKE">MDKSA-2000-069</ref>
      <ref url="http://www.debian.org/security/2000/20001111a" source="DEBIAN">20001111a</ref>
      <ref url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-043.0.txt" source="CALDERA">CSSA-2000-043.0</ref>
      <ref url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-042.0.txt" source="CALDERA">CSSA-2000-042.0</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97561816504170&amp;w=2" source="BUGTRAQ">20001130 [ADV/EXP]: RH6.x root from bash /tmp vuln + MORE</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000354" source="CONECTIVA">CLSA-2000:354</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000350" source="CONECTIVA">CLA-2000:350</ref>
      <ref url="http://archives.neohapsis.com/archives/tru64/2002-q1/0009.html" source="COMPAQ">SSRT1-41U</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0418.html" source="BUGTRAQ">20001028 tcsh: unsafe tempfile in &lt;&lt; redirects</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20011103-02-P" source="SGI">20011103-02-P</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4047" source="OVAL" sig="1">oval:org.mitre.oval:def:4047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="immunix" name="immunix">
        <vers num="6.2" />
      </prod>
      <prod vendor="caldera" name="openlinux">
        <vers num="" />
      </prod>
      <prod vendor="caldera" name="openlinux_edesktop">
        <vers num="2.4" />
      </prod>
      <prod vendor="caldera" name="openlinux_eserver">
        <vers num="2.3" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="4.0" />
        <vers num="4.0es" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.11" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="5.2" />
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.2e" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1135" published="2001-01-09" name="CVE-2000-1135" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">fshd (fsh daemon) in Debian GNU/Linux allows local users to overwrite files of other users via a symlink attack.</descript>
    </desc>
    <sols>
      <sol source="nvd">Note: fixed in potato version</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2000/20001130" source="DEBIAN" patch="1" adv="1">20001130 DSA-002-1 fsh: symlink attack</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5633" source="XF">linux-fsh-symlink(5633)</ref>
      <ref url="http://www.osvdb.org/7208" source="OSVDB">7208</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1136" published="2001-01-09" name="CVE-2000-1136" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">elvis-tiny before 1.4-10 in Debian GNU/Linux, and possibly other Linux operating systems, allows local users to overwrite files of other users via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1984" source="BID" patch="1" adv="1">1984</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97502995616099&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20001122 New version of elvis-tiny released</ref>
      <ref url="http://xforce.iss.net/static/5632.php" source="XF">linux-tinyelvis-tmpfiles</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="elvis_tiny">
        <vers prev="1" num="1.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1137" published="2001-01-09" name="CVE-2000-1137" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">GNU ed before 0.2-18.1 allows local users to overwrite the files of other users via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-123.html" source="REDHAT" patch="1" adv="1">RHSA-2000:123</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5723" source="XF">gnu-ed-symlink(5723)</ref>
      <ref url="http://www.osvdb.org/6491" source="OSVDB">6491</ref>
      <ref url="http://www.linux-mandrake.com/en/security/MDKSA-2000-076.php3" source="MANDRAKE">MDKSA-2000:076</ref>
      <ref url="http://www.debian.org/security/2000/20001129" source="DEBIAN">20001129 DSA-001-1 ed: symlink attack</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000359" source="CONECTIVA">CLA-2000:359-2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="ed">
        <vers num="2.15" />
        <vers num="2.16tr" />
        <vers num="2.18" />
        <vers num="2.18.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1138" published="2001-01-09" name="CVE-2000-1138" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Lotus Notes R5 client R5.0.5 and earlier does not properly warn users when an S/MIME email message has been modified, which could allow an attacker to modify the email in transit without being detected.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1925" source="BID" adv="1">1925</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97370725220953&amp;w=2" source="BUGTRAQ" adv="1">20001108 Lotus Notes R5 clients - no warning for broken signature or encryption</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_notes">
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers prev="1" num="5.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1139" published="2001-01-09" name="CVE-2000-1139" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The installation of Microsoft Exchange 2000 before Rev. A creates a user account with a known password, which could allow attackers to gain privileges, aka the "Exchange User Account" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1958" source="BID" patch="1" adv="1">1958</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-088.asp" source="MS" patch="1" adv="1">MS00-088</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5537" source="XF">ms-exchange-username-pwd(5537)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="2000" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-1140" published="2001-01-09" name="CVE-2000-1140" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Recourse ManTrap 1.6 does not properly hide processes from attackers, which could allow attackers to determine that they are in a honeypot system by comparing the results from kill commands with the process listing in the /proc filesystem.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1908" source="BID" patch="1" adv="1">1908</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0100.html" source="BUGTRAQ" adv="1">20001107 Vendor Response Re: Mantrap Advisory Vendor Followup - Fate Research Labs</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0041.html" source="BUGTRAQ" adv="1">20001102 Mantrap By Recourse Technologies - Fate Advisory (11-01-00)</ref>
      <ref url="http://xforce.iss.net/static/5473.php" source="XF">mantrap-hidden-processes</ref>
    </refs>
    <vuln_soft>
      <prod vendor="recourse_technologies" name="mantrap">
        <vers num="1.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-1141" published="2001-01-09" name="CVE-2000-1141" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Recourse ManTrap 1.6 modifies the kernel so that ".." does not appear in the /proc listing, which allows attackers to determine that they are in a honeypot system.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97349791405580&amp;w=2" source="BUGTRAQ" adv="1">20001105 Mantrap Advisory Vendor Followup - Fate Research Labs</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0100.html" source="BUGTRAQ" adv="1">20001107 Vendor Response Re: Mantrap Advisory Vendor Followup - Fate Research Labs</ref>
      <ref url="http://xforce.iss.net/static/5473.php" source="XF">mantrap-hidden-processes</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0041.html" source="BUGTRAQ">20001102 Mantrap By Recourse Technologies - Fate Advisory (11-01-00)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="recourse_technologies" name="mantrap">
        <vers num="1.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-1142" published="2001-01-09" name="CVE-2000-1142" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Recourse ManTrap 1.6 generates an error when an attacker cd's to /proc/self/cwd and executes the pwd command, which allows attackers to determine that they are in a honeypot system.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97349791405580&amp;w=2" source="BUGTRAQ" adv="1">20001105 Mantrap Advisory Vendor Followup - Fate Research Labs</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0100.html" source="BUGTRAQ" adv="1">20001107 Vendor Response Re: Mantrap Advisory Vendor Followup - Fate Research Labs</ref>
      <ref url="http://xforce.iss.net/static/5949.php" source="XF">mantrap-pwd-reveal-information</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0041.html" source="BUGTRAQ">20001102 Mantrap By Recourse Technologies - Fate Advisory (11-01-00)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="recourse_technologies" name="mantrap">
        <vers num="1.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-1143" published="2001-01-09" name="CVE-2000-1143" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Recourse ManTrap 1.6 hides the first 4 processes that run on a Solaris system, which allows attackers to determine that they are in a honeypot system.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97349791405580&amp;w=2" source="BUGTRAQ" adv="1">20001105 Mantrap Advisory Vendor Followup - Fate Research Labs</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0100.html" source="BUGTRAQ" adv="1">20001107 Vendor Response Re: Mantrap Advisory Vendor Followup - Fate Research Labs</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0041.html" source="BUGTRAQ" adv="1">20001102 Mantrap By Recourse Technologies - Fate Advisory (11-01-00)</ref>
      <ref url="http://xforce.iss.net/static/5473.php" source="XF">mantrap-hidden-processes</ref>
    </refs>
    <vuln_soft>
      <prod vendor="recourse_technologies" name="mantrap">
        <vers num="1.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-1144" published="2001-01-09" name="CVE-2000-1144" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Recourse ManTrap 1.6 sets up a chroot environment to hide the fact that it is running, but the inode number for the resulting "/" file system is higher than normal, which allows attackers to determine that they are in a chroot environment.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1909" source="BID" patch="1" adv="1">1909</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0100.html" source="BUGTRAQ" adv="1">20001107 Vendor Response Re: Mantrap Advisory Vendor Followup - Fate Research Labs</ref>
      <ref url="http://xforce.iss.net/static/5472.php" source="XF">mantrap-inode-disclosure</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97349791405580&amp;w=2" source="BUGTRAQ">20001105 Mantrap Advisory Vendor Followup - Fate Research Labs</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0041.html" source="BUGTRAQ">20001102 Mantrap By Recourse Technologies - Fate Advisory (11-01-00)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="recourse_technologies" name="mantrap">
        <vers num="1.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1145" published="2001-01-09" name="CVE-2000-1145" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Recourse ManTrap 1.6 allows attackers who have gained root access to use utilities such as crash or fsdb to read /dev/mem and raw disk devices to identify ManTrap processes or modify arbitrary data files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97349791405580&amp;w=2" source="BUGTRAQ" adv="1">20001105 Mantrap Advisory Vendor Followup - Fate Research Labs</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0100.html" source="BUGTRAQ" adv="1">20001107 Vendor Response Re: Mantrap Advisory Vendor Followup - Fate Research Labs</ref>
      <ref url="http://xforce.iss.net/static/5950.php" source="XF">mantrap-identify-processes</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0041.html" source="BUGTRAQ">20001102 Mantrap By Recourse Technologies - Fate Advisory (11-01-00)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="recourse_technologies" name="mantrap">
        <vers num="1.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-1146" published="2001-01-09" name="CVE-2000-1146" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Recourse ManTrap 1.6 allows attackers to cause a denial of service via a sequence of commands that navigate into and out of the /proc/self directory and executing various commands such as ls or pwd.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1913" source="BID" patch="1" adv="1">1913</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0100.html" source="BUGTRAQ" adv="1">20001107 Vendor Response Re: Mantrap Advisory Vendor Followup - Fate Research Labs</ref>
      <ref url="http://xforce.iss.net/static/5528.php" source="XF">mantrap-dir-dos</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97349791405580&amp;w=2" source="BUGTRAQ">20001105 Mantrap Advisory Vendor Followup - Fate Research Labs</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0041.html" source="BUGTRAQ">20001102 Mantrap By Recourse Technologies - Fate Advisory (11-01-00)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="recourse_technologies" name="mantrap">
        <vers num="1.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1147" published="2001-01-09" name="CVE-2000-1147" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in IIS ISAPI .ASP parsing mechanism allows attackers to execute arbitrary commands via a long string to the "LANGUAGE" argument in a script tag.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1911" source="BID" patch="1" adv="1">1911</ref>
      <ref url="http://www.securityfocus.com/archive/1/143070" source="BUGTRAQ" patch="1" adv="1">20001103 IIS ASP $19.95 hack - IISHack 1.5</ref>
      <ref url="http://xforce.iss.net/static/5510.php" source="XF">iis-isapi-asp-bo</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1148" published="2001-01-09" name="CVE-2000-1148" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The installation of VolanoChatPro chat server sets world-readable permissions for its configuration file and stores the server administrator passwords in plaintext, which allows local users to gain privileges on the server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1906" source="BID" patch="1" adv="1">1906</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0085.html" source="BUGTRAQ" adv="1">20001106 Re: FW: Filesystem Access + VolanoChat = VChat admin (fwd)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0072.html" source="BUGTRAQ" adv="1">20001104 Filesystem Access + VolanoChat = VChat admin (fwd)</ref>
      <ref url="http://xforce.iss.net/static/5465.php" source="XF">volanochatpro-plaintext-password</ref>
    </refs>
    <vuln_soft>
      <prod vendor="volano_llc" name="volanochatpro">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1149" published="2001-01-09" name="CVE-2000-1149" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in RegAPI.DLL used by Windows NT 4.0 Terminal Server allows remote attackers to execute arbitrary commands via a long username, aka the "Terminal Server Login Buffer Overflow" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1924" source="BID" patch="1" adv="1">1924</ref>
      <ref url="http://www.securityfocus.com/archive/1/143991" source="BUGTRAQ" patch="1" adv="1">20001108 [CORE SDI ADVISORY] MS NT4.0 Terminal Server Edition GINA buffer overflow </ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-087.asp" source="MS" patch="1" adv="1">MS00-087</ref>
      <ref url="http://xforce.iss.net/static/5489.php" source="XF">nt-termserv-gina-bo</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="terminal_server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1150" published="2001-01-09" name="CVE-2000-1150" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Felix IRC client in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0203.html" source="BUGTRAQ" adv="1">20001113 beos vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xavier_ducrohet" name="felix">
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1151" published="2001-01-09" name="CVE-2000-1151" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Baxter IRC client in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0203.html" source="BUGTRAQ" adv="1">20001113 beos vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="abisoft" name="baxter">
        <vers num="x" />
        <vers num="y" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1152" published="2001-01-09" name="CVE-2000-1152" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Browser IRC client in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0203.html" source="BUGTRAQ">20001113 beos vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="be" name="beos">
        <vers num="4.5" />
        <vers num="5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1153" published="2001-01-09" name="CVE-2000-1153" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PostMaster 1.0 in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0203.html" source="BUGTRAQ" adv="1">20001113 beos vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kenny_carruthers" name="postmaster">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1154" published="2001-01-09" name="CVE-2000-1154" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">RHConsole in RobinHood 1.1 web server in BeOS r5 pro and earlier allows remote attackers to cause a denial of service via long HTTP request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0203.html" source="BUGTRAQ" adv="1">20001113 beos vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joe_kloss" name="robinhood">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1155" published="2001-01-09" name="CVE-2000-1155" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">RHDaemon in RobinHood 1.1 web server in BeOS r5 pro and earlier allows remote attackers to cause a denial of service via long HTTP request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0203.html" source="BUGTRAQ" adv="1">20001113 beos vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joe_kloss" name="robinhood">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-1156" published="2001-01-09" name="CVE-2000-1156" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">StarOffice 5.2 follows symlinks and sets world-readable permissions for the /tmp/soffice.tmp directory, which allows a local user to read files of the user who is using StarOffice.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1922" source="BID" patch="1" adv="1">1922</ref>
      <ref url="http://xforce.iss.net/static/5487.php" source="XF">staroffice-tmp-sym-link</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0115.html" source="BUGTRAQ" adv="1">20001108 StarOffice 5.2 Temporary Dir Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="staroffice">
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1157" published="2001-01-09" name="CVE-2000-1157" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in NAI Sniffer Agent allows remote attackers to execute arbitrary commands via a long SNMP community name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1901" source="BID" adv="1">1901</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0038.html" source="BUGTRAQ" adv="1">20001102 Remotely exploitable buffer overflow in NAI's Distributed Sniffer Agent</ref>
    </refs>
    <vuln_soft>
      <prod vendor="network_associates" name="sniffer_agent">
        <vers num="3.0.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1158" published="2001-01-09" name="CVE-2000-1158" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">NAI Sniffer Agent uses base64 encoding for authentication, which allows attackers to sniff the network and easily decrypt usernames and passwords.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0038.html" source="BUGTRAQ" adv="1">20001102 Remotely exploitable buffer overflow in NAI's Distributed Sniffer Agent</ref>
    </refs>
    <vuln_soft>
      <prod vendor="network_associates" name="sniffer_agent">
        <vers num="3.0.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1159" published="2001-01-09" name="CVE-2000-1159" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">NAI Sniffer Agent allows remote attackers to gain privileges on the agent by sniffing the initial UDP authentication packets and spoofing commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1902" source="BID" adv="1">1902</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0038.html" source="BUGTRAQ" adv="1">20001102 Remotely exploitable buffer overflow in NAI's Distributed Sniffer Agent</ref>
    </refs>
    <vuln_soft>
      <prod vendor="network_associates" name="sniffer_agent">
        <vers num="3.0.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1160" published="2001-01-09" name="CVE-2000-1160" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">NAI Sniffer Agent allows remote attackers to cause a denial of service (crash) by sending a large number of login requests.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1903" source="BID" adv="1">1903</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0038.html" source="BUGTRAQ" adv="1">20001102 Remotely exploitable buffer overflow in NAI's Distributed Sniffer Agent</ref>
    </refs>
    <vuln_soft>
      <prod vendor="network_associates" name="sniffer_agent">
        <vers num="3.0.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1161" published="2001-01-09" name="CVE-2000-1161" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The installation of AdCycle banner management system leaves the build.cgi program in a web-accessible directory, which allows remote attackers to execute the program and view passwords or delete databases.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1969" source="BID" patch="1" adv="1">1969</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0271.html" source="BUGTRAQ" patch="1" adv="1">20001120 security problem in AdCycle installation</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adcycle" name="adcycle">
        <vers num="0.77b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-1162" published="2001-01-09" name="CVE-2000-1162" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">ghostscript before 5.10-16 allows local users to overwrite files of other users via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1990" source="BID" patch="1" adv="1">1990</ref>
      <ref url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-041.0.txt" source="CALDERA" patch="1" adv="1">CSSA-2000-041</ref>
      <ref url="http://xforce.iss.net/static/5563.php" source="XF">ghostscript-sym-link</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-114.html" source="REDHAT">RHSA-2000:114</ref>
      <ref url="http://www.linux-mandrake.com/en/security/MDKSA-2000-074.php3" source="MANDRAKE">MDKSA-2000:074</ref>
      <ref url="http://www.debian.org/security/2000/20001123" source="DEBIAN">20001123 ghostscript: symlink attack</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000343" source="CONECTIVA">CLSA-2000:343</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aladdin_enterprises" name="ghostscript">
        <vers num="4.3" />
        <vers num="5.10.10" />
        <vers num="5.10.15" />
        <vers num="5.50" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1163" published="2001-01-09" name="CVE-2000-1163" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">ghostscript before 5.10-16 uses an empty LD_RUN_PATH environmental variable to find libraries in the current directory, which could allow local users to execute commands as other users by placing a Trojan horse library into a directory from which another user executes ghostscript.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1991" source="BID" patch="1" adv="1">1991</ref>
      <ref url="http://www.debian.org/security/2000/20001123" source="DEBIAN" patch="1" adv="1">20001123 ghostscript: symlink attack</ref>
      <ref url="http://xforce.iss.net/static/5564.php" source="XF">ghostscript-env-variable</ref>
      <ref url="http://www.linux-mandrake.com/en/security/MDKSA-2000-074.php3" source="MANDRAKE">MDKSA-2000:074</ref>
      <ref url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-041.0.txt" source="CALDERA">CSSA-2000-041</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000343" source="CONECTIVA">CLSA-2000:343</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aladdin_enterprises" name="ghostscript">
        <vers num="4.3" />
        <vers num="5.10.10" />
        <vers num="5.10.15" />
        <vers num="5.10cl" />
        <vers num="5.50" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1164" published="2001-01-09" name="CVE-2000-1164" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">WinVNC installs the WinVNC3 registry key with permissions that give Special Access (read and modify) to the Everybody group, which allows users to read and modify sensitive information such as passwords and gain access to the system.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1961" source="BID" patch="1" adv="1">1961</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0253.html" source="BUGTRAQ" patch="1" adv="1">20001118 WinVNC 3.3.x</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5545" source="XF">winvnc-modify-registry(5545)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="att" name="winvnc">
        <vers num="3.3.3" />
        <vers num="3.3.3r7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1165" published="2001-01-09" name="CVE-2000-1165" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Balabit syslog-ng allows remote attackers to cause a denial of service (application crash) via a malformed log message that does not have a closing > in the priority specifier.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1981" source="BID" patch="1" adv="1">1981</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0300.html" source="BUGTRAQ" patch="1" adv="1">20001122 DoS possibility in syslog-ng</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5576" source="XF">balabit-syslog-ng-dos(5576)</ref>
      <ref url="http://www.balabit.hu/products/syslog-ng/" source="CONFIRM">http://www.balabit.hu/products/syslog-ng/</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:02.syslog-ng.asc" source="FREEBSD">FreeBSD-SA-01:02</ref>
    </refs>
    <vuln_soft>
      <prod vendor="balabit" name="syslog-ng">
        <vers prev="1" num="1.4.6" />
        <vers num="1.4.7" />
        <vers num="1.4.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1166" published="2001-01-09" name="CVE-2000-1166" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Twig webmail system does not properly set the "vhosts" variable if it is not configured on the site, which allows remote attackers to insert arbitrary PHP (PHP3) code by specifying an alternate vhosts as an argument to the index.php3 program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1998" source="BID" patch="1" adv="1">1998</ref>
      <ref url="http://twig.screwdriver.net/file.php3?file=CHANGELOG" source="CONFIRM">http://twig.screwdriver.net/file.php3?file=CHANGELOG</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0351.html" source="BUGTRAQ" adv="1">20001124 Security problems with TWIG webmail system</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5581" source="XF">twig-php3-script-execute(5581)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="twig_development_team" name="twig">
        <vers num="2.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1167" published="2001-01-09" name="CVE-2000-1167" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">ppp utility in FreeBSD 4.1.1 and earlier does not properly restrict access as specified by the "nat deny_incoming" command, which allows remote attackers to connect to the target system.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1974" source="BID" patch="1" adv="1">1974</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5584" source="XF">freebsd-ppp-bypass-gateway(5584)</ref>
      <ref url="http://www.osvdb.org/1655" source="OSVDB">1655</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:70.ppp-nat.asc" source="FREEBSD">FreeBSD-SA-00:70</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.5" />
        <vers num="3.5.1" />
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.1.1" edition="stable" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1168" published="2001-01-09" name="CVE-2000-1168" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">IBM HTTP Server 1.3.6 (based on Apache) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97502498610979&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20001123 IBM HTTP Server 1.3.6 Remote Overflow</ref>
      <ref url="http://www.securityfocus.com/bid/1988" source="BID" adv="1">1988</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="http_server">
        <vers num="1.3.6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1169" published="2001-01-09" name="CVE-2000-1169" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">OpenSSH SSH client before 2.3.0 does not properly disable X11 or agent forwarding, which could allow a malicious SSH server to gain access to the X11 display and sniff X11 events, or gain access to the ssh-agent.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1949" source="BID" patch="1" adv="1">1949</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0195.html" source="BUGTRAQ" patch="1" adv="1">20001123 OpenSSH Security Advisory (adv.fwd)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5517" source="XF">openssh-unauthorized-access(5517)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-111.html" source="REDHAT">RHSA-2000:111</ref>
      <ref url="http://www.osvdb.org/6248" source="OSVDB">6248</ref>
      <ref url="http://www.osvdb.org/2114" source="OSVDB">2114</ref>
      <ref url="http://www.linux-mandrake.com/en/security/MDKSA-2000-068.php3" source="MANDRAKE">MDKSA-2000:068</ref>
      <ref url="http://www.debian.org/security/2000/20001118" source="DEBIAN">20001118 openssh: possible remote exploit</ref>
      <ref url="http://lists.suse.com/archives/suse-security-announce/2000-Nov/0004.html" source="SUSE">SuSE-SA:2000:47</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000345" source="CONECTIVA">CLSA-2000:345</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0217.html" source="BUGTRAQ">20001115 Trustix Security Advisory - bind and openssh (and modutils)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openssh">
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1170" published="2001-01-09" name="CVE-2000-1170" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Netsnap webcam HTTP server before 1.2.9 allows remote attackers to execute arbitrary commands via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1956" source="BID" patch="1" adv="1">1956</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97439536016554&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20001115 Netsnap Webcam Software Remote Overflow</ref>
      <ref url="http://www.netsnap.com/new.htm" source="CONFIRM">http://www.netsnap.com/new.htm</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5534" source="XF">netsnap-remote-bo(5534)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pelesoft" name="netsnap">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1171" published="2001-01-09" name="CVE-2000-1171" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in cgiforum.pl script in CGIForum 1.0 allows remote attackers to ready arbitrary files via a .. (dot dot) attack in the "thesection" parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1963" source="BID" patch="1" adv="1">1963</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0263.html" source="BUGTRAQ" adv="1">20001120 CGIForum 1.0 Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5553" source="XF">cgiforum-view-files(5553)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="markus_triska" name="cgiforum">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1172" published="2001-01-09" name="CVE-2000-1172" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Gaim 0.10.3 and earlier using the OSCAR protocol allows remote attackers to conduct a denial of service and possibly execute arbitrary commands via a long HTML tag.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1948" source="BID" adv="1">1948</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0204.html" source="BUGTRAQ" adv="1">20001110 Advisory: Gaim remote vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rob_flynn" name="gaim">
        <vers num="0.10" />
        <vers num="0.10.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1173" published="2001-01-09" name="CVE-2000-1173" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsys CyberPatrol uses weak encryption (trivial encoding) for credit card numbers and uses no encryption for the remainder of the information during registration, which could allow attackers to sniff network traffic and obtain this sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1977" source="BID" adv="1">1977</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0323.html" source="BUGTRAQ" adv="1">20001122 CyberPatrol - poor credit card protection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsys" name="cyberpatrol">
        <vers num="4.04.003" />
        <vers num="4.04.005" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1174" published="2001-01-09" name="CVE-2000-1174" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in AFS ACL parser for Ethereal 0.8.13 and earlier allows remote attackers to execute arbitrary commands via a packet with a long username.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1972" source="BID" patch="1" adv="1">1972</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5557" source="XF">ethereal-afs-bo(5557)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-116.html" source="REDHAT">RHSA-2000:116</ref>
      <ref url="http://www.debian.org/security/2000/20001122a" source="DEBIAN">20001121 ethereal: remote exploit</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000342" source="CONECTIVA">CLSA-2000:342</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0251.html" source="BUGTRAQ">20001118 [hacksware] Ethereal 0.8.13 AFS ACL parsing buffer overflow bug</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:81.ethereal.asc" source="FREEBSD">FreeBSD-SA-00:81</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers prev="1" num="0.8.13" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1175" published="2001-01-09" name="CVE-2000-1175" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Koules 1.4 allows local users to execute arbitrary commands via a long command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1967" source="BID" adv="1">1967</ref>
      <ref url="http://www.securityfocus.com/archive/1/145823" source="BUGTRAQ" adv="1">20001120 local exploit for linux's Koules1.4 package</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jan_hubicka" name="koules">
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1176" published="2001-01-09" name="CVE-2000-1176" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in YaBB search.pl CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "catsearch" form field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1921" source="BID" adv="1">1921</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0110.html" source="BUGTRAQ" adv="1">20001107 Insecure input balidation in YaBB Search.pl</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yabb" name="yabb">
        <vers num="2000-09-11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1177" published="2001-01-09" name="CVE-2000-1177" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">bb-hist.sh, bb-histlog.sh, bb-hostsvc.sh, bb-rep.sh, bb-replog.sh, and bb-ack.sh in Big Brother (BB) before 1.5d3 allows remote attackers to determine the existence of files and user ID's by specifying the target file in the HISTFILE parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1971" source="BID" patch="1" adv="1">1971</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0284.html" source="BUGTRAQ" patch="1" adv="1">20001121 Big Brother Advisory - Fate Research Labs</ref>
      <ref url="http://bb4.com/incident.nov21" source="CONFIRM">http://bb4.com/incident.nov21</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bb4" name="big_brother_network_monitor">
        <vers prev="1" num="1.5d2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-1178" published="2001-01-09" name="CVE-2000-1178" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Joe text editor follows symbolic links when creating a rescue copy called DEADJOE during an abnormal exit, which allows local users to overwrite the files of other users whose joe session crashes.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1959" source="BID" patch="1" adv="1">1959</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0227.html" source="BUGTRAQ" adv="1">20001116 Joe's Own Editor File Link Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5546" source="XF">joe-symlink-corruption(5546)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-110.html" source="REDHAT">RHSA-2000:110</ref>
      <ref url="http://www.linux-mandrake.com/en/security/MDKSA-2000-072.php3" source="MANDRAKE">MDKSA-2000:072</ref>
      <ref url="http://www.debian.org/security/2000/20001201" source="DEBIAN">20001201 DSA-003-1 joe: symlink attack</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97500174210821&amp;w=2" source="BUGTRAQ">20001121 Immunix OS Security update for joe</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000356" source="CONECTIVA">CLA-2000:356</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joseph_allen" name="joe">
        <vers num="2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1179" published="2001-01-09" name="CVE-2000-1179" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Netopia ISDN Router 650-ST before 4.3.5 allows remote attackers to read system logs without authentication by directly connecting to the login screen and typing certain control characters.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1952" source="BID" patch="1" adv="1">1952</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97440068130051&amp;w=2" source="BUGTRAQ" adv="1">20001115 Netopia ISDN Router 650-ST: Viewing of all system logs without login</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5536" source="XF">netopia-view-system-log(5536)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netopia" name="650-st_isdn_router">
        <vers num="3.3.2_firmware" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1180" published="2001-01-09" name="CVE-2000-1180" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in cmctl program in Oracle 8.1.5 Connection Manager Control allows local users to gain privileges via a long command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1968" source="BID" patch="1" adv="1">1968</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5551" source="XF">oracle-cmctl-bo(5551)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97474521003453&amp;w=2" source="BUGTRAQ" adv="1">20001120 vulnerability in Connection Manager Control binary in Oracle</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="oracle8i">
        <vers num="8.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1181" published="2001-01-09" name="CVE-2000-1181" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Real Networks RealServer 7 and earlier allows remote attackers to obtain portions of RealServer's memory contents, possibly including sensitive information, by accessing the /admin/includes/ URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1957" source="BID" patch="1" adv="1">1957</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0236.html" source="BUGTRAQ" patch="1" adv="1">20001116 [CORE SDI ADVISORY] RealServer memory contents disclosure</ref>
      <ref url="http://service.real.com/help/faq/security/memory.html" source="CONFIRM">http://service.real.com/help/faq/security/memory.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5538" source="XF">realserver-gain-access(5538)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realserver">
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1182" published="2001-01-09" name="CVE-2000-1182" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WatchGuard Firebox II allows remote attackers to cause a denial of service by flooding the Firebox with a large number of FTP or SMTP requests, which disables proxy handling.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1953" source="BID" patch="1" adv="1">1953</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0224.html" source="BUGTRAQ" adv="1">20001116 Possible Watchguard Firebox II DoS</ref>
      <ref url="https://www.watchguard.com/support/patches.html" source="CONFIRM">https://www.watchguard.com/support/patches.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5535" source="XF">watchguard-firebox-ftp-dos(5535)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="watchguard" name="firebox_ii">
        <vers num="4.1" />
        <vers num="4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1183" published="2001-01-09" name="CVE-2000-1183" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in socks5 server on Linux allows attackers to execute arbitrary commands via a long connection request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0219.html" source="BUGTRAQ">20001115 socks5 remote exploit / linux x86</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nec" name="socks_5">
        <vers num="1.0r5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1184" published="2001-01-09" name="CVE-2000-1184" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">telnetd in FreeBSD 4.2 and earlier, and possibly other operating systems, allows remote attackers to cause a denial of service by specifying an arbitrary large file in the TERMCAP environmental variable, which consumes resources as the server processes the file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:69.telnetd.v1.1.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-00:69</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5959" source="XF">telnetd-termcap-dos(5959)</ref>
      <ref url="http://www.osvdb.org/6083" source="OSVDB">6083</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.0" />
        <vers num="3.5.1" edition="stable" />
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1185" published="2001-01-09" name="CVE-2000-1185" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The telnet proxy in RideWay PN proxy server allows remote attackers to cause a denial of service via a flood of connections that contain malformed requests.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1938" source="BID" adv="1">1938</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0201.html" source="BUGTRAQ" adv="1">20001113 Rideway PN Telnet DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="itserv_incorporated" name="ridewaypn">
        <vers num="6.22" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1186" published="2001-01-09" name="CVE-2000-1186" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in phf CGI program allows remote attackers to execute arbitrary commands by specifying a large number of arguments and including a long MIME header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0221.html" source="BUGTRAQ" patch="1" adv="1">20001115 Exploit: phf buffer overflow (CGI)</ref>
      <ref url="http://xforce.iss.net/static/5970.php" source="XF">phf-cgi-bo(5970)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phf" name="phf">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1187" published="2001-01-09" name="CVE-2000-1187" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the HTML parser for Netscape 4.75 and earlier allows remote attackers to execute arbitrary commands via a long password value in a form field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-109.html" source="REDHAT" patch="1" adv="1">RHSA-2000:109</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:66.netscape.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-00:66</ref>
      <ref url="http://xforce.iss.net/static/5542.php" source="XF">netscape-client-html-bo</ref>
      <ref url="http://www.osvdb.org/7207" source="OSVDB">7207</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97500270012529&amp;w=2" source="BUGTRAQ">20001121 Immunix OS Security update for netscape</ref>
      <ref url="http://lists.suse.com/archives/suse-security-announce/2000-Nov/0005.html" source="SUSE">SuSE-SA:2000:48</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000344" source="CONECTIVA">CLSA-2000:344</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="communicator">
        <vers prev="1" num="4.75" />
      </prod>
      <prod vendor="netscape" name="navigator">
        <vers prev="1" num="4.75" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1188" published="2001-01-09" name="CVE-2000-1188" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Quikstore shopping cart program allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "page" parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0283.html" source="BUGTRAQ" patch="1" adv="1">20001120 Cgisecurity Quickstore Shopping cart</ref>
    </refs>
    <vuln_soft>
      <prod vendor="i-soft" name="quikstore">
        <vers num="2.0" />
        <vers num="2.9.10" />
        <vers num="2.9.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1189" published="2001-01-09" name="CVE-2000-1189" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in pam_localuser PAM module in Red Hat Linux 7.x and 6.x allows attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-120.html" source="REDHAT" patch="1" adv="1">RHSA-2000:120</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5747" source="XF">pam-localuser-bo(5747)</ref>
      <ref url="http://www.linux-mandrake.com/en/security/MDKSA-2000-082.php3" source="MANDRAKE">MDKSA-2000:082-1</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000358" source="CONECTIVA">CLA-2000:358</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":sparc" />
        <vers num="6.0" edition=":i386" />
        <vers num="6.0" edition=":alpha" />
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":sparc" />
        <vers num="6.1" edition=":i386" />
        <vers num="6.1" edition=":alpha" />
        <vers num="6.2" edition="" />
        <vers num="6.2" edition=":alpha" />
        <vers num="6.2" edition=":sparc" />
        <vers num="6.2" edition=":i386" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":alpha" />
        <vers num="7.0" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-1190" published="2001-08-31" name="CVE-2000-1190" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">imwheel-solo in imwheel package allows local users to modify arbitrary files via a symlink attack from the .imwheelrc file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-016.html" source="REDHAT">RHSA-2000:016</ref>
      <ref url="http://www.iss.net/security_center/static/4941.php" source="XF">linux-imwheel-symlink(4941)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95984116811100&amp;w=2" source="BUGTRAQ">20000531 Re: strike#2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jon_atkins" name="imwheel">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1191" published="2001-08-31" name="CVE-2000-1191" modified="2010-08-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">htsearch program in htDig 3.2 beta, 3.1.6, 3.1.5, and earlier allows remote attackers to determine the physical path of the server by requesting a non-existent configuration file using the config parameter, which generates an error message that includes the full path.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securiteam.com/exploits/htDig_reveals_web_server_configuration_paths.html" source="MISC">http://www.securiteam.com/exploits/htDig_reveals_web_server_configuration_paths.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10526" source="OVAL">oval:org.mitre.oval:def:10526</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/7367" source="XF">htdig-htsearch-path-disclosure(7367)</ref>
      <ref url="http://www.securityfocus.com/bid/4366" source="BID">4366</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1192" published="2001-08-31" name="CVE-2000-1192" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in BTT Software SNMP Trap Watcher 1.16 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string trap.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securiteam.com/windowsntfocus/5ZP0C000KC.html" source="MISC" patch="1" adv="1">http://www.securiteam.com/windowsntfocus/5ZP0C000KC.html</ref>
      <ref url="http://www.securityfocus.com/bid/985" source="BID">985</ref>
      <ref url="http://www.bttsoftware.co.uk/snmptrap.html" source="MISC" adv="1">http://www.bttsoftware.co.uk/snmptrap.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="btt_software" name="snmp_trap_watcher">
        <vers num="1.16" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1193" published="2001-08-31" name="CVE-2000-1193" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Performance Metrics Collector Daemon (PMCD) in Performance Copilot in IRIX 6.x allows remote attackers to cause a denial of service (resource exhaustion) via an extremely long string to the PMCD port.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4284.php" source="XF" patch="1" adv="1">irix-pcp-pmcd-dos(4284)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0056.html" source="BUGTRAQ" patch="1" adv="1">20000412 Performance Copilot for IRIX 6.5</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20020407-01-I" source="SGI">20020407-01-I</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.3" />
        <vers num="6.4" />
        <vers num="6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1194" published="2001-08-31" name="CVE-2000-1194" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Argosoft FRP server 1.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to the (1) USER or (2) CWD commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1227" source="BID" adv="1">1227</ref>
      <ref url="http://www.mdma.za.net/fk/FK9.zip" source="MISC">http://www.mdma.za.net/fk/FK9.zip</ref>
    </refs>
    <vuln_soft>
      <prod vendor="argosoft" name="ftp_server">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1195" published="2001-08-31" name="CVE-2000-1195" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">telnet daemon (telnetd) from the Linux netkit package before netkit-telnet-0.16 allows remote attackers to bypass authentication when telnetd is running with the -L command line option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.caldera.com/support/security/advisories/CSSA-2000-008.0.txt" source="CALDERA" patch="1" adv="1">CSSA-2000-008.0</ref>
      <ref url="http://xforce.iss.net/static/4225.php" source="XF">telnetd-login-bypass(4225)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="caldera" name="openlinux_edesktop">
        <vers num="2.3" />
      </prod>
      <prod vendor="caldera" name="openlinux_eserver">
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1196" published="2001-08-31" name="CVE-2000-1196" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PSCOErrPage.htm in Netscape PublishingXpert 2.5 before SP2 allows remote attackers to read arbitrary files by specifying the target file in the errPagePath parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://docs.iplanet.com/docs/manuals/pubx/2.5.2_Relnotes.html" source="CONFIRM" patch="1" adv="1">http://docs.iplanet.com/docs/manuals/pubx/2.5.2_Relnotes.html</ref>
      <ref url="http://packetstormsecurity.org/0004-exploits/ooo1.txt" source="MISC" adv="1">http://packetstormsecurity.org/0004-exploits/ooo1.txt</ref>
      <ref url="http://xforce.iss.net/static/7362.php" source="XF">publishingxpert-pscoerrpage-url(7362)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="publishingxpert">
        <vers prev="1" num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-1197" published="2001-08-31" name="CVE-2000-1197" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">POP2 or POP3 server (pop3d) in imap-uw IMAP package on FreeBSD and other operating systems creates lock files with predictable names, which allows local users to cause a denial of service (lack of mail access) for other users by creating lock files for other mail boxes.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1132" source="BID">1132</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95624629924545&amp;w=2" source="BUGTRAQ" adv="1">20000420 pop3d/imap DOS (while we're on the subject)</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:15.imap-uw.asc" source="FREEBSD">FreeBSD-SA-00:15</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_washington" name="imap">
        <vers num="4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-1198" published="2001-08-31" name="CVE-2000-1198" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">qpopper POP server creates lock files with predictable names, which allows local users to cause a denial of service for other users (lack of mail access) by creating lock files for other mail boxes.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1132" source="BID">1132</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95634229925906&amp;w=2" source="BUGTRAQ" adv="1">20000420 pop3</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95624629924545&amp;w=2" source="BUGTRAQ" adv="1">20000420 pop3d/imap DOS (while we're on the subject)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qualcomm" name="qpopper">
        <vers num="2.53" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1199" published="2001-08-31" name="CVE-2000-1199" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">PostgreSQL stores usernames and passwords in plaintext in (1) pg_shadow and (2) pg_pwd, which allows attackers with sufficient privileges to gain access to databases.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4364.php" source="XF" adv="1">postgresql-plaintext-passwords(4364)</ref>
      <ref url="http://www.securityfocus.com/bid/1139" source="BID" adv="1">1139</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95659987018649&amp;w=2" source="BUGTRAQ" adv="1">20000423 Postgresql cleartext password storage</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postgresql" name="postgresql">
        <vers num="6.3.2" />
        <vers num="6.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1200" published="2001-08-31" name="CVE-2000-1200" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Windows NT allows remote attackers to list all users in a domain by obtaining the domain SID with the LsaQueryInformationPolicy policy function via a null session and using the SID to list the users.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4015.php" source="XF" patch="1" adv="1">nt-lsa-domain-sid(4015)</ref>
      <ref url="http://www.securityfocus.com/bid/959" source="BID" patch="1" adv="1">959</ref>
      <ref url="http://www.securityfocus.com/archive/1/44430" source="BUGTRAQ" adv="1">20000201 Windows NT and account list leak ! A new SID usage</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1201" published="2001-08-31" name="CVE-2000-1201" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Check Point FireWall-1 allows remote attackers to cause a denial of service (high CPU) via a flood of packets to port 264.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0085.html" source="BUGTRAQ" adv="1">20000707 Re: CheckPoint FW1 BUG</ref>
    </refs>
    <vuln_soft>
      <prod vendor="checkpoint" name="firewall-1">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1202" published="2001-08-31" name="CVE-2000-1202" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">ikeyman in IBM IBMHSSSB 1.0 sets the CLASSPATH environmental variable to include the user's own CLASSPATH directories before the system's directories, which allows a malicious local user to execute arbitrary code as root via a Trojan horse Ikeyman class.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/4235.php" source="XF" patch="1" adv="1">ibm-ikeyman(4235)</ref>
      <ref url="http://www.securityfocus.com/bid/1092" source="BID" patch="1" adv="1">1092</ref>
      <ref url="http://www.securityfocus.com/archive/1/54073" source="BUGTRAQ" adv="1">20000405 minor issue with IBM HTTPD and /usr/bin/ikeyman</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="http_server_ssl_module_common">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1203" published="2001-08-20" name="CVE-2000-1203" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Lotus Domino SMTP server 4.63 through 5.08 allows remote attackers to cause a denial of service (CPU consumption) by forging an email message with the sender as bounce@[127.0.0.1] (localhost), which causes Domino to enter a mail loop.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/3212" source="BID" patch="1" adv="1">3212</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/7012" source="XF" adv="1">lotus-domino-bounced-message-dos(7012)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=95886062521327&amp;w=2" source="VULN-DEV" adv="1">20000520 Infinite loop in LOTUS NOTE 5.0.3. SMTP SERVER</ref>
      <ref url="http://www.securityfocus.com/cgi-bin/archive.pl?id=1&amp;start=2002-01-21&amp;end=2002-01-27&amp;mid=209116&amp;threads=1" source="BUGTRAQ">20010820 Lotus Domino DoS</ref>
      <ref url="http://www.securityfocus.com/archive/1/209754" source="BUGTRAQ">20010823 Lotus Domino DoS solution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lotus" name="domino">
        <vers num="4.6.1" />
        <vers num="4.6.3" />
        <vers num="4.6.4" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.0.6" />
        <vers num="5.0.7" />
        <vers num="5.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1204" published="2000-10-13" name="CVE-2000-1204" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Vulnerability in the mod_vhost_alias virtual hosting module for Apache 1.3.9, 1.3.11 and 1.3.12 allows remote attackers to obtain the source code for CGI programs if the cgi-bin directory is under the document root.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.apacheweek.com/issues/00-10-13" source="CONFIRM" adv="1">http://www.apacheweek.com/issues/00-10-13</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="1.3.11" />
        <vers num="1.3.12" />
        <vers num="1.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1205" published="2000-02-01" name="CVE-2000-1205" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross site scripting vulnerabilities in Apache 1.3.0 through 1.3.11 allow remote attackers to execute script as other web site visitors via (1) the printenv CGI (printenv.pl), which does not encode its output, (2) pages generated by the ap_send_error_response function such as a default 404, which does not add an explicit charset, or (3) various messages that are generated by certain Apache modules or core code.  NOTE: the printenv issue might still exist for web browsers that can render text/plain content types as HTML, such as Internet Explorer, but CVE regards this as a design limitation of those browsers, not Apache.  The printenv.pl/acuparam vector, discloser on 20070724, is one such variant.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://httpd.apache.org/info/css-security/apache_specific.html" source="CONFIRM" patch="1" adv="1">http://httpd.apache.org/info/css-security/apache_specific.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/35597" source="XF">apache-printenv-acuparam-xss(35597)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/10938" source="XF">apache-printenv-xss(10938)</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=118529436424127&amp;w=2" source="BUGTRAQ">20070724 printenv.pl(all versions) cross site scripting Vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2002-12/0233.html" source="BUGTRAQ">20021222 'printenv' XSS vulnerability</ref>
      <ref url="http://archive.cert.uni-stuttgart.de/bugtraq/2002/12/msg00243.html" source="BUGTRAQ">20021223 Re: 'printenv' XSS vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.10" />
        <vers num="1.3.11" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers num="1.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1206" published="1999-08-20" name="CVE-2000-1206" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using mod_rewrite, or mod_vhost_alias in Apache 1.3.9, allows remote attackers to retrieve arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.apacheweek.com/issues/00-01-07#status" source="CONFIRM">http://www.apacheweek.com/issues/00-01-07#status</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="1.3.10" />
        <vers num="1.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1207" published="2000-09-30" name="CVE-2000-1207" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">userhelper in the usermode package on Red Hat Linux executes non-setuid programs as root, which does not activate the security measures in glibc and allows the programs to be exploited via format string vulnerabilities in glibc via the LANG or LC_ALL environment variables (CVE-2000-0844).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-075.html" source="REDHAT" patch="1" adv="1">RHSA-2000:075</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2000/MDKSA-2000-059.php3" source="MANDRAKE" adv="1">MDKSA-2000:059</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97034397026473&amp;w=2" source="BUGTRAQ" adv="1">20000930 glibc and userhelper - local root</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97063854808796&amp;w=2" source="BUGTRAQ">20001003 SuSE: userhelper/usermode</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1208" published="2002-08-12" name="CVE-2000-1208" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in startprinting() function of printjob.c in BSD-based lpr lpd package may allow local users to gain privileges via an improper syslog call that uses format strings from the checkremote() call.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-066.html" source="REDHAT" patch="1" adv="1">RHSA-2000:066</ref>
      <ref url="http://www.iss.net/security_center/static/5286.php" source="XF" patch="1" adv="1">lpr-checkremote-format-string(5286)</ref>
      <ref url="http://www.securityfocus.com/bid/1711" source="BID">1711</ref>
      <ref url="http://online.securityfocus.com/archive/1/137555" source="BUGTRAQ">20001004 Immunix OS Security Update for lpr</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96994604300675&amp;w=2" source="BUGTRAQ">20000925 Format strings: bug #1: BSD-lpr</ref>
    </refs>
    <vuln_soft>
      <prod vendor="immunix" name="immunix">
        <vers num="6.2" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.7" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1209" published="2002-08-12" name="CVE-2000-1209" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that use these products such as (4) Tumbleweed Secure Mail (MMS) (5) Compaq Insight Manager, and (6) Visio 2000, which allows remote attackers to gain privileges, as exploited by worms such as Voyager Alpha Force and Spida.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/635463" source="CERT-VN" patch="1" adv="1">VU#635463</ref>
      <ref url="http://www.iss.net/security_center/static/1459.php" source="XF" patch="1" adv="1">mssql-no-sapassword(1459)</ref>
      <ref url="http://www.microsoft.com/security/security_bulletins/ms02020_sql.asp" source="CONFIRM">http://www.microsoft.com/security/security_bulletins/ms02020_sql.asp</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;EN-US;q321081" source="MSKB">Q321081</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q313418" source="MSKB">Q313418</ref>
      <ref url="http://security-archive.merton.ox.ac.uk/bugtraq-200008/0233.html" source="BUGTRAQ">20000815 MS-SQL 'sa' user exploit code</ref>
      <ref url="http://www.securityfocus.com/bid/4797" source="BID">4797</ref>
      <ref url="http://www.osvdb.org/3570" source="OSVDB">3570</ref>
      <ref url="http://online.securityfocus.com/archive/1/273639" source="BUGTRAQ">20020522 Opty-Way Enterprise includes MSDE with sa &lt;blank></ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96644570412692&amp;w=2" source="BUGTRAQ">20000816 Released Patch: Tumbleweed Worldsecure (MMS) BLANK 'sa' account password</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96593218804850&amp;w=2" source="BUGTRAQ">20000810 Tumbleweed Worldsecure (MMS) BLANK 'sa' account password</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96333895000350&amp;w=2" source="BUGTRAQ">20000710 MSDE / Re: Default Password Database</ref>
    </refs>
    <vuln_soft>
      <prod vendor="compaq" name="insight_manager">
        <vers num="7.0" edition="sp1" />
      </prod>
      <prod vendor="compaq" name="insight_manager_xe">
        <vers num="1.1" />
        <vers num="1.21" />
        <vers num="2.1" />
        <vers num="2.1b" />
        <vers num="2.1c" />
        <vers num="2.2" />
      </prod>
      <prod vendor="microsoft" name="data_engine">
        <vers num="1.0" />
      </prod>
      <prod vendor="microsoft" name="msde">
        <vers num="2000" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1210" published="2002-03-22" name="CVE-2000-1210" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in source.jsp of Apache Tomcat before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the argument to source.jsp.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.iss.net/security_center/static/4205.php" source="XF" patch="1" adv="1">apache-tomcat-file-contents(4205)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95371672300045&amp;w=2" source="BUGTRAQ" adv="1">20000322 Security bug in Apache project: Jakarta Tomcat</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="tomcat">
        <vers prev="1" num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1211" published="2000-12-16" name="CVE-2000-1211" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Zope 2.2.0 through 2.2.4 does not properly perform security registration for legacy names of object constructors such as DTML method objects, which could allow attackers to perform unauthorized activities.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.zope.org/Products/Zope/Hotfix_2000-12-08/security_alert" source="CONFIRM" patch="1" adv="1">http://www.zope.org/Products/Zope/Hotfix_2000-12-08/security_alert</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2000/MDKSA-2000-083.php3" source="MANDRAKE" patch="1" adv="1">MDKSA-2000:083</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-125.html" source="REDHAT">RHSA-2000:125</ref>
      <ref url="http://www.osvdb.org/6282" source="OSVDB">6282</ref>
      <ref url="http://www.iss.net/security_center/static/5824.php" source="XF">zope-legacy-names(5824)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zope" name="zope">
        <vers num="2.2.0" />
        <vers num="2.2.0a1" />
        <vers num="2.2.0b1" />
        <vers num="2.2.0b2" />
        <vers num="2.2.0b3" />
        <vers num="2.2.0b4" />
        <vers num="2.2.1" />
        <vers num="2.2.1b1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1212" published="2000-12-18" name="CVE-2000-1212" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Zope 2.2.0 through 2.2.4 does not properly protect a data updating method on Image and File objects, which allows attackers with DTML editing privileges to modify the raw data of these objects.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.zope.org/Products/Zope/Hotfix_2000-12-18/security_alert" source="CONFIRM" patch="1" adv="1">http://www.zope.org/Products/Zope/Hotfix_2000-12-18/security_alert</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5778" source="XF">zope-image-file(5778)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-135.html" source="REDHAT">RHSA-2000:135</ref>
      <ref url="http://www.osvdb.org/6283" source="OSVDB">6283</ref>
      <ref url="http://www.debian.org/security/2001/dsa-007" source="DEBIAN">DSA-007</ref>
      <ref url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2000:086" source="MANDRAKE">MDKSA-2000:086</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000365" source="CONECTIVA">CLA-2000:365</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zope" name="zope">
        <vers num="2.2.0" />
        <vers num="2.2.0a1" />
        <vers num="2.2.0b1" />
        <vers num="2.2.0b2" />
        <vers num="2.2.0b3" />
        <vers num="2.2.0b4" />
        <vers num="2.2.1" />
        <vers num="2.2.1b1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1213" published="2000-10-18" name="CVE-2000-1213" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">ping in iputils before 20001010, as distributed on Red Hat Linux 6.2 through 7J and other operating systems, does not drop privileges after acquiring a raw socket, which increases ping's exposure to bugs that otherwise would occur at lower privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-087.html" source="REDHAT" adv="1">RHSA-2000:087</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97249980727834&amp;w=2" source="BUGTRAQ">20001025 Immunix OS Security Update for ping package</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0429.html" source="BUGTRAQ">20001030 Trustix Security Advisory - ping gnupg ypbind</ref>
    </refs>
    <vuln_soft>
      <prod vendor="immunix" name="immunix">
        <vers num="6.2" />
      </prod>
      <prod vendor="iputils" name="iputils">
        <vers prev="1" num="2000-10-10" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="6.2" edition="" />
        <vers num="6.2" edition=":alpha" />
        <vers num="6.2" edition=":sparc" />
        <vers num="6.2" edition=":i386" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1214" published="2000-10-18" name="CVE-2000-1214" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflows in the (1) outpack or (2) buf variables of ping in iputils before 20001010, as distributed on Red Hat Linux 6.2 through 7J and other operating systems, may allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-087.html" source="REDHAT" patch="1" adv="1">RHSA-2000:087</ref>
      <ref url="http://www.iss.net/security_center/static/5431.php" source="XF" patch="1" adv="1">ping-buf-bo(5431)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97249980727834&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20001025 Immunix OS Security Update for ping package</ref>
      <ref url="http://www.securityfocus.com/bid/1813" source="BID">1813</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97208562830613&amp;w=2" source="BUGTRAQ">20001020 Re: [RHSA-2000:087-02] Potential security problems in ping fixed.</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0429.html" source="BUGTRAQ">20001030 Trustix Security Advisory - ping gnupg ypbind</ref>
    </refs>
    <vuln_soft>
      <prod vendor="immunix" name="immunix">
        <vers num="6.2" />
      </prod>
      <prod vendor="iputils" name="iputils">
        <vers prev="1" num="2000-10-10" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="6.2" edition="" />
        <vers num="6.2" edition=":alpha" />
        <vers num="6.2" edition=":sparc" />
        <vers num="6.2" edition=":i386" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1215" published="2001-09-19" name="CVE-2000-1215" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The default configuration of Lotus Domino server 5.0.8 includes system information (version, operating system, and build date) in the HTTP headers of replies, which allows remote attackers to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/984555" source="CERT-VN">VU#984555</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/10685" source="XF">lotus-domino-information-disclosure(10685)</ref>
      <ref url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/5552251934afaa9585256c0000737a7f?OpenDocument&amp;Highlight=0,AWHN4A8QWM" source="CONFIRM">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/5552251934afaa9585256c0000737a7f?OpenDocument&amp;Highlight=0,AWHN4A8QWM</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=100094373621813&amp;w=2" source="BUGTRAQ">20010919 lotus domino server 5.08 is very gabby</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino">
        <vers num="5.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1216" published="2000-01-27" name="CVE-2000-1216" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in portmir for AIX 4.3.0 allows local users to corrupt lock files and gain root privileges via the echo_error routine.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/433499" source="CERT-VN" patch="1">VU#433499</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/7929" source="XF">aix-portmir-echoerror-bo(7929)</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY07832" source="AIXAPAR">IY07832</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1217" published="2000-11-21" name="CVE-2000-1217" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Microsoft Windows 2000 before Service Pack 2 (SP2), when running in a non-Windows 2000 domain and using NTLM authentication, and when credentials of an account are locally cached, allows local users to bypass account lockout policies and make an unlimited number of login attempts, aka the "Domain Account Lockout" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/818496" source="CERT-VN">VU#818496</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5585" source="XF">win2k-brute-force(5585)</ref>
      <ref url="http://www.securityfocus.com/bid/1973" source="BID">1973</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS00-089.mspx" source="MS">MS00-089</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp1:server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1218" published="2000-04-14" name="CVE-2000-1218" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query, which allows remote attackers to poison the DNS cache.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/458659" source="CERT-VN">VU#458659</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/4280" source="XF" adv="1">win2k-dns-resolver(4280)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:professional" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":alpha" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:alpha" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp2:alpha" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp3:alpha" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp4:alpha" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp5:alpha" />
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:alpha" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:alpha" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":media_center" />
        <vers num="" edition=":home" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:home" />
        <vers num="" edition="sp2:media_center" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1219" published="2000-11-01" name="CVE-2000-1219" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The -ftrapv compiler option in gcc and g++ 3.3.3 and earlier does not handle all types of integer overflows, which may leave applications vulnerable to vulnerabilities related to overflows.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/540517" source="CERT-VN">VU#540517</ref>
      <ref url="http://gcc.gnu.org/ml/gcc-bugs/2002-05/msg00198.html" source="MLIST">[gcc-bugs] 20020506 c/6586: -ftrapv doesn't catch multiplication overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="g++">
        <vers prev="1" num="3.3.3" />
      </prod>
      <prod vendor="gnu" name="gcc">
        <vers prev="1" num="3.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1220" published="2000-01-08" name="CVE-2000-1220" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local users to gain root privileges by causing sendmail to execute with arbitrary command line arguments, as demonstrated using the -C option to specify a configuration file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/39001" source="CERT-VN">VU#39001</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/3841" source="XF">redhat-lpd-print-control(3841)</ref>
      <ref url="http://www.securityfocus.com/bid/927" source="BID">927</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-002.html" source="REDHAT">RHSA-2000:002</ref>
      <ref url="http://www.debian.org/security/2000/20000109" source="DEBIAN">20000109 lpr -- access control problem and root exploit</ref>
      <ref url="http://www.debian.org/security/2000/20000109" source="DEBIAN">20000109 lpr -- access control problem and root exploit</ref>
      <ref url="http://www.atstake.com/research/advisories/2000/lpd_advisory.txt" source="MISC" adv="1">http://www.atstake.com/research/advisories/2000/lpd_advisory.txt</ref>
      <ref url="http://www.atstake.com/research/advisories/2000/lpd_advisory.txt" source="MISC">http://www.atstake.com/research/advisories/2000/lpd_advisory.txt</ref>
      <ref url="http://seclists.org/lists/bugtraq/2000/Jan/0116.html" source="BUGTRAQ">20000108 L0pht Advisory: LPD, RH 4.x,5.x,6.x</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20021104-01-P" source="SGI">20021104-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" edition="" />
        <vers num="5.2" edition=":i386" />
        <vers num="6.0" />
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":i386" />
      </prod>
      <prod vendor="sgi" name="irix">
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.10" />
        <vers num="6.5.11" />
        <vers num="6.5.12" />
        <vers num="6.5.13" />
        <vers num="6.5.14f" />
        <vers num="6.5.14m" />
        <vers num="6.5.15f" />
        <vers num="6.5.15m" />
        <vers num="6.5.16f" />
        <vers num="6.5.16m" />
        <vers num="6.5.17f" />
        <vers num="6.5.17m" />
        <vers num="6.5.18f" />
        <vers num="6.5.18m" />
        <vers num="6.5.2" />
        <vers num="6.5.3" />
        <vers num="6.5.4" />
        <vers num="6.5.5" />
        <vers num="6.5.6" />
        <vers num="6.5.7" />
        <vers num="6.5.8" />
        <vers num="6.5.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1221" published="2000-01-08" name="CVE-2000-1221" modified="2009-02-28" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The line printer daemon (lpd) in the lpr package in multiple Linux operating systems authenticates by comparing the reverse-resolved hostname of the local machine to the hostname of the print server as returned by gethostname, which allows remote attackers to bypass intended access controls by modifying the DNS for the attacking IP.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/30308" source="CERT-VN">VU#30308</ref>
      <ref url="http://www.debian.org/security/2000/20000109" source="DEBIAN" patch="1">20000109 lpr -- access control problem and root exploit</ref>
      <ref url="http://www.atstake.com/research/advisories/2000/lpd_advisory.txt" source="L0PHT" patch="1">20000108 Quadruple Inverted Backflip</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20021104-01-P" source="SGI" patch="1">20021104-01-P</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/3840" source="XF">redhat-lpd-auth(3840)</ref>
      <ref url="http://www.securityfocus.com/bid/0927" source="BID">927</ref>
      <ref url="http://www.atstake.com/research/advisories/2000/lpd_advisory.txt" source="L0PHT">20000108 Quadruple Inverted Backflip</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2000-002.html" source="REDHAT">RHSA-2000:002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.1" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.2" edition="" />
        <vers num="5.2" edition=":i386" />
        <vers num="6.0" />
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":i386" />
      </prod>
      <prod vendor="sgi" name="irix">
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.10" />
        <vers num="6.5.11" />
        <vers num="6.5.12" />
        <vers num="6.5.13" />
        <vers num="6.5.14f" />
        <vers num="6.5.14m" />
        <vers num="6.5.15f" />
        <vers num="6.5.15m" />
        <vers num="6.5.16f" />
        <vers num="6.5.16m" />
        <vers num="6.5.17f" />
        <vers num="6.5.17m" />
        <vers num="6.5.18f" />
        <vers num="6.5.18m" />
        <vers num="6.5.2" />
        <vers num="6.5.3" />
        <vers num="6.5.4" />
        <vers num="6.5.5" />
        <vers num="6.5.6" />
        <vers num="6.5.7" />
        <vers num="6.5.8" />
        <vers num="6.5.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1222" published="2000-12-10" name="CVE-2000-1222" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">AIX sysback before 4.2.1.13 uses a relative path to find and execute the hostname program, which allows local users to gain privileges by modifying the path to point to a malicious hostname program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/17566" source="CERT-VN" adv="1">VU#17566</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6432" source="XF" adv="1">aix-sysback-elevate-privileges(6432)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers prev="1" num="4.2.1.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1223" published="2000-11-20" name="CVE-2000-1223" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">quikstore.cgi in Quikstore Shopping Cart allows remote attackers to execute arbitrary commands via shell metacharacters in the URL portion of an HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/671444" source="CERT-VN" adv="1">VU#671444</ref>
    </refs>
    <vuln_soft>
      <prod vendor="i-soft" name="quikstore">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1224" published="2000-11-23" name="CVE-2000-1224" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Caucho Technology Resin 1.2 and possibly earlier allows remote attackers to view JSP source via an HTTP request to a .jsp file with certain characters appended to the file name, such as (1) "..", (2) "%2e..", (3) "%81", (4) "%82", and others.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/5568" source="XF" adv="1">resin-jsp-source-disclosure(5568)</ref>
      <ref url="http://www.securityfocus.com/bid/1986" source="BID" adv="1">1986</ref>
      <ref url="http://www.securityfocus.com/archive/1/146770" source="BUGTRAQ">20001123 Re: RESIN ServletExec JSP Source Disclosure Vulnerability(Apache 1.3.6 Win2k))</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97502269408279&amp;w=2" source="BUGTRAQ" adv="1">20001123 RESIN ServletExec JSP Source Disclosure Vulnerability(Apache 1.3.6 Win2k))</ref>
    </refs>
    <vuln_soft>
      <prod vendor="caucho_technology" name="resin">
        <vers num="1.1.5" />
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1225" published="2000-12-31" name="CVE-2000-1225" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Xitami 2.5b installs the testcgi.exe program by default in the cgi-bin directory, which allows remote attackers to gain sensitive configuration information about the web server by accessing the program.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q4/0109.html" source="MISC">http://archives.neohapsis.com/archives/win2ksecadvice/2000-q4/0109.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="imatix" name="xitami">
        <vers num="2.5_b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1226" published="2000-12-31" name="CVE-2000-1226" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Snort 1.6, when running in straight ASCII packet logging mode or IDS mode with straight decoded ASCII packet logging selected, allows remote attackers to cause a denial of service (crash) by sending non-IP protocols that Snort does not know about, as demonstrated by an nmap protocol scan.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0126.html" source="BUGTRAQ" patch="1" adv="1">20000614 Re: Snort 1.6 and nmap 2.54beta1</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0122.html" source="BUGTRAQ" adv="1">20000614 Snort 1.6 and nmap 2.54beta1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snort" name="snort">
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1227" published="2000-12-31" name="CVE-2000-1227" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Windows NT 4.0 and Windows 2000 hosts allow remote attackers to cause a denial of service (unavailable connections) by sending multiple SMB SMBnegprots requests but not reading the response that is sent back.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/1301" source="BID">1301</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":professional" />
        <vers num="" edition=":server" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:server" />
        <vers num="4.0" edition="sp1:enterprise_server" />
        <vers num="4.0" edition="sp1:workstation" />
        <vers num="4.0" edition="sp1:terminal_server" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp2:workstation" />
        <vers num="4.0" edition="sp2:enterprise_server" />
        <vers num="4.0" edition="sp2:server" />
        <vers num="4.0" edition="sp2:terminal_server" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp3:workstation" />
        <vers num="4.0" edition="sp3:enterprise_server" />
        <vers num="4.0" edition="sp3:server" />
        <vers num="4.0" edition="sp3:terminal_server" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp4:workstation" />
        <vers num="4.0" edition="sp4:enterprise_server" />
        <vers num="4.0" edition="sp4:terminal_server" />
        <vers num="4.0" edition="sp4:server" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp5:workstation" />
        <vers num="4.0" edition="sp5:enterprise_server" />
        <vers num="4.0" edition="sp5:server" />
        <vers num="4.0" edition="sp5:terminal_server" />
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:enterprise_server" />
        <vers num="4.0" edition="sp6:terminal_server" />
        <vers num="4.0" edition="sp6:server" />
        <vers num="4.0" edition="sp6:workstation" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:enterprise_server" />
        <vers num="4.0" edition="sp6a:workstation" />
        <vers num="4.0" edition="sp6a:server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1228" published="2000-12-31" name="CVE-2000-1228" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Phorum 3.0.7 allows remote attackers to change the administrator password without authentication via an HTTP request for admin.php3 that sets step, option, confirm and newPssword variables.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2271" source="BID" patch="1">2271</ref>
      <ref url="http://cert.uni-stuttgart.de/archive/bugtraq/2000/01/msg00215.html" source="BUGTRAQ" patch="1" adv="1">20000106 Phorum 3.0.7 exploits and IDS signatures</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phorum" name="phorum">
        <vers num="3.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1229" published="2000-12-31" name="CVE-2000-1229" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Phorum 3.0.7 allows remote Phorum administrators to read arbitrary files via ".." (dot dot) sequences in the default .langfile name field in the Master Settings administrative function, which causes the file to be displayed in admin.php3.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://cert.uni-stuttgart.de/archive/bugtraq/2000/01/msg00215.html" source="BUGTRAQ" patch="1" adv="1">20000106 Phorum 3.0.7 exploits and IDS signatures</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phorum" name="phorum">
        <vers num="3.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1230" published="2000-12-31" name="CVE-2000-1230" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Backdoor in auth.php3 in Phorum 3.0.7 allows remote attackers to access restricted web pages via an HTTP request with the PHP_AUTH_USER parameter set to "boogieman".</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.digitalsec.net/stuff/z-mirrors/hispahack/mi020.htm" source="MISC" patch="1">http://www.digitalsec.net/stuff/z-mirrors/hispahack/mi020.htm</ref>
      <ref url="http://cert.uni-stuttgart.de/archive/bugtraq/2000/01/msg00215.html" source="BUGTRAQ" patch="1" adv="1">20000106 Phorum 3.0.7 exploits and IDS signatures</ref>
      <ref url="http://www.securityfocus.com/bid/2274" source="BID">2274</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phorum" name="phorum">
        <vers num="3.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1231" published="2000-12-31" name="CVE-2000-1231" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">code.php3 in Phorum 3.0.7 allows remote attackers to read arbitrary files in the phorum directory via the query string.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://cert.uni-stuttgart.de/archive/bugtraq/2000/01/msg00215.html" source="BUGTRAQ" patch="1" adv="1">20000106 Phorum 3.0.7 exploits and IDS signatures</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phorum" name="phorum">
        <vers num="3.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1232" published="2000-12-31" name="CVE-2000-1232" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">upgrade.php3 in Phorum 3.0.7 could allow remote attackers to modify certain Phorum database tables via an unknown method.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://cert.uni-stuttgart.de/archive/bugtraq/2000/01/msg00215.html" source="BUGTRAQ" patch="1" adv="1">20000106 Phorum 3.0.7 exploits and IDS signatures</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phorum" name="phorum">
        <vers num="3.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1233" published="2000-12-31" name="CVE-2000-1233" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in read.php3 and other scripts in Phorum 3.0.7 allows remote attackers to execute arbitrary SQL queries via the sSQL parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://cert.uni-stuttgart.de/archive/bugtraq/2000/01/msg00215.html" source="BUGTRAQ" patch="1" adv="1">20000106 Phorum 3.0.7 exploits and IDS signatures</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phorum" name="phorum">
        <vers num="3.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1234" published="2000-12-31" name="CVE-2000-1234" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">violation.php3 in Phorum 3.0.7 allows remote attackers to send e-mails to arbitrary addresses and possibly use Phorum as a "spam proxy" by setting the Mod and ForumName parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2272" source="BID" patch="1">2272</ref>
      <ref url="http://cert.uni-stuttgart.de/archive/bugtraq/2000/01/msg00215.html" source="BUGTRAQ" adv="1">20000106 Phorum 3.0.7 exploits and IDS signatures</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phorum" name="phorum">
        <vers num="3.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1235" published="2000-12-31" name="CVE-2000-1235" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The default configurations of (1) the port listener and (2) modplsql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allow remote attackers to view privileged database information via HTTP requests for Database Access Descriptor (DAD) files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2150" source="BID" patch="1">2150</ref>
      <ref url="http://www.iss.net/security_center/static/5818.php" source="XF" patch="1">oracle-webdb-admin-access(5818)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0463.html" source="BUGTRAQ" adv="1">20001223 Potential Vulnerabilities in Oracle Internet Application Server</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0372.html" source="BUGTRAQ">20001221 Re: Oracle WebDb engine brain-damagse</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0339.html" source="BUGTRAQ" adv="1">20001219 Oracle WebDb engine brain-damagse</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers prev="1" num="3.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1236" published="2000-12-31" name="CVE-2000-1236" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in mod_sql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the query string of the URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2150" source="BID" patch="1">2150</ref>
      <ref url="http://www.iss.net/security_center/static/5817.php" source="XF" patch="1">oracle-execute-plsql(5817)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0463.html" source="BUGTRAQ">20001223 Potential Vulnerabilities in Oracle Internet Application Server</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0372.html" source="BUGTRAQ">20001221 Re: Oracle WebDb engine brain-damagse</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0339.html" source="BUGTRAQ">20001219 Oracle WebDb engine brain-damagse</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers prev="1" num="3.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1237" published="2000-12-31" name="CVE-2000-1237" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The POP3 server in FTGate returns an -ERR code after receiving an invalid USER request, which makes it easier for remote attackers to determine valid usernames and conduct brute force password guessing.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.iss.net/security_center/static/4793.php" source="XF">ftgate-invalid-user-requests(4793)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0282.html" source="BUGTRAQ" adv="1">20000626 Problems with FTGate</ref>
    </refs>
    <vuln_soft>
      <prod vendor="floosietek" name="ftgate">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1238" published="2000-12-31" name="CVE-2000-1238" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to bypass access controls for restricted JSP or servlet pages via a URL with multiple / (forward slash) characters before the restricted pages.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product releases:
BEA Systems Weblogic Server 5.1 SP 7
BEA Systems WebLogic Express 5.1 SP 7</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/5588" source="XF" patch="1">weblogic-bypass-auth(5588)</ref>
      <ref url="http://www.securityfocus.com/bid/5089" source="BID" patch="1">5089</ref>
      <ref url="ftp://ftpna.bea.com/pub/releases/patches/SecurityBEA00-0600.zip" source="CONFIRM" patch="1">ftp://ftpna.bea.com/pub/releases/patches/SecurityBEA00-0600.zip</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="5.1" edition="" />
        <vers num="5.1" edition=":express" />
        <vers num="5.1" edition="sp1" />
        <vers num="5.1" edition="sp1:express" />
        <vers num="5.1" edition="sp2" />
        <vers num="5.1" edition="sp2:express" />
        <vers num="5.1" edition="sp3" />
        <vers num="5.1" edition="sp3:express" />
        <vers num="5.1" edition="sp4" />
        <vers num="5.1" edition="sp4:express" />
        <vers num="5.1" edition="sp5" />
        <vers num="5.1" edition="sp5:express" />
        <vers num="5.1" edition="sp6" />
        <vers num="5.1" edition="sp6:express" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1239" published="2000-12-31" name="CVE-2000-1239" modified="2008-09-05" discovered="2000-03-13" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">The HTTP interface of Tivoli Lightweight Client Framework (LCF) in IBM Tivoli Management Framework 3.7.1 sets http_disable to zero at install time, which allows remote authenticated users to bypass file permissions on Tivoli Endpoint Configuration data files via an unspecified manipulation of log files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/3927" source="XF">tivoli-lcf-file-read(3927)</ref>
      <ref url="http://www.securityfocus.com/bid/17085" source="BID">17085</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="tivoli_management_framework">
        <vers num="3.7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1240" published="2000-12-31" name="CVE-2000-1240" modified="2008-09-05" discovered="2000-04-22" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in siteman.php3 in AnyPortal(php) before 22 APR 00 allows remote attackers to obtain sensitive information via unknown attack vectors, which reveal the absolute path.  NOTE: the provenance of this information is unknown; the details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/25441" source="XF" patch="1">anyportalphp-siteman-information-disclosure(25441)</ref>
      <ref url="http://www.osvdb.org/23983" source="OSVDB" patch="1">23983</ref>
    </refs>
    <vuln_soft>
      <prod vendor="anyportal_php" name="anyportal_php">
        <vers prev="1" num="2000-04-18" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1241" published="2000-12-31" name="CVE-2000-1241" modified="2009-10-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Haakon Nilsen simple, integrated publishing system (SIPS) before 0.2.4 has an unknown impact and attack vectors, related to a "grave security fault."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/forum/forum.php?forum_id=25971" source="CONFIRM">http://sourceforge.net/forum/forum.php?forum_id=25971</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sips" name="sips">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1242" published="2000-12-31" name="CVE-2000-1242" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">The HTTP service in American Power Conversion (APC) PowerChute uses a default username and password, which allows remote attackers to gain system access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/30768" source="OSVDB" adv="1">30768</ref>
      <ref url="http://governmentsecurity.org/articles/DefaultLoginsandPasswordsforNetworkedDevices.php" source="MISC">http://governmentsecurity.org/articles/DefaultLoginsandPasswordsforNetworkedDevices.php</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apc" name="powerchute">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2000-1243" published="2000-12-31" name="CVE-2000-1243" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Privacy leak in Dansie Shopping Cart 3.04, and probably earlier versions, sends sensitive information such as user credentials to an e-mail address controlled by the product developers.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/470457/100/0/threaded" source="BUGTRAQ">20070603 Dansie Cart Script Exploit Reported</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0086.html" source="BUGTRAQ">20000413 Re: Back Door in Commercial Shopping Cart [RESOLVED]</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0071.html" source="BUGTRAQ">20000413 Re: Back Door in Commercial Shopping Cart</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0066.html" source="BUGTRAQ">20000413 Re: Back Door in Commercial Shopping Cart [Stormer Hosting]</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0051.html" source="BUGTRAQ">20000411 Back Door in Commercial Shopping Cart</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dansie" name="shopping_cart">
        <vers num="3.04" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1244" published="2000-12-31" name="CVE-2000-1244" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Computer Associates InoculateIT Agent for Exchange Server does not recognize an e-mail virus attachment if the SMTP header is missing the "From" field, which allows remote attackers to bypass virus protection.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0158.html" source="BUGTRAQ">20001110 CA's InoculateIT Agent for Exchange Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="inoculateit_agent_for_exchange">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2000-1245" published="2010-04-05" name="CVE-2000-1245" modified="2010-04-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in NWFTPD.nlm before 5.01o in the FTP server in Novell NetWare 5.1 SP3 allow remote attackers to bypass intended restrictions on anonymous access via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.novell.com/support/viewContent.do?externalId=3238588&amp;sliceId=1" source="CONFIRM" adv="1">http://www.novell.com/support/viewContent.do?externalId=3238588&amp;sliceId=1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="netware_ftp_server">
        <vers prev="1" num="5.01i" />
      </prod>
      <prod vendor="novell" name="netware">
        <vers num="5.1" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-1246" published="2010-04-05" name="CVE-2000-1246" modified="2010-04-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:N/A:P)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">NWFTPD.nlm before 5.01o in the FTP server in Novell NetWare 5.1 SP3 allows remote authenticated users to cause a denial of service (abend) by sending an RNTO command after a failed RNFR command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.novell.com/support/viewContent.do?externalId=3238588&amp;sliceId=1" source="CONFIRM" adv="1">http://www.novell.com/support/viewContent.do?externalId=3238588&amp;sliceId=1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="netware_ftp_server">
        <vers prev="1" num="5.01i" />
      </prod>
      <prod vendor="novell" name="netware">
        <vers num="5.1" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2000-1247" published="2011-10-04" name="CVE-2000-1247" modified="2011-10-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The default configuration of the jserv-status handler in jserv.conf in Apache JServ 1.1.2 includes an "allow from 127.0.0.1" line, which allows local users to discover JDBC passwords or other sensitive information via a direct request to the jserv/ URI.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archive.apache.org/dist/java/java.apache.org-www.tar.gz" source="CONFIRM" patch="1">http://archive.apache.org/dist/java/java.apache.org-www.tar.gz</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/51946" source="XF">apache-jserv-env-information-disclosure(51946)</ref>
      <ref url="http://marc.info/?l=java-apache-users&amp;m=97036799917909&amp;w=2" source="MLIST">[java-apache-users] 20000929 jserv wrapper error</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="jserv">
        <vers num="1.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0001" published="2001-06-02" name="CVE-2001-0001" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">cookiedecode function in PHP-Nuke 4.4 allows users to bypass authentication and gain access to other user accounts by extracting the authentication information from a cookie.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0257.html" source="BUGTRAQ" patch="1" adv="1">20010213 RFP2101: RFPlutonium to fuel your PHP-Nuke</ref>
      <ref url="http://xforce.iss.net/static/6183.php" source="XF">php-nuke-elevate-privileges(6183)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="4.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0002" published="2001-07-21" name="CVE-2001-0002" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Internet Explorer 5.5 and earlier allows remote attackers to obtain the physical location of cached content and open the content in the Local Computer Zone, then use compiled HTML help (.chm) files to execute arbitrary programs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/5567" source="XF">ie-chm-execute-files(5567)</ref>
      <ref url="http://www.securityfocus.com/bid/2456" source="BID">2456</ref>
      <ref url="http://www.osvdb.org/7823" source="OSVDB">7823</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-015.asp" source="MS">MS01-015</ref>
      <ref url="http://www.guninski.com/chmtempmain.html" source="MISC">http://www.guninski.com/chmtempmain.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:920" source="OVAL" sig="1">oval:org.mitre.oval:def:920</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" />
        <vers prev="1" num="5.5" />
      </prod>
      <prod vendor="microsoft" name="windows_script_host">
        <vers num="5.1" />
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0003" published="2001-02-12" name="CVE-2001-0003" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly process Internet Explorer security settings for NTLM authentication, which allows attackers to obtain NTLM credentials and possibly obtain the password, aka the "Web Client NTLM Authentication" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2199" source="BID" patch="1" adv="1">2199</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-001.asp" source="MS" patch="1" adv="1">MS01-001</ref>
      <ref url="http://xforce.iss.net/static/5920.php" source="XF">wec-ntlm-authentication</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2000" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0004" published="2001-02-12" name="CVE-2001-0004" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IIS 5.0 and 4.0 allows remote attackers to read the source code for executable web server programs by appending "%3F+.htr" to the requested URL, which causes the files to be parsed by the .HTR ISAPI extension, aka a variant of the "File Fragment Reading via .HTR" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-004.asp" source="MS" patch="1" adv="1">MS01-004</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97897954625305&amp;w=2" source="BUGTRAQ" adv="1">20010108 IIS 5.0 allows viewing files using %3F+.htr</ref>
      <ref url="http://xforce.iss.net/static/5903.php" source="XF">iis-read-files(5903)</ref>
      <ref url="http://www.securityfocus.com/bid/2313" source="BID">2313</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0005" published="2001-02-12" name="CVE-2001-0005" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">Buffer overflow in the parsing mechanism of the file loader in Microsoft PowerPoint 2000 allows attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-002.asp" source="MS" patch="1" adv="1">MS01-002</ref>
      <ref url="http://www.atstake.com/research/advisories/2001/a012301-1.txt" source="ATSTAKE" adv="1">A012301-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5996" source="XF">powerpoint-execute-code(5996)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="powerpoint">
        <vers num="2000" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0006" published="2001-02-12" name="CVE-2001-0006" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allows local users to modify the permissions to "No Access" and disable Winsock network connectivity to cause a denial of service, aka the "Winsock Mutex" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-003.asp" source="MS">MS01-003</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98075221915234&amp;w=2" source="BUGTRAQ" adv="1">20010126 ntsecurity.nu advisory: Winsock Mutex Vulnerability in Windows NT 4.0 SP6 and below</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6006" source="XF">winnt-mutex-dos(6006)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0007" published="2001-02-12" name="CVE-2001-0007" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in NetScreen Firewall WebUI allows remote attackers to cause a denial of service via a long URL request to the web administration interface.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2176" source="BID" patch="1" adv="1">2176</ref>
      <ref url="http://www.securityfocus.com/archive/1/155149" source="BUGTRAQ" adv="1">20010109 NSFOCUS SA2001-01: NetScreen Firewall WebUI Buffer Overflow vulnerability</ref>
      <ref url="http://xforce.iss.net/static/5908.php" source="XF">netscreen-webui-bo(5908)</ref>
      <ref url="http://www.osvdb.org/1707" source="OSVDB">1707</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscreen" name="screen_os">
        <vers num="1.73r" />
        <vers num="2.10r3" />
        <vers num="2.1r6" />
        <vers num="2.5r1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0008" published="2001-02-12" name="CVE-2001-0008" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Backdoor account in Interbase database server allows remote attackers to overwrite arbitrary files using stored procedures.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2001-01.html" source="CERT" patch="1" adv="1">CA-2001-01</ref>
      <ref url="http://www.securityfocus.com/bid/2192" source="BID" patch="1" adv="1">2192</ref>
      <ref url="http://xforce.iss.net/static/5911.php" source="XF">interbase-backdoor-account(5911)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="borland_software" name="interbase">
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="6.0" />
      </prod>
      <prod vendor="firebirdsql" name="firebird">
        <vers prev="1" num="0.9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0009" published="2001-02-12" name="CVE-2001-0009" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Lotus Domino 5.0.5 web server allows remote attackers to read arbitrary files via a .. attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2173" source="BID" patch="1" adv="1">2173</ref>
      <ref url="http://www.securityfocus.com/archive/1/155124" source="BUGTRAQ" patch="1">20010109 bugtraq id 2173 Lotus Domino Server</ref>
      <ref url="http://www.securityfocus.com/archive/1/154537" source="BUGTRAQ" adv="1">20010105 Lotus Domino 5.0.5 Web Server vulnerability - reading files outside the web root</ref>
      <ref url="http://xforce.iss.net/static/5899.php" source="XF">lotus-domino-directory-traversal(5899)</ref>
      <ref url="http://www.osvdb.org/1703" source="OSVDB">1703</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lotus" name="domino_server">
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.5" />
        <vers num="5.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0010" published="2001-02-12" name="CVE-2001-0010" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2001-02.html" source="CERT" patch="1" adv="1">CA-2001-02</ref>
      <ref url="http://www.securityfocus.com/bid/2302" source="BID" patch="1" adv="1">2302</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-007.html" source="REDHAT">RHSA-2001:007</ref>
      <ref url="http://www.nai.com/research/covert/advisories/047.asp" source="NAI">20010129 Vulnerabilities in BIND 4 and 8</ref>
      <ref url="http://www.debian.org/security/2001/dsa-026" source="DEBIAN">DSA-026</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="bind">
        <vers num="8.2" />
        <vers num="8.2.1" />
        <vers num="8.2.2" edition="p1" />
        <vers num="8.2.2" edition="p2" />
        <vers num="8.2.2" edition="p3" />
        <vers num="8.2.2" edition="p4" />
        <vers num="8.2.2" edition="p5" />
        <vers num="8.2.2" edition="p6" />
        <vers num="8.2.2" edition="p7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0011" published="2001-02-12" name="CVE-2001-0011" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in nslookupComplain function in BIND 4 allows remote attackers to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2001-02.html" source="CERT" patch="1" adv="1">CA-2001-02</ref>
      <ref url="http://www.securityfocus.com/bid/2307" source="BID">2307</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-007.html" source="REDHAT">RHSA-2001:007</ref>
      <ref url="http://www.nai.com/research/covert/advisories/047.asp" source="NAI">20010129 Vulnerabilities in BIND 4 and 8</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="bind">
        <vers num="4.9.3" />
        <vers num="4.9.5" edition="p1" />
        <vers num="4.9.6" />
        <vers num="4.9.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0012" published="2001-02-12" name="CVE-2001-0012" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BIND 4 and BIND 8 allow remote attackers to access sensitive information such as environment variables.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2001-02.html" source="CERT" patch="1" adv="1">CA-2001-02</ref>
      <ref url="http://www.securityfocus.com/bid/2321" source="BID">2321</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-007.html" source="REDHAT">RHSA-2001:007</ref>
      <ref url="http://www.nai.com/research/covert/advisories/047.asp" source="NAI">20010129 Vulnerabilities in BIND 4 and 8</ref>
      <ref url="http://www.debian.org/security/2001/dsa-026" source="DEBIAN">DSA-026</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="bind">
        <vers num="4.9.3" />
        <vers num="4.9.5" edition="p1" />
        <vers num="4.9.6" />
        <vers num="4.9.7" />
        <vers num="8.2" />
        <vers num="8.2.1" />
        <vers num="8.2.2" edition="p1" />
        <vers num="8.2.2" edition="p2" />
        <vers num="8.2.2" edition="p3" />
        <vers num="8.2.2" edition="p4" />
        <vers num="8.2.2" edition="p5" />
        <vers num="8.2.2" edition="p6" />
        <vers num="8.2.2" edition="p7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0013" published="2001-02-12" name="CVE-2001-0013" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in nslookupComplain function in BIND 4 allows remote attackers to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2001-02.html" source="CERT" patch="1" adv="1">CA-2001-02</ref>
      <ref url="http://www.securityfocus.com/bid/2309" source="BID">2309</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-007.html" source="REDHAT">RHSA-2001:007</ref>
      <ref url="http://www.nai.com/research/covert/advisories/047.asp" source="NAI">20010129 Vulnerabilities in BIND 4 and 8</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="bind">
        <vers num="4.9.3" />
        <vers num="4.9.5" edition="p1" />
        <vers num="4.9.6" />
        <vers num="4.9.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0014" published="2001-02-12" name="CVE-2001-0014" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Remote Data Protocol (RDP) in Windows 2000 Terminal Service does not properly handle certain malformed packets, which allows remote attackers to cause a denial of service, aka the "Invalid RDP Data" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2326" source="BID" patch="1" adv="1">2326</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-006.asp" source="MS" patch="1" adv="1">MS01-006</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0015" published="2001-03-12" name="CVE-2001-0015" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Network Dynamic Data Exchange (DDE) in Windows 2000 allows local users to gain SYSTEM privileges via a "WM_COPYDATA" message to an invisible window that is running with the privileges of the WINLOGON process.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-007.asp" source="MS" patch="1">MS01-007</ref>
      <ref url="http://www.atstake.com/research/advisories/2001/a020501-1.txt" source="ATSTAKE" patch="1" adv="1">A020501-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6062" source="XF">win-dde-elevate-privileges(6062)</ref>
      <ref url="http://www.securityfocus.com/bid/2341" source="BID">2341</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0016" published="2001-03-12" name="CVE-2001-0016" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">NTLM Security Support Provider (NTLMSSP) service does not properly check the function number in an LPC request, which could allow local users to gain administrator level access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms01-008.asp" source="MS" patch="1" adv="1">MS01-008</ref>
      <ref url="http://razor.bindview.com/publish/advisories/adv_NTLMSSP.html" source="BINDVIEW">20010207 Local promotion vulnerability in NT4's NTLM Security Support Provider</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6076" source="XF">ntlm-ssp-elevate-privileges(6076)</ref>
      <ref url="http://www.securityfocus.com/bid/2348" source="BID">2348</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers prev="1" num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0017" published="2001-03-12" name="CVE-2001-0017" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Memory leak in PPTP server in Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed data packet, aka the "Malformed PPTP Packet Stream" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-009.asp" source="MS" patch="1" adv="1">MS01-009</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6103" source="XF">winnt-pptp-dos(6103)</ref>
      <ref url="http://www.securityfocus.com/bid/2368" source="BID">2368</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers prev="1" num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0018" published="2001-07-21" name="CVE-2001-0018" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Windows 2000 domain controller in Windows 2000 Server, Advanced Server, or Datacenter Server allows remote attackers to cause a denial of service via a flood of malformed service requests.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms01-011.asp" source="MS" patch="1" adv="1">MS01-011</ref>
      <ref url="http://xforce.iss.net/static/6136.php" source="XF">win2k-domain-controller-dos(6136)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/l-049.shtml" source="CIAC">L-049</ref>
      <ref url="http://online.securityfocus.com/archive/82/148411" source="VULN-DEV">20001202 UDP Ping-pong in Win2k</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":advanced_server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0019" published="2001-02-12" name="CVE-2001-0019" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Arrowpoint (aka Cisco Content Services, or CSS) allows local users to cause a denial of service via a long argument to the "show script," "clear script," "show archive," "clear archive," "show log," or "clear log" commands.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/arrowpoint-cli-filesystem-pub.shtml" source="CISCO" adv="1">20010131 Cisco Content Services Switch Vulnerability</ref>
      <ref url="http://www.atstake.com/research/advisories/2001/a013101-1.txt" source="ATSTAKE" adv="1">A013101-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="arrowpoint">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="content_services_switch">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0020" published="2001-02-12" name="CVE-2001-0020" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Arrowpoint (aka Cisco Content Services, or CSS) allows local unprivileged users to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/arrowpoint-cli-filesystem-pub.shtml" source="CISCO" adv="1">20010131 Cisco Content Services Switch Vulnerability</ref>
      <ref url="http://www.atstake.com/research/advisories/2001/a013101-1.txt" source="ATSTAKE" adv="1">A013101-1</ref>
      <ref url="http://xforce.iss.net/static/6031.php" source="XF">cisco-ccs-file-access(6031)</ref>
      <ref url="http://www.securityfocus.com/bid/2331" source="BID">2331</ref>
      <ref url="http://www.osvdb.org/1757" source="OSVDB">1757</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="arrowpoint">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="content_services_switch">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0021" published="2001-02-16" name="CVE-2001-0021" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">MailMan Webmail 3.0.25 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the alternate_template parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2063" source="BID" patch="1" adv="1">2063</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0057.html" source="BUGTRAQ" patch="1" adv="1">20001206 (SRADV00005) Remote command execution vulnerabilities in MailMan Webmail</ref>
      <ref url="http://xforce.iss.net/static/5649.php" source="XF" adv="1">mailman-alternate-templates</ref>
      <ref url="http://www.endymion.com/products/mailman/history.htm" source="CONFIRM">http://www.endymion.com/products/mailman/history.htm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="endymion" name="mailman_webmail">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.15" />
        <vers num="3.0.16" />
        <vers num="3.0.18" />
        <vers num="3.0.19" />
        <vers num="3.0.20" />
        <vers num="3.0.21" />
        <vers num="3.0.22" />
        <vers num="3.0.23" />
        <vers num="3.0.24" />
        <vers num="3.0.25" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0022" published="2001-02-12" name="CVE-2001-0022" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">simplestguest.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the guestbook parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5743.php" source="XF" adv="1">http-cgi-simplestguest</ref>
      <ref url="http://www.securityfocus.com/bid/2106" source="BID" adv="1">2106</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0168.html" source="BUGTRAQ" adv="1">20001213 Re: Insecure input validation in simplestmail.cgi</ref>
    </refs>
    <vuln_soft>
      <prod vendor="leif_m._wright" name="simplestguest.cgi">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0023" published="2001-02-12" name="CVE-2001-0023" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">everythingform.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the config parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5736.php" source="XF" adv="1">http-cgi-everythingform</ref>
      <ref url="http://www.securityfocus.com/bid/2101" source="BID" adv="1">2101</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0137.html" source="BUGTRAQ">20001211 Insecure input validation in everythingform.cgi (remote command execution)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="leif_m._wright" name="everythingform.cgi">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0024" published="2001-02-12" name="CVE-2001-0024" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">simplestmail.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the MyEmail parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5739.php" source="XF" adv="1">http-cgi-simplestmail</ref>
      <ref url="http://www.securityfocus.com/bid/2102" source="BID" adv="1">2102</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0136.html" source="BUGTRAQ">20001211 Insecure input validation in simplestmail.cgi (remote command execution)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="leif_m._wright" name="simplestmail.cgi">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0025" published="2001-02-12" name="CVE-2001-0025" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">ad.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5741.php" source="XF" adv="1">http-cgi-ad</ref>
      <ref url="http://www.securityfocus.com/bid/2103" source="BID" adv="1">2103</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0143.html" source="BUGTRAQ">20001211 Insecure input validation in ad.cgi</ref>
    </refs>
    <vuln_soft>
      <prod vendor="leif_m._wright" name="ad.cgi">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0026" published="2001-02-12" name="CVE-2001-0026" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">rp-pppoe PPPoE client allows remote attackers to cause a denial of service via the Clamp MSS option and a TCP packet with a zero-length TCP option.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2098" source="BID" patch="1" adv="1">2098</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-130.html" source="REDHAT" patch="1" adv="1">RHSA-2000:130</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0134.html" source="BUGTRAQ" patch="1" adv="1">20001211 DoS vulnerability in rp-pppoe versions &lt;= 2.4</ref>
      <ref url="http://xforce.iss.net/static/5727.php" source="XF" adv="1">rppppoe-zero-length-dos</ref>
      <ref url="http://www.linux-mandrake.com/en/security/MDKSA-2000-084.php3" source="MANDRAKE">MDKSA-2000:084</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000357" source="CONECTIVA">CLA-2000:357</ref>
    </refs>
    <vuln_soft>
      <prod vendor="roaring_penguin" name="pppoe">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0027" published="2001-02-12" name="CVE-2001-0027" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">mod_sqlpw module in ProFTPD does not reset a cached password when a user uses the "user" command to change accounts, which allows authenticated attackers to gain privileges of other users.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5737.php" source="XF" adv="1">proftpd-modsqlpw-unauth-access</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0139.html" source="BUGTRAQ" adv="1">20001211 mod_sqlpw Password Caching Bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="proftpd_project" name="proftpd">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0028" published="2001-02-12" name="CVE-2001-0028" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the HTML parsing code in oops WWW proxy server 1.5.2 and earlier allows remote attackers to execute arbitrary commands via a large number of " (quotation) characters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2099" source="BID" patch="1" adv="1">2099</ref>
      <ref url="http://archives.neohapsis.com/archives/freebsd/2000-12/0418.html" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-00:79</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0127.html" source="BUGTRAQ" patch="1" adv="1">20001211 [pkc] remote heap buffer overflow in oops</ref>
      <ref url="http://xforce.iss.net/static/5725.php" source="XF" adv="1">oops-ftputils-bo</ref>
    </refs>
    <vuln_soft>
      <prod vendor="igor_khasilev" name="oops_proxy_server">
        <vers num="1.4.22" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0029" published="2001-02-12" name="CVE-2001-0029" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in oops WWW proxy server 1.4.6 (and possibly other versions) allows remote attackers to execute arbitrary commands via a long host or domain name that is obtained from a reverse DNS lookup.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2099" source="BID" patch="1" adv="1">2099</ref>
      <ref url="http://zipper.paco.net/~igor/oops/ChangeLog" source="MISC">http://zipper.paco.net/~igor/oops/ChangeLog</ref>
      <ref url="http://xforce.iss.net/static/6122.php" source="XF">oops-dns-bo(6122)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0158.html" source="BUGTRAQ">20001212 Stack too ;) Re: [pkc] remote heap buffer overflow in oops</ref>
    </refs>
    <vuln_soft>
      <prod vendor="igor_khasilev" name="oops_proxy_server">
        <vers num="1.4.22" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0030" published="2001-02-16" name="CVE-2001-0030" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">FoolProof 3.9 allows local users to bypass program execution restrictions by downloading the restricted executables from another source and renaming them.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5758.php" source="XF" adv="1">foolproof-security-bypass</ref>
      <ref url="http://www.securityfocus.com/bid/2089" source="BID" adv="1">2089</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smartstuff" name="foolproof_security">
        <vers num="3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0031" published="2001-02-16" name="CVE-2001-0031" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BroadVision One-To-One Enterprise allows remote attackers to determine the physical path of server files by requesting a .JSP file name that does not exist.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5661.php" source="XF" adv="1">broadvision-bv1to1-reveal-path</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0074.html" source="BUGTRAQ" adv="1">20001207 BroadVision One-To-One Enterprise Path Disclosure Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="broadvision" name="one-to-one_enterprise_server">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0032" published="2001-02-16" name="CVE-2001-0032" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in ssldump possibly allows remote attackers to cause a denial of service and possibly gain root privileges via malicious format string specifiers in a URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5717.php" source="XF" adv="1">ssldump-format-strings</ref>
      <ref url="http://www.securityfocus.com/bid/2096" source="BID" adv="1">2096</ref>
      <ref url="http://www.securityfocus.com/archive/1/149917" source="BUGTRAQ" adv="1">20001208 format string in ssl dump</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eric_rescorla" name="ssldump">
        <vers num="0.9b1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0033" published="2001-02-16" name="CVE-2001-0033" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">KTH Kerberos IV allows local users to change the configuration of a Kerberos server running at an elevated privilege by specifying an alternate directory using with the KRBCONFDIR environmental variable, which allows the user to gain additional privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0105.html" source="BUGTRAQ" patch="1">20001210 KTH upgrade and FIX</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0093.html" source="BUGTRAQ" patch="1" adv="1">20001208 Vulnerabilities in KTH Kerberos IV</ref>
      <ref url="http://xforce.iss.net/static/5738.php" source="XF" adv="1">kerberos4-user-config</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kth" name="kth_kerberos">
        <vers num="4" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0034" published="2001-02-16" name="CVE-2001-0034" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">KTH Kerberos IV allows local users to specify an alternate proxy using the krb4_proxy variable, which allows the user to generate false proxy responses and possibly gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0105.html" source="BUGTRAQ" patch="1">20001210 KTH upgrade and FIX</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0093.html" source="BUGTRAQ" patch="1" adv="1">20001208 Vulnerabilities in KTH Kerberos IV</ref>
      <ref url="http://xforce.iss.net/static/5733.php" source="XF" adv="1">kerberos4-arbitrary-proxy</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kth" name="kth_kerberos">
        <vers prev="1" num="4.1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0035" published="2001-02-16" name="CVE-2001-0035" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the kdc_reply_cipher function in KTH Kerberos IV allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long authentication request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0105.html" source="BUGTRAQ" patch="1">20001210 KTH upgrade and FIX</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0093.html" source="BUGTRAQ" patch="1" adv="1">20001208 Vulnerabilities in KTH Kerberos IV</ref>
      <ref url="http://xforce.iss.net/static/5734.php" source="XF" adv="1">kerberos4-auth-packet-overflow</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0511.html" source="BUGTRAQ">20010130 Buffer overflow in old ssh-1.2.2x-afs-kerberosv4 patches</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kth" name="kth_kerberos">
        <vers num="4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0036" published="2001-02-16" name="CVE-2001-0036" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">KTH Kerberos IV allows local users to overwrite arbitrary files via a symlink attack on a ticket file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0105.html" source="BUGTRAQ" patch="1">20001210 KTH upgrade and FIX</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0093.html" source="BUGTRAQ" patch="1" adv="1">20001208 Vulnerabilities in KTH Kerberos IV</ref>
      <ref url="http://xforce.iss.net/static/5754.php" source="XF" adv="1">kerberos4-tmpfile-dos</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-025.html" source="REDHAT">RHSA-2001:025</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kth" name="kth_kerberos">
        <vers num="4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0037" published="2001-02-16" name="CVE-2001-0037" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in HomeSeer before 1.4.29 allows remote attackers to read arbitrary files via a URL containing .. (dot dot) specifiers.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2085" source="BID" patch="1" adv="1">2085</ref>
      <ref url="http://xforce.iss.net/static/5663.php" source="XF" adv="1">homeseer-directory-traversal</ref>
      <ref url="http://www.keware.com/hsbetachanges.htm" source="MISC">http://www.keware.com/hsbetachanges.htm</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0082.html" source="BUGTRAQ" adv="1">20001207 HomeSeer Directory Traversal Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="keware_technologies" name="homeseer">
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0038" published="2001-02-16" name="CVE-2001-0038" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Offline Explorer 1.4 before Service Release 2 allows remote attackers to read arbitrary files by specifying the drive letter (e.g. C:) in the requested URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2084" source="BID" patch="1" adv="1">2084</ref>
      <ref url="http://xforce.iss.net/static/5728.php" source="XF" adv="1">offline-explorer-reveal-files</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0078.html" source="BUGTRAQ" adv="1">20001207 MetaProducts Offline Explorer</ref>
    </refs>
    <vuln_soft>
      <prod vendor="metaproducts" name="offline_explorer">
        <vers num="1.0x" />
        <vers num="1.1x" />
        <vers num="1.2x" />
        <vers num="1.3x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0039" published="2001-02-16" name="CVE-2001-0039" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IPSwitch IMail 6.0.5 allows remote attackers to cause a denial of service using the SMTP AUTH command by sending a base64-encoded user password whose length is between 80 and 136 bytes.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2083" source="BID" patch="1" adv="1">2083</ref>
      <ref url="http://xforce.iss.net/static/5674.php" source="XF" adv="1">imail-smtp-auth-dos</ref>
      <ref url="http://www.ipswitch.com/Support/IMail/news.html" source="CONFIRM">http://www.ipswitch.com/Support/IMail/news.html</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0071.html" source="BUGTRAQ" adv="1">20001206 DoS by SMTP AUTH command in IPSwitch IMail server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="imail">
        <vers num="6.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0040" published="2001-02-16" name="CVE-2001-0040" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">APC UPS daemon, apcupsd, saves its process ID in a world-writable file, which allows local users to kill an arbitrary process by specifying the target process ID in the apcupsd.pid file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2070" source="BID" patch="1" adv="1">2070</ref>
      <ref url="http://xforce.iss.net/static/5654.php" source="XF" adv="1">apc-apcupsd-dos</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0066.html" source="BUGTRAQ" adv="1">20001206 apcupsd 3.7.2 Denial of Service</ref>
      <ref url="http://www.linux-mandrake.com/en/security/MDKSA-2000-077.php3" source="MANDRAKE">MDKSA-2000:077</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apc" name="apcupsd">
        <vers num="3.7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0041" published="2001-02-16" name="CVE-2001-0041" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Memory leak in Cisco Catalyst 4000, 5000, and 6000 series switches allows remote attackers to cause a denial of service via a series of failed telnet authentication attempts.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2072" source="BID" patch="1" adv="1">2072</ref>
      <ref url="http://www.cisco.com/warp/public/707/catalyst-memleak-pub.shtml" source="CISCO" patch="1" adv="1">20001206 Cisco Catalyst Memory Leak Vulnerability</ref>
      <ref url="http://xforce.iss.net/static/5656.php" source="XF" adv="1">cisco-catalyst-telnet-dos</ref>
      <ref url="http://www.osvdb.org/801" source="OSVDB">801</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="catos">
        <vers num="4.5(2)" />
        <vers num="4.5(3)" />
        <vers num="4.5(4)" />
        <vers num="4.5(5)" />
        <vers num="4.5(6)" />
        <vers num="4.5(7)" />
        <vers num="4.5(8)" />
        <vers num="4.5(9)" />
        <vers num="5.1" />
        <vers num="5.1(1)" />
        <vers num="5.1(1a)" />
        <vers num="5.1(2a)" />
        <vers num="5.2" />
        <vers num="5.2(1)" />
        <vers num="5.2(1a)" />
        <vers num="5.2(2)" />
        <vers num="5.2(3)" />
        <vers num="5.2(4)" />
        <vers num="5.2(5)" />
        <vers num="5.2(6)" />
        <vers num="5.2(7)" />
        <vers num="5.3(1)csx" />
        <vers num="5.3(1a)csx" />
        <vers num="5.3(2)csx" />
        <vers num="5.3(3)csx" />
        <vers num="5.3(4)csx" />
        <vers num="5.3(5)csx" />
        <vers num="5.3(5a)csx" />
        <vers num="5.3(6)csx" />
        <vers num="5.4" />
        <vers num="5.4(1)" />
        <vers num="5.4(2)" />
        <vers num="5.4(3)" />
        <vers num="5.4(4)" />
        <vers num="5.5" />
        <vers num="5.5(1)" />
        <vers num="5.5(2)" />
        <vers num="5.5(3)" />
        <vers num="5.5(4)" />
        <vers num="5.5(4a)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0042" published="2001-02-16" name="CVE-2001-0042" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing "%5c" (encoded backslash) sequences.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5659.php" source="XF" adv="1">apache-php-disclose-files</ref>
      <ref url="http://www.securityfocus.com/bid/2060" source="BID" adv="1">2060</ref>
      <ref url="http://www.securityfocus.com/archive/1/149210" source="BUGTRAQ" adv="1">20001206 CHINANSL Security Advisory(CSA-200011)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0043" published="2001-02-16" name="CVE-2001-0043" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">phpGroupWare before 0.9.7 allows remote attackers to execute arbitrary PHP commands by specifying a malicious include file in the phpgw_info parameter of the phpgw.inc.php program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2069" source="BID" patch="1" adv="1">2069</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=17604" source="MISC" patch="1">http://sourceforge.net/project/shownotes.php?release_id=17604</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0053.html" source="BUGTRAQ" patch="1" adv="1">20001206 (SRADV00006) Remote command execution vulnerabilities in phpGroupWare</ref>
      <ref url="http://xforce.iss.net/static/5650.php" source="XF" adv="1">phpgroupware-include-files</ref>
      <ref url="http://www.osvdb.org/1682" source="OSVDB">1682</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpgroupware" name="phpgroupware">
        <vers num="0.9.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0044" published="2001-02-16" name="CVE-2001-0044" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple buffer overflows in Lexmark MarkVision printer driver programs allows local users to gain privileges via long arguments to the cat_network, cat_paraller, and cat_serial commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2075" source="BID" patch="1" adv="1">2075</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0064.html" source="BUGTRAQ" patch="1" adv="1">20001206 (SRADV00007) Local root compromise through Lexmark MarkVision printer drivers</ref>
      <ref url="http://xforce.iss.net/static/5651.php" source="XF" adv="1">markvision-printer-driver-bo</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lexmark" name="markvision">
        <vers num="4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0045" published="2001-02-16" name="CVE-2001-0045" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The default permissions for the RAS Administration key in Windows NT 4.0 allows local users to execute arbitrary commands by changing the value to point to a malicious DLL, aka one of the "Registry Permissions" vulnerabilities.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2064" source="BID" patch="1" adv="1">2064</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS00-095.asp" source="MS" patch="1" adv="1">MS00-095</ref>
      <ref url="http://xforce.iss.net/static/5671.php" source="XF" adv="1">nt-ras-reg-perms</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:500" source="OVAL" sig="1">oval:org.mitre.oval:def:500</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
        <vers num="terminal_server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0046" published="2001-02-16" name="CVE-2001-0046" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The default permissions for the SNMP Parameters registry key in Windows NT 4.0 allows remote attackers to read and possibly modify the SNMP community strings to obtain sensitive information or modify network configuration, aka one of the "Registry Permissions" vulnerabilities.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2066" source="BID" patch="1" adv="1">2066</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS00-095.asp" source="MS" patch="1" adv="1">MS00-095</ref>
      <ref url="http://xforce.iss.net/static/5672.php" source="XF" adv="1">nt-snmp-reg-perms</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:139" source="OVAL" sig="1">oval:org.mitre.oval:def:139</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0047" published="2001-02-16" name="CVE-2001-0047" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The default permissions for the MTS Package Administration registry key in Windows NT 4.0 allows local users to install or modify arbitrary Microsoft Transaction Server (MTS) packages and gain privileges, aka one of the "Registry Permissions" vulnerabilities.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS00-095.asp" source="MS" patch="1" adv="1">MS00-095</ref>
      <ref url="http://xforce.iss.net/static/5673.php" source="XF" adv="1">nt-mts-reg-perms</ref>
      <ref url="http://www.securityfocus.com/bid/2065" source="BID">2065</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:140" source="OVAL" sig="1">oval:org.mitre.oval:def:140</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
        <vers num="terminal_server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0048" published="2001-02-12" name="CVE-2001-0048" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The "Configure Your Server" tool in Microsoft 2000 domain controllers installs a blank password for the Directory Service Restore Mode, which allows attackers with physical access to the controller to install malicious programs, aka the "Directory Service Restore Mode Password" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2133" source="BID" patch="1" adv="1">2133</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS00-099.asp" source="MS" patch="1" adv="1">MS00-099</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":server" />
        <vers num="" edition=":advanced_server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0049" published="2001-02-16" name="CVE-2001-0049" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WatchGuard SOHO FireWall 2.2.1 and earlier allows remote attackers to cause a denial of service via a large number of GET requests.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5665.php" source="XF" adv="1">watchguard-soho-get-dos</ref>
      <ref url="http://www.securityfocus.com/bid/2082" source="BID" adv="1">2082</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0079.html" source="BUGTRAQ" adv="1">20001207 WatchGuard SOHO v2.2.1 DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="watchguard" name="soho_firewall">
        <vers prev="1" num="2.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0050" published="2001-02-16" name="CVE-2001-0050" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in BitchX IRC client allows remote attackers to cause a denial of service and possibly execute arbitrary commands via an IP address that resolves to a long DNS hostname or domain name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2087" source="BID" patch="1" adv="1">2087</ref>
      <ref url="http://xforce.iss.net/static/5701.php" source="XF" adv="1">irc-bitchx-dns-bo</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0086.html" source="BUGTRAQ">20001207 bitchx/ircd DNS overflow demonstration</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0081.html" source="BUGTRAQ">20001207 BitchX DNS Overflow Patch</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-126.html" source="REDHAT">RHSA-2000:126</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2000/MDKSA-2000-079.php3" source="MANDRAKE">MDKSA-2000:079</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000364" source="CONECTIVA">CLA-2000:364</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:78.bitchx.v1.1.asc" source="FREEBSD">FreeBSD-SA-00:78</ref>
    </refs>
    <vuln_soft>
      <prod vendor="colten_edwards" name="bitchx">
        <vers num="1.0c17" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0051" published="2001-02-16" name="CVE-2001-0051" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">IBM DB2 Universal Database version 6.1 creates an account with a default user name and password, which allows remote attackers to gain access to the databasse.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5662.php" source="XF" adv="1">ibm-db2-gain-access</ref>
      <ref url="http://www.securityfocus.com/bid/2068" source="BID" adv="1">2068</ref>
      <ref url="http://www.securityfocus.com/archive/1/149222" source="BUGTRAQ" adv="1">20001205 IBM DB2 default account and password Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="db2_universal_database">
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":linux" />
        <vers num="6.1" edition=":windows_nt" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0052" published="2001-02-16" name="CVE-2001-0052" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">IBM DB2 Universal Database version 6.1 allows users to cause a denial of service via a malformed query.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5664.php" source="XF" adv="1">ibm-db2-dos</ref>
      <ref url="http://www.securityfocus.com/bid/2067" source="BID" adv="1">2067</ref>
      <ref url="http://www.securityfocus.com/archive/1/149207" source="BUGTRAQ" adv="1">20001205 IBM DB2 SQL DOS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="db2_universal_database">
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":windows_nt" />
        <vers num="7.1" edition="" />
        <vers num="7.1" edition=":windows_nt" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0053" published="2001-02-12" name="CVE-2001-0053" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5776.php" source="XF" patch="1" adv="1">bsd-ftpd-replydirname-bo</ref>
      <ref url="http://www.securityfocus.com/bid/2124" source="BID" patch="1" adv="1">2124</ref>
      <ref url="http://www.openbsd.org/advisories/ftpd_replydirname.txt" source="OPENBSD" patch="1" adv="1">20001218</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0275.html" source="BUGTRAQ" patch="1">20001218 Trustix Security Advisory - ed, tcsh, and ftpd-BSD</ref>
      <ref url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-018.txt.asc" source="NETBSD">NetBSD-SA2000-018</ref>
    </refs>
    <vuln_soft>
      <prod vendor="david_madore" name="ftpd-bsd">
        <vers num="0.2.3" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.5" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.6" />
        <vers num="2.7" />
        <vers num="2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0054" published="2001-02-16" name="CVE-2001-0054" modified="2010-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in FTP Serv-U before 2.5i allows remote attackers to escape the FTP root and read arbitrary files by appending a string such as "/..%20." to a CD command, a variant of a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2052" source="BID" patch="1" adv="1">2052</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97604119024280&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20001205 Serv-U FTP directory traversal vunerability (all versions)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0043.html" source="BUGTRAQ" patch="1" adv="1">20001205 (no subject)</ref>
      <ref url="http://xforce.iss.net/static/5639.php" source="XF" adv="1">ftp-servu-homedir-travers</ref>
      <ref url="http://www.osvdb.org/464" source="OSVDB">464</ref>
    </refs>
    <vuln_soft>
      <prod vendor="serv-u" name="serv-u">
        <vers num="3.0.0.16" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0055" published="2001-02-16" name="CVE-2001-0055" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CBOS 2.4.1 and earlier in Cisco 600 routers allows remote attackers to cause a denial of service via a slow stream of TCP SYN packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5627.php" source="XF" adv="1">cisco-cbos-syn-packets</ref>
      <ref url="http://www.cisco.com/warp/public/707/CBOS-multiple.shtml" source="CISCO" adv="1">20001204 Multiple Vulnerabilities in CBOS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="cisco_6xx_routers">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="broadband_operating_system">
        <vers prev="1" num="2.3.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0056" published="2001-02-16" name="CVE-2001-0056" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Cisco Web Management interface in routers running CBOS 2.4.1 and earlier does not log invalid logins, which allows remote attackers to guess passwords without detection.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5628.php" source="XF" adv="1">cisco-cbos-invalid-login</ref>
      <ref url="http://www.cisco.com/warp/public/707/CBOS-multiple.shtml" source="CISCO" adv="1">20001204 Multiple Vulnerabilities in CBOS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="broadband_operating_system">
        <vers prev="1" num="2.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0057" published="2001-02-16" name="CVE-2001-0057" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco 600 routers running CBOS 2.4.1 and earlier allow remote attackers to cause a denial of service via a large ICMP echo (ping) packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5629.php" source="XF" adv="1">cisco-cbos-icmp-echo</ref>
      <ref url="http://www.cisco.com/warp/public/707/CBOS-multiple.shtml" source="CISCO" adv="1">20001204 Multiple Vulnerabilities in CBOS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="cisco_6xx_routers">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="broadband_operating_system">
        <vers prev="1" num="2.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0058" published="2001-02-16" name="CVE-2001-0058" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Web interface to Cisco 600 routers running CBOS 2.4.1 and earlier allow remote attackers to cause a denial of service via a URL that does not end in a space character.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5626.php" source="XF" adv="1">cisco-cbos-web-access</ref>
      <ref url="http://www.cisco.com/warp/public/707/CBOS-multiple.shtml" source="CISCO" adv="1">20001204 Multiple Vulnerabilities in CBOS</ref>
      <ref url="http://www.osvdb.org/460" source="OSVDB">460</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="cisco_6xx_routers">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="broadband_operating_system">
        <vers prev="1" num="2.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0059" published="2001-02-12" name="CVE-2001-0059" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">patchadd in Solaris allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5789.php" source="XF" adv="1">solaris-patchadd-symlink</ref>
      <ref url="http://www.securityfocus.com/bid/2127" source="BID" adv="1">2127</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97720205217707&amp;w=2" source="BUGTRAQ" adv="1">20001218 Solaris patchadd(1)  (3) symlink vulnerabilty</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0060" published="2001-02-12" name="CVE-2001-0060" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in stunnel 3.8 and earlier allows attackers to execute arbitrary commands via a malformed ident username.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2128" source="BID" patch="1" adv="1">2128</ref>
      <ref url="http://www.securityfocus.com/archive/1/151719" source="BUGTRAQ" patch="1" adv="1">20001218 Stunnel format bug</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0337.html" source="BUGTRAQ" patch="1" adv="1">20001209 Trustix Security Advisory - stunnel</ref>
      <ref url="http://xforce.iss.net/static/5807.php" source="XF" adv="1">stunnel-format-logfile</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-129.html" source="REDHAT">RHSA-2000:129</ref>
      <ref url="http://www.debian.org/security/2001/dsa-009" source="DEBIAN">DSA-009</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000363" source="CONECTIVA">CLA-2000:363</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stunnel" name="stunnel">
        <vers num="3.3" />
        <vers num="3.4a" />
        <vers num="3.7" />
        <vers num="3.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0061" published="2001-02-12" name="CVE-2001-0061" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">procfs in FreeBSD and possibly other operating systems does not properly restrict access to per-process mem and ctl files, which allows local users to gain root privileges by forking a child process and executing a privileged process from the child, while the parent retains access to the child's address space.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2130" source="BID" patch="1" adv="1">2130</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:77.procfs.v1.1.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-00:77</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6106" source="XF">procfs-elevate-privileges(6106)</ref>
      <ref url="http://www.osvdb.org/1697" source="OSVDB">1697</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.5.1" />
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0062" published="2001-02-12" name="CVE-2001-0062" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">procfs in FreeBSD and possibly other operating systems allows local users to cause a denial of service by calling mmap on the process' own mem file, which causes the kernel to hang.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2131" source="BID" patch="1" adv="1">2131</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:77.procfs.v1.1.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-00:77</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6107" source="XF">procfs-mmap-dos(6107)</ref>
      <ref url="http://www.osvdb.org/6082" source="OSVDB">6082</ref>
      <ref url="http://www.osvdb.org/1698" source="OSVDB">1698</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.5.1" />
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0063" published="2001-02-12" name="CVE-2001-0063" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">procfs in FreeBSD and possibly other operating systems allows local users to bypass access control restrictions for a jail environment and gain additional privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2132" source="BID" patch="1" adv="1">2132</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:77.procfs.v1.1.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-00:77</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6108" source="XF">procfs-access-control-bo(6108)</ref>
      <ref url="http://www.osvdb.org/1691" source="OSVDB">1691</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.5.1" />
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0064" published="2001-02-12" name="CVE-2001-0064" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Webconfig, IMAP, and other services in MDaemon 3.5.0 and earlier allows remote attackers to cause a denial of service via a long URL terminated by a "\r\n" string.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2134" source="BID" patch="1" adv="1">2134</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0315.html" source="BUGTRAQ" patch="1" adv="1">20001219 def-2000-03: MDaemon 3.5.0 DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alt-n" name="mdaemon">
        <vers num="3.5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0065" published="2001-02-12" name="CVE-2001-0065" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in bftpd 1.0.13 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long SITE CHOWN command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5775.php" source="XF" adv="1">bftpd-site-chown-bo</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0189.html" source="BUGTRAQ">20001213 Potential Buffer Overflow vulnerability in bftpd-1.0.13</ref>
    </refs>
    <vuln_soft>
      <prod vendor="max-wilhelm_bruker" name="bftpd">
        <vers num="1.0.13" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0066" published="2001-02-16" name="CVE-2001-0066" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Secure Locate (slocate) allows local users to corrupt memory via a malformed database file that specifies an offset value that accesses memory outside of the intended buffer.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2004" source="BID" patch="1" adv="1">2004</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0356.html" source="BUGTRAQ" adv="1">20001126 [MSY] S(ecure)Locate heap corruption vulnerability</ref>
      <ref url="http://xforce.iss.net/static/5594.php" source="XF">slocate-heap-execute-code(5594)</ref>
      <ref url="http://www.turbolinux.com/pipermail/tl-security-announce/2001-February/000144.html" source="TURBO">TLSA2001002-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-128.html" source="REDHAT">RHSA-2000:128</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2000/MDKSA-2000-085.php3" source="MANDRAKE">MDKSA-2000:085</ref>
      <ref url="http://www.debian.org/security/2000/20001217a" source="DEBIAN">DSA-005-1</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000369" source="CONECTIVA">CLA-2001:369</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kevin_lindsay" name="secure_locate">
        <vers num="1.4" />
        <vers num="1.5" />
        <vers num="1.6" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0067" published="2001-02-12" name="CVE-2001-0067" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The installation of J-Pilot creates the .jpilot directory with the user's umask, which could allow local attackers to read other users' PalmOS backup information if their umasks are not securely set.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.linux-mandrake.com/en/security/2000/MDKSA-2000-081.php3" source="MANDRAKE" patch="1">MDKSA-2000:081</ref>
      <ref url="http://xforce.iss.net/static/5762.php" source="XF" adv="1">jpilot-perms</ref>
      <ref url="http://www.securityfocus.com/templates/archive.pike?mid=150957&amp;end=2001-02-03&amp;fromthread=1&amp;start=2001-01-28&amp;threads=0&amp;list=1&amp;" source="BUGTRAQ" adv="1">20001214 J-Pilot Permissions Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="judd_montgomery" name="jpilot">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0068" published="2001-02-12" name="CVE-2001-0068" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Mac OS Runtime for Java (MRJ) 2.2.3 allows remote attackers to use malicious applets to read files outside of the CODEBASE context via the ARCHIVE applet parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5784.php" source="XF" adv="1">mrj-runtime-malicious-applets</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0241.html" source="BUGTRAQ">20001215 Security Hole of MRJ 2.2.3 (Mac OS Runtime for Java) - Inconsistent Use of CODEBASE and ARCHIVE Attributes -</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_runtime_for_java">
        <vers num="2.2.3" edition="" />
        <vers num="2.2.3" edition=":java" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0069" published="2001-02-12" name="CVE-2001-0069" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">dialog before 0.9a-20000118-3bis in Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2151" source="BID" patch="1" adv="1">2151</ref>
      <ref url="http://www.debian.org/security/2000/20001225" source="DEBIAN" patch="1">DSA-008-1</ref>
      <ref url="http://xforce.iss.net/static/5809.php" source="XF" adv="1">dialog-symlink</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.2" edition="" />
        <vers num="2.2" edition=":powerpc" />
        <vers num="2.2" edition=":arm" />
        <vers num="2.2" edition=":68k" />
        <vers num="2.2" edition=":sparc" />
        <vers num="2.2" edition=":alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0070" published="2001-02-12" name="CVE-2001-0070" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in 1st Up Mail Server 4.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long MAIL FROM command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q4/0143.html" source="BUGTRAQ" patch="1" adv="1">20001226 1st Up Mail Server v4.1 Buffer Overflow Vulnerability</ref>
      <ref url="http://xforce.iss.net/static/5808.php" source="XF" adv="1">1stup-mail-server-bo</ref>
      <ref url="http://www.securityfocus.com/bid/2152" source="BID" adv="1">2152</ref>
    </refs>
    <vuln_soft>
      <prod vendor="upland_solutions" name="1st_up_mail_server">
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0071" published="2001-02-12" name="CVE-2001-0071" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">gpg (aka GnuPG) 1.0.4 and other versions does not properly verify detached signatures, which allows attackers to modify the contents of a file without detection.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2141" source="BID" patch="1" adv="1">2141</ref>
      <ref url="http://www.securityfocus.com/archive/1/152197" source="BUGTRAQ" patch="1" adv="1">20001220 Trustix Security Advisory - gnupg, ftpd-BSD</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-131.html" source="REDHAT" patch="1" adv="1">RHSA-2000:131</ref>
      <ref url="http://xforce.iss.net/static/5802.php" source="XF" adv="1">gnupg-detached-sig-modify</ref>
      <ref url="http://www.osvdb.org/1699" source="OSVDB">1699</ref>
      <ref url="http://www.linux-mandrake.com/en/updates/2000/MDKSA-2000-087.php3" source="MANDRAKE">MDKSA-2000-087</ref>
      <ref url="http://www.debian.org/security/2000/20001225b" source="DEBIAN">DSA-010-1</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000368" source="CONECTIVA">CLA-2000:368</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="privacy_guard">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.3b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0072" published="2001-02-12" name="CVE-2001-0072" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">gpg (aka GnuPG) 1.0.4 and other versions imports both public and private keys from public key servers without notifying the user about the private keys, which could allow an attacker to break the web of trust.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2153" source="BID" patch="1" adv="1">2153</ref>
      <ref url="http://xforce.iss.net/static/5803.php" source="XF">gnupg-reveal-private</ref>
      <ref url="http://www.securityfocus.com/archive/1/152197" source="BUGTRAQ">20001220 Trustix Security Advisory - gnupg, ftpd-BSD</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-131.html" source="REDHAT">RHSA-2000:131</ref>
      <ref url="http://www.osvdb.org/1702" source="OSVDB">1702</ref>
      <ref url="http://www.linux-mandrake.com/en/updates/2000/MDKSA-2000-087.php3" source="MANDRAKE">MDKSA-2000-087</ref>
      <ref url="http://www.debian.org/security/2000/20001225b" source="DEBIAN">DSA-010-1</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000368" source="CONECTIVA">CLA-2000:368</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="privacy_guard">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.3b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0073" published="2001-02-12" name="CVE-2001-0073" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Buffer overflow in the find_default_type function in libsecure in NSA Security-enhanced Linux, which may allow attackers to modify critical data in memory.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2154" source="BID" adv="1">2154</ref>
      <ref url="http://www.securityfocus.com/archive/1/153188" source="BUGTRAQ" adv="1">20001226 buffer overflow in libsecure (NSA Security-enhanced Linux)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nsa" name="security-enhanced_linux">
        <vers num="slinux_2000-12-18" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0074" published="2001-02-12" name="CVE-2001-0074" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in print.cgi in Technote allows remote attackers to read arbitrary files via a .. (dot dot) attack in the board parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2155" source="BID" adv="1">2155</ref>
      <ref url="http://www.securityfocus.com/archive/1/153007" source="BUGTRAQ" adv="1">20001223 Technote</ref>
    </refs>
    <vuln_soft>
      <prod vendor="technote_inc" name="technote">
        <vers num="2000" />
        <vers num="2001" />
        <vers num="pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0075" published="2001-02-12" name="CVE-2001-0075" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in main.cgi in Technote allows remote attackers to read arbitrary files via a .. (dot dot) attack in the filename parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2156" source="BID" adv="1">2156</ref>
      <ref url="http://www.securityfocus.com/archive/1/153212" source="BUGTRAQ" adv="1">20001227 [Ksecurity Advisory] main.cgi in technote</ref>
    </refs>
    <vuln_soft>
      <prod vendor="technote_inc" name="technote">
        <vers num="2000" />
        <vers num="2001" />
        <vers num="pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0076" published="2001-02-12" name="CVE-2001-0076" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">register.cgi in Ikonboard 2.1.7b and earlier allows remote attackers to execute arbitrary commands via the SEND_MAIL parameter, which overwrites an internal program variable that references a program to be executed.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2157" source="BID" patch="1" adv="1">2157</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0483.html" source="BUGTRAQ" patch="1" adv="1">20001228 Remote vulnerability in Ikonboard upto version 2.1.7b</ref>
      <ref url="http://xforce.iss.net/static/5819.php" source="XF">http-cgi-ikonboard</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ikonboard.com" name="ikonboard">
        <vers num="2.1.7b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0077" published="2001-02-12" name="CVE-2001-0077" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The clustmon service in Sun Cluster 2.x does not require authentication, which allows remote attackers to obtain sensitive information such as system logs and cluster configurations.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0180.html" source="BUGTRAQ" adv="1">20001212 Two Holes in Sun Cluster 2.x</ref>
      <ref url="http://xforce.iss.net/static/6123.php" source="XF">clustmon-no-authentication(6123)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="cluster">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0078" published="2001-02-12" name="CVE-2001-0078" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">in.mond in Sun Cluster 2.x allows local users to read arbitrary files via a symlink attack on the status file of a host running HA-NFS.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0180.html" source="BUGTRAQ" adv="1">20001212 Two Holes in Sun Cluster 2.x</ref>
      <ref url="http://xforce.iss.net/static/6125.php" source="XF">ha-nfs-symlink(6125)</ref>
      <ref url="http://www.osvdb.org/6437" source="OSVDB">6437</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="cluster">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0079" published="2001-02-12" name="CVE-2001-0079" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Support Tools Manager (STM) A.22.00 for HP-UX allows local users to overwrite arbitrary files via a symlink attack on the tool_stat.txt log file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0174.html" source="BUGTRAQ" adv="1">20001213 STM symlink Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="support_tools_manager">
        <vers num="a.22.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0080" published="2001-02-12" name="CVE-2001-0080" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco Catalyst 6000, 5000, or 4000 switches allow remote attackers to cause a denial of service by connecting to the SSH service with a non-SSH client, which generates a protocol mismatch error.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/catalyst-ssh-protocolmismatch-pub.shtml" source="CISCO" patch="1" adv="1">20001213 Cisco Catalyst SSH Protocol Mismatch Vulnerability</ref>
      <ref url="http://xforce.iss.net/static/5760.php" source="XF" adv="1">cisco-catalyst-ssh-mismatch</ref>
      <ref url="http://www.securityfocus.com/bid/2117" source="BID">2117</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="catalyst_4000">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="catalyst_5000">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="catalyst_6000">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0081" published="2001-02-12" name="CVE-2001-0081" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">swinit in nCipher does not properly disable the Operator Card Set recovery feature even when explicitly disabled by the user, which could allow attackers to gain access to application keys.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0152.html" source="BUGTRAQ" patch="1" adv="1">20001212 nCipher Security Advisory: Operator Cards unexpectedly recoverable</ref>
      <ref url="http://active.ncipher.com/updates/advisory.txt" source="CONFIRM" patch="1" adv="1">http://active.ncipher.com/updates/advisory.txt</ref>
      <ref url="http://xforce.iss.net/static/5999.php" source="XF">ncipher-recover-operator-cards(5999)</ref>
      <ref url="http://www.osvdb.org/4849" source="OSVDB">4849</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ncipher" name="ncipher">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0082" published="2001-02-12" name="CVE-2001-0082" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Check Point VPN-1/FireWall-1 4.1 SP2 with Fastmode enabled allows remote attackers to bypass access restrictions via malformed, fragmented packets.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0271.html" source="BUGTRAQ" adv="1">20001218 FireWall-1 Fastmode Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="checkpoint" name="firewall-1">
        <vers num="4.1" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0083" published="2001-02-12" name="CVE-2001-0083" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Windows Media Unicast Service in Windows Media Services 4.0 and 4.1 does not properly shut down some types of connections, producing a memory leak that allows remote attackers to cause a denial of service via a series of severed connections, aka the "Severed Windows Media Server Connection" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS00-097.asp" source="MS" patch="1" adv="1">MS00-097</ref>
      <ref url="http://xforce.iss.net/static/5785.php" source="XF" adv="1">mediaservices-dropped-connection-dos</ref>
      <ref url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q281256" source="MSKB">Q281256</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_media_services">
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0084" published="2001-02-12" name="CVE-2001-0084" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">GTK+ library allows local users to specify arbitrary modules via the GTK_MODULES environmental variable, which could allow local users to gain privileges if GTK+ is used by a setuid/setgid program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2165" source="BID" patch="1" adv="1">2165</ref>
      <ref url="http://www.gtk.org/setuid.html" source="MISC">http://www.gtk.org/setuid.html</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0027.html" source="BUGTRAQ">20010103 Claimed vulnerability in GTK_MODULES</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0498.html" source="BUGTRAQ">20010102 gtk+ security hole.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gtk" name="gtk+">
        <vers num="1.2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0085" published="2001-02-12" name="CVE-2001-0085" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Kermit communications software in HP-UX 11.0 and earlier allows local users to cause a denial of service and possibly execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2170" source="BID" patch="1" adv="1">2170</ref>
      <ref url="http://xforce.iss.net/static/5793.php" source="XF" adv="1">hpux-kermit-bo</ref>
      <ref url="http://archives.neohapsis.com/archives/hp/2000-q4/0083.html" source="HP" adv="1">HPSBUX0012-135</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.01" />
        <vers num="10.10" />
        <vers num="10.20" />
        <vers num="11.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0086" published="2001-02-12" name="CVE-2001-0086" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CGI Script Center Subscribe Me LITE 2.0 and earlier allows remote attackers to delete arbitrary mailing list users without authentication by directly calling subscribe.pl with the target address as a parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5735.php" source="XF" adv="1">subscribemelite-gain-admin-access</ref>
      <ref url="http://www.securityfocus.com/bid/2108" source="BID" adv="1">2108</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0160.html" source="BUGTRAQ" adv="1">20001212 Security Advisory: Subscribe Me Lite 1.0 - 2.0 Unix or 1.0 - 2.0 NT and below.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cgi_script_center" name="subscribe_me_lite">
        <vers num="1.0" />
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0087" published="2001-02-12" name="CVE-2001-0087" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">itetris/xitetris 1.6.2 and earlier trusts the PATH environmental variable to find and execute the gunzip program, which allows local users to gain root privileges by changing their PATH so that it points to a malicious gunzip program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2139" source="BID" patch="1" adv="1">2139</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0295.html" source="BUGTRAQ" adv="1">20001219 itetris[v1.6.2] local root exploit (system()+../ protection)</ref>
      <ref url="http://xforce.iss.net/static/5795.php" source="XF">itetris-svgalib-path</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michael_glickman" name="itetris">
        <vers num="1.6.1" />
        <vers num="1.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0088" published="2001-02-16" name="CVE-2001-0088" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">common.inc.php in phpWebLog 0.4.2 does not properly initialize the $CONF array, which inadvertently sets the password to a single character, allowing remote attackers to easily guess the SiteKey and gain administrative privileges to phpWebLog.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5625.php" source="XF" adv="1">phpweblog-bypass-authentication</ref>
      <ref url="http://www.securityfocus.com/bid/2047" source="BID" adv="1">2047</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0025.html" source="BUGTRAQ" adv="1">20001202 Bypassing admin authentication in phpWebLog</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jason_hines" name="phpweblog">
        <vers num="0.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0089" published="2001-02-16" name="CVE-2001-0089" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Internet Explorer 5.0 through 5.5 allows remote attackers to read arbitrary files from the client via the INPUT TYPE element in an HTML form, aka the "File Upload via Form" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-093.asp" source="MS" patch="1" adv="1">MS00-093</ref>
      <ref url="http://xforce.iss.net/static/5615.php" source="XF" adv="1">ie-form-file-upload</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0" />
        <vers num="5.01" />
        <vers prev="1" num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0090" published="2001-02-16" name="CVE-2001-0090" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">The Print Templates feature in Internet Explorer 5.5 executes arbitrary custom print templates without prompting the user, which could allow an attacker to execute arbitrary ActiveX controls, aka the "Browser Print Template" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2046" source="BID" patch="1" adv="1">2046</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-093.asp" source="MS" patch="1" adv="1">MS00-093</ref>
      <ref url="http://xforce.iss.net/static/5614.php" source="XF">ie-print-template(5614)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0091" published="2001-02-16" name="CVE-2001-0091" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">The ActiveX control for invoking a scriptlet in Internet Explorer 5.0 through 5.5 renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka a variant of the "Scriptlet Rendering" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-093.asp" source="MS" patch="1" adv="1">MS00-093</ref>
      <ref url="http://xforce.iss.net/static/6085.php" source="XF">ie-scriptlet-rendering-read-files(6085)</ref>
      <ref url="http://www.osvdb.org/7820" source="OSVDB">7820</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="5.01" />
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0092" published="2001-02-16" name="CVE-2001-0092" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">A function in Internet Explorer 5.0 through 5.5 does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a new variant of the "Frame Domain Verification" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-093.asp" source="MS" patch="1" adv="1">MS00-093</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6086" source="XF">ie-frame-verification-read-files(6086)</ref>
      <ref url="http://www.osvdb.org/7817" source="OSVDB">7817</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0" />
        <vers num="5.01" />
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0093" published="2001-02-12" name="CVE-2001-0093" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in telnetd in FreeBSD 1.5 allows local users to gain root privileges by modifying critical environmental variables that affect the behavior of telnetd.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-017.txt.asc" source="NETBSD" adv="1">NetBSD-SA2000-017</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0094" published="2001-02-12" name="CVE-2001-0094" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in kdc_reply_cipher of libkrb (Kerberos 4 authentication library) in NetBSD 1.5 and FreeBSD 4.2 and earlier, as used in Kerberised applications such as telnetd and login, allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-017.txt.asc" source="NETBSD" patch="1" adv="1">NetBSD-SA2000-017</ref>
      <ref url="http://xforce.iss.net/static/5734.php" source="XF">kerberos4-auth-packet-overflow(5734)</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:25.kerberosIV.asc" source="FREEBSD">FreeBSD-SA-01:25</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0095" published="2001-02-12" name="CVE-2001-0095" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">catman in Solaris 2.7 and 2.8 allows local users to overwrite arbitrary files via a symlink attack on the sman_PID temporary file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5788.php" source="XF" adv="1">solaris-catman-symlink(5788)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0313.html" source="BUGTRAQ" adv="1">20001218 Catman file clobbering vulnerability Solaris 2.x</ref>
      <ref url="http://www.osvdb.org/6024" source="OSVDB">6024</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.7" />
        <vers num="2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0096" published="2001-02-12" name="CVE-2001-0096" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">FrontPage Server Extensions (FPSE) in IIS 4.0 and 5.0 allows remote attackers to cause a denial of service via a malformed form, aka the "Malformed Web Form Submission" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS00-100.asp" source="MS" patch="1" adv="1">MS00-100</ref>
      <ref url="http://xforce.iss.net/static/5823.php" source="XF" adv="1">iis-web-form-submit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0097" published="2001-02-12" name="CVE-2001-0097" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Web interface for Infinite Interchange 3.6.1 allows remote attackers to cause a denial of service (application crash) via a large POST request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5798.php" source="XF" adv="1">infinite-interchange-dos</ref>
      <ref url="http://www.securityfocus.com/bid/2140" source="BID" adv="1">2140</ref>
      <ref url="http://www.securityfocus.com/archive/1/152403" source="BUGTRAQ">20001221 Infinite InterChange DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="infinite" name="infinite_interchange">
        <vers num="3.61" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0098" published="2001-02-12" name="CVE-2001-0098" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with a ".."  string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5782.php" source="XF" patch="1" adv="1">weblogic-dot-bo</ref>
      <ref url="http://www.securityfocus.com/bid/2138" source="BID" patch="1" adv="1">2138</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0331.html" source="BUGTRAQ" patch="1">20001219 def-2000-04: Bea WebLogic Server dotdot-overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers prev="1" num="4.5.2" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0099" published="2001-02-12" name="CVE-2001-0099" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">bsguest.cgi guestbook script allows remote attackers to execute arbitrary commands via shell metacharacters in the email address.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5796.php" source="XF" patch="1" adv="1">bsguest-cgi-execute-commands</ref>
      <ref url="http://www.stanback.net/" source="MISC" patch="1">http://www.stanback.net/</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0390.html" source="BUGTRAQ" patch="1" adv="1">20001221 BS Scripts Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="brian_stanback" name="bsguest.cgi">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0100" published="2001-02-12" name="CVE-2001-0100" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">bslist.cgi mailing list script allows remote attackers to execute arbitrary commands via shell metacharacters in the email address.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5797.php" source="XF" patch="1" adv="1">bslist-cgi-execute-commands</ref>
      <ref url="http://www.stanback.net/" source="MISC" patch="1">http://www.stanback.net/</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0390.html" source="BUGTRAQ" patch="1" adv="1">20001221 BS Scripts Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="brian_stanback" name="bslist.cgi">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0101" published="2001-02-12" name="CVE-2001-0101" modified="2011-02-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Vulnerability in fetchmail 5.5.0-2 and earlier in the AUTHENTICATE GSSAPI command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/7455.php" source="XF" patch="1">fetchmail-authenticate-gssapi(7455)</ref>
      <ref url="http://www.turbolinux.com/pipermail/tl-security-announce/2000-December/000027.html" source="TURBO" patch="1">TLSA2000024-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHBA-2000-106.html" source="REDHAT" adv="1">RHBA-2000:106-04</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fetchmail" name="fetchmail">
        <vers num="4.5.1" />
        <vers num="4.5.2" />
        <vers num="4.5.3" />
        <vers num="4.5.4" />
        <vers num="4.5.5" />
        <vers num="4.5.6" />
        <vers num="4.5.7" />
        <vers num="4.5.8" />
        <vers num="4.6.0" />
        <vers num="4.6.1" />
        <vers num="4.6.2" />
        <vers num="4.6.3" />
        <vers num="4.6.4" />
        <vers num="4.6.5" />
        <vers num="4.6.6" />
        <vers num="4.6.7" />
        <vers num="4.6.8" />
        <vers num="4.6.9" />
        <vers num="4.7.0" />
        <vers num="4.7.1" />
        <vers num="4.7.2" />
        <vers num="4.7.3" />
        <vers num="4.7.4" />
        <vers num="4.7.5" />
        <vers num="4.7.6" />
        <vers num="4.7.7" />
        <vers num="5.0.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.0.6" />
        <vers num="5.0.7" />
        <vers num="5.0.8" />
        <vers num="5.1.0" />
        <vers num="5.1.4" />
        <vers num="5.2.0" />
        <vers num="5.2.1" />
        <vers num="5.2.3" />
        <vers num="5.2.4" />
        <vers num="5.2.7" />
        <vers num="5.2.8" />
        <vers num="5.3.0" />
        <vers num="5.3.1" />
        <vers num="5.3.3" />
        <vers num="5.3.8" />
        <vers num="5.4.0" />
        <vers num="5.4.3" />
        <vers num="5.4.4" />
        <vers num="5.4.5" />
        <vers prev="1" num="5.5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0102" published="2001-02-12" name="CVE-2001-0102" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">"Multiple Users" Control Panel in Mac OS 9 allows Normal users to gain Owner privileges by removing the Users &amp; Groups Data File, which effectively removes the Owner password and allows the Normal user to log in as the Owner account without a password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5830.php" source="XF" adv="1">macos-multiple-users</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0497.html" source="BUGTRAQ" adv="1">20001229 Mac OS 9 Multiple Users Control Panel Password Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0103" published="2001-02-12" name="CVE-2001-0103" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">CoffeeCup Direct and Free FTP clients uses weak encryption to store passwords in the FTPServers.ini file, which could allow attackers to easily decrypt the passwords.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5744.php" source="XF" adv="1">coffeecup-ftp-weak-encryption</ref>
      <ref url="http://www.securityfocus.com/bid/2107" source="BID" adv="1">2107</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coffeecup_software" name="coffeecup_direct_ftp">
        <vers num="1.0" />
      </prod>
      <prod vendor="coffeecup_software" name="coffeecup_free_ftp">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0104" published="2001-02-12" name="CVE-2001-0104" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">MDaemon Pro 3.5.1 and earlier allows local users to bypass the "lock server" security setting by pressing the Cancel button at the password prompt, then pressing the enter key.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5763.php" source="XF" adv="1">mdaemon-lock-bypass-password</ref>
      <ref url="http://www.securityfocus.com/bid/2115" source="BID" adv="1">2115</ref>
      <ref url="http://www.securityfocus.com/archive/1/151156" source="BUGTRAQ">20001214 Bypass MDaemon 3.5.1 "Lock Server" Protection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alt-n" name="mdaemon">
        <vers num="3.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0105" published="2001-02-12" name="CVE-2001-0105" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Vulnerability in top in HP-UX 11.04 and earlier allows local users to overwrite files owned by the "sys" group.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/hp/2000-q4/0079.html" source="HP" patch="1">HPSBUX0012-134</ref>
      <ref url="http://xforce.iss.net/static/5773.php" source="XF" adv="1">hp-top-sys-files</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10" />
        <vers num="11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0106" published="2001-02-12" name="CVE-2001-0106" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Vulnerability in inetd server in HP-UX 11.04 and earlier allows attackers to cause a denial of service when the "swait" state is used by a server.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/hp/2001-q1/0009.html" source="HP" patch="1" adv="1">HPSBUX0101-136</ref>
      <ref url="http://xforce.iss.net/static/5904.php" source="XF">hp-inetd-swait-dos(5904)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers prev="1" num="11.04" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0107" published="2001-03-12" name="CVE-2001-0107" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Veritas Backup agent on Linux allows remote attackers to cause a denial of service by establishing a connection without sending any data, which causes the process to hang.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2204" source="BID" adv="1">2204</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97958921407182&amp;w=2" source="BUGTRAQ" adv="1">20010115 Veritas BackupExec (remote DoS)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec_veritas" name="backup">
        <vers num="4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0108" published="2001-03-12" name="CVE-2001-0108" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP Apache module 4.0.4 and earlier allows remote attackers to bypass .htaccess access restrictions via a malformed HTTP request on an unrestricted page that causes PHP to use those access controls on the next page that is requested.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2206" source="BID" patch="1" adv="1">2206</ref>
      <ref url="http://xforce.iss.net/static/5940.php" source="XF">php-htaccess-unauth-access(5940)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-136.html" source="REDHAT">RHSA-2000:136</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-013.php3" source="MANDRAKE">MDKSA-2001:013</ref>
      <ref url="http://www.debian.org/security/2001/dsa-020" source="DEBIAN">DSA-020</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97957961212852" source="BUGTRAQ">20010112 PHP Security Advisory - Apache Module bugs</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000373" source="CONECTIVA">CLA-2001:373</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0109" published="2001-03-12" name="CVE-2001-0109" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">rctab in SuSE 7.0 and earlier allows local users to create or overwrite arbitrary files via a symlink attack on the rctmp temporary file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2207" source="BID" patch="1" adv="1">2207</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0226.html" source="BUGTRAQ" adv="1">20010113 Serious security flaw in SuSE rctab</ref>
      <ref url="http://xforce.iss.net/static/5945.php" source="XF">rctab-elevate-privileges(5945)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0272.html" source="BUGTRAQ">20010117 Re: Serious security flaw in SuSE rctab</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="suse_linux">
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0110" published="2001-03-12" name="CVE-2001-0110" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in jaZip Zip/Jaz drive manager allows local users to gain root privileges via a long DISPLAY environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2001/dsa-017" source="DEBIAN" patch="1">DSA-017</ref>
      <ref url="http://www.securityfocus.com/bid/2209" source="BID" adv="1">2209</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0228.html" source="BUGTRAQ">20010114 Vulnerability in jaZip.</ref>
      <ref url="http://xforce.iss.net/static/5942.php" source="XF">jazip-display-bo(5942)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iomega" name="jazip">
        <vers num="0.32.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0111" published="2001-03-12" name="CVE-2001-0111" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in splitvt before 1.6.5 allows local users to execute arbitrary commands via the -rcfile command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2210" source="BID" patch="1" adv="1">2210</ref>
      <ref url="http://www.debian.org/security/2001/dsa-014" source="DEBIAN" patch="1">DSA-014-1</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97958269320974&amp;w=2" source="BUGTRAQ" adv="1">20010114 [MSY] Multiple vulnerabilities in splitvt</ref>
      <ref url="http://xforce.iss.net/static/5948.php" source="XF">splitvt-perserc-format-string(5948)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sam_lantinga" name="splitvt">
        <vers num="1.6.4" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.2" edition="" />
        <vers num="2.2" edition=":powerpc" />
        <vers num="2.2" edition=":arm" />
        <vers num="2.2" edition=":68k" />
        <vers num="2.2" edition=":sparc" />
        <vers num="2.2" edition=":alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0112" published="2001-03-12" name="CVE-2001-0112" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple buffer overflows in splitvt before 1.6.5 allow local users to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2210" source="BID" patch="1" adv="1">2210</ref>
      <ref url="http://www.debian.org/security/2001/dsa-014" source="DEBIAN" patch="1">DSA-014</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97958269320974&amp;w=2" source="BUGTRAQ" adv="1">20010114 [MSY] Multiple vulnerabilities in splitvt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sam_lantinga" name="splitvt">
        <vers prev="1" num="1.6.4" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.2" edition="" />
        <vers num="2.2" edition=":powerpc" />
        <vers num="2.2" edition=":arm" />
        <vers num="2.2" edition=":68k" />
        <vers num="2.2" edition=":sparc" />
        <vers num="2.2" edition=":alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0113" published="2001-03-12" name="CVE-2001-0113" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">statsconfig.pl in OmniHTTPd 2.07 allows remote attackers to execute arbitrary commands via the mostbrowsers parameter, whose value is used as part of a generated Perl script.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2211" source="BID" patch="1" adv="1">2211</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0248.html" source="BUGTRAQ">20010116 Vulnerabilities in OmniHTTPd default installation</ref>
    </refs>
    <vuln_soft>
      <prod vendor="omnicron" name="omnihttpd">
        <vers num="2.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0114" published="2001-03-12" name="CVE-2001-0114" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">statsconfig.pl in OmniHTTPd 2.07 allows remote attackers to overwrite arbitrary files via the cgidir parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2211" source="BID" patch="1" adv="1">2211</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0248.html" source="BUGTRAQ">20010116 Vulnerabilities in OmniHTTPd default installation</ref>
    </refs>
    <vuln_soft>
      <prod vendor="omnicron" name="omnihttpd">
        <vers num="2.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0115" published="2001-03-12" name="CVE-2001-0115" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in arp command in Solaris 7 and earlier allows local users to execute arbitrary commands via a long -f parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2193" source="BID" patch="1" adv="1">2193</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/200&amp;type=0&amp;nav=sec.sba" source="SUN" patch="1" adv="1">00200</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97957435729702&amp;w=2" source="BUGTRAQ">20010112 arp exploit</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97934312727101&amp;w=2" source="BUGTRAQ">20010111 Solaris Arp Vulnerability</ref>
      <ref url="http://xforce.iss.net/static/5928.php" source="XF">solaris-arp-bo(5928)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":x86" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0116" published="2001-03-12" name="CVE-2001-0116" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">gpm 1.19.3 allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2188" source="BID" patch="1" adv="1">2188</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-006.php3" source="MANDRAKE" patch="1">MDKSA-2001:006</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97916374410647&amp;w=2" source="BUGTRAQ" adv="1">20010110 Immunix OS Security update for lots of temp file problems</ref>
      <ref url="http://xforce.iss.net/static/5917.php" source="XF">linux-gpm-symlink(5917)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="immunix" name="immunix">
        <vers num="7.0_beta" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0117" published="2001-03-12" name="CVE-2001-0117" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">sdiff 2.7 in the diffutils package allows local users to overwrite files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/579928" source="CERT-VN">VU#579928</ref>
      <ref url="http://www.securityfocus.com/bid/2191" source="BID" patch="1" adv="1">2191</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-008.php3" source="MANDRAKE" patch="1">MDKSA-2001:008-1</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97916374410647&amp;w=2" source="BUGTRAQ" adv="1">20010110 Immunix OS Security update for lots of temp file problems</ref>
      <ref url="http://xforce.iss.net/static/5914.php" source="XF">linux-diffutils-sdiff-symlink(5914)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-116.html" source="REDHAT">RHSA-2001:116</ref>
      <ref url="http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2000-70-028-01" source="IMMUNIX">IMNX-2000-70-028-01</ref>
    </refs>
    <vuln_soft>
      <prod vendor="immunix" name="immunix">
        <vers num="7.0_beta" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="1.0.1" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.0" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="1.1" />
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0118" published="2001-03-12" name="CVE-2001-0118" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">rdist 6.1.5 allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2195" source="BID" patch="1" adv="1">2195</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-005.php3" source="MANDRAKE" patch="1">MDKSA-2001-005</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97916374410647&amp;w=2" source="BUGTRAQ" adv="1">20010110 Immunix OS Security update for lots of temp file problems</ref>
      <ref url="http://xforce.iss.net/static/5925.php" source="XF">rdist-symlink(5925)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="immunix" name="immunix">
        <vers num="7.0_beta" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0119" published="2001-03-12" name="CVE-2001-0119" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">getty_ps 2.0.7j allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2194" source="BID" patch="1" adv="1">2194</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-004.php3" source="MANDRAKE" patch="1">MDKSA-2001:004</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97916374410647&amp;w=2" source="BUGTRAQ" adv="1">20010110 Immunix OS Security update for lots of temp file problems</ref>
      <ref url="http://xforce.iss.net/static/5924.php" source="XF">gettyps-symlink(5924)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="immunix" name="immunix">
        <vers num="7.0_beta" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0120" published="2001-03-12" name="CVE-2001-0120" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">useradd program in shadow-utils program may allow local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2196" source="BID" patch="1" adv="1">2196</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-007.php3" source="MANDRAKE" patch="1">MDKSA-2001:007</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97916374410647&amp;w=2" source="BUGTRAQ" adv="1">20010110 Immunix OS Security update for lots of temp file problems</ref>
      <ref url="http://xforce.iss.net/static/5927.php" source="XF">shadow-utils-useradd-symlink(5927)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="immunix" name="immunix">
        <vers num="7.0_beta" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0121" published="2001-03-12" name="CVE-2001-0121" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ImageCast Control Center 4.1.0 allows remote attackers to cause a denial of service (resource exhaustion or system crash) via a long string to port 12002.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2174" source="BID" adv="1">2174</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0071.html" source="BUGTRAQ" adv="1">20010108 def-2001-01: ImageCast IC3 Control Center DoS</ref>
      <ref url="http://xforce.iss.net/static/5901.php" source="XF">storagesoft-imagecast-dos(5901)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="storagesoft" name="imagecast_ic3">
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0122" published="2001-03-13" name="CVE-2001-0122" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Server 1.3.x and Websphere 3.52 allows remote attackers to cause a denial of service via a series of malformed HTTP requests that generate a "bad request" error.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2175" source="BID" patch="1" adv="1">2175</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0079.html" source="BUGTRAQ" patch="1" adv="1">20010108 def-2001-02: IBM Websphere 3.52 Kernel Leak DoS </ref>
      <ref url="http://www-4.ibm.com/software/webservers/security.html" source="CONFIRM">http://www-4.ibm.com/software/webservers/security.html</ref>
      <ref url="http://xforce.iss.net/static/5900.php" source="XF">ibm-websphere-dos(5900)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0061.html" source="BUGTRAQ">20010307 def-2001-02: IBM HTTP Server Kernel Leak DoS (re-release)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="http_server">
        <vers num="1.3.12.2" />
      </prod>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="3.52" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0123" published="2001-03-12" name="CVE-2001-0123" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in eXtropia bbs_forum.cgi 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the file parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2177" source="BID" patch="1" adv="1">2177</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97905792214999&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010107 Cgisecurity.com Advisory #3.1</ref>
      <ref url="http://www.extropia.com/hacks/bbs_security.html" source="CONFIRM">http://www.extropia.com/hacks/bbs_security.html</ref>
      <ref url="http://xforce.iss.net/static/5906.php" source="XF">http-cgi-bbs-forum(5906)</ref>
      <ref url="http://www.osvdb.org/3546" source="OSVDB">3546</ref>
    </refs>
    <vuln_soft>
      <prod vendor="extropia" name="bbs_forum.cgi">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0124" published="2001-03-12" name="CVE-2001-0124" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in exrecover in Solaris 2.6 and earlier possibly allows local users to gain privileges via a long command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2179" source="BID" patch="1" adv="1">2179</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97908386502156&amp;w=2" source="BUGTRAQ">20010109 Solaris /usr/lib/exrecover buffer overflow</ref>
      <ref url="http://xforce.iss.net/static/5913.php" source="XF">solaris-exrecover-bo(5913)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.5.1" />
        <vers num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0125" published="2001-03-12" name="CVE-2001-0125" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">exmh 2.2 and earlier allows local users to overwrite arbitrary files via a symlink attack on the exmhErrorMsg temporary file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <exception />
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5829.php" source="XF" patch="1" adv="1">exmh-error-symlink</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-015.php3" source="MANDRAKE" patch="1">MDKSA-2001:015</ref>
      <ref url="http://www.beedub.com/exmh/symlink.html" source="CONFIRM" patch="1" adv="1">http://www.beedub.com/exmh/symlink.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97958594330100&amp;w=2" source="BUGTRAQ" patch="1">20010112 exmh security vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97846489313059&amp;w=2" source="BUGTRAQ" adv="1">20001231 Advisory: exmh symlink vulnerability</ref>
      <ref url="http://www.debian.org/security/2001/dsa-022" source="DEBIAN">DSA-022</ref>
      <ref url="http://archives.neohapsis.com/archives/freebsd/2001-01/0543.html" source="FREEBSD">FreeBSD-SA-01:17</ref>
    </refs>
    <vuln_soft>
      <prod vendor="exmh" name="exmh">
        <vers prev="1" num="2.2" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.2" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0126" published="2001-03-12" name="CVE-2001-0126" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Oracle XSQL servlet 1.0.3.0 and earlier allows remote attackers to execute arbitrary Java code by redirecting the XSQL server to another source via the xml-stylesheet parameter in the xslt stylesheet.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97906670012796&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010109 Oracle XSQL servlet and xml-stylesheet allow executing java on the web server </ref>
      <ref url="http://xforce.iss.net/static/5905.php" source="XF">oracle-xsql-execute-code(5905)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98027700625521&amp;w=2" source="BUGTRAQ">20010123 Patch for Potential Vulnerability in Oracle XSQL Servlet</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="oracle8i">
        <vers num="8.1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0127" published="2001-03-12" name="CVE-2001-0127" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Buffer overflow in Olivier Debon Flash plugin (not the Macromedia plugin) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long DefineSound tag.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/451096" source="CERT-VN">VU#451096</ref>
      <ref url="http://www.securityfocus.com/bid/2214" source="BID" adv="1">2214</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0236.html" source="BUGTRAQ" adv="1">20010115 Flash plugin write-overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oliver_debon" name="flash">
        <vers prev="1" num="0.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0128" published="2001-03-12" name="CVE-2001-0128" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Zope before 2.2.4 does not properly compute local roles, which could allow users to bypass specified access restrictions and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.linux-mandrake.com/en/updates/2000/MDKSA-2000-083.php3" source="MANDRAKE" patch="1">MDKSA-2000-083</ref>
      <ref url="http://www.debian.org/security/2000/20001219" source="DEBIAN" patch="1" adv="1">DSA-006-1</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:06.zope.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-01:06</ref>
      <ref url="http://xforce.iss.net/static/5777.php" source="XF" adv="1">zope-calculate-roles</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2000-127.html" source="REDHAT">RHSA-2000:127</ref>
      <ref url="http://www.osvdb.org/6284" source="OSVDB">6284</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000365" source="CONECTIVA">CLA-2000:365</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux_powertools">
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="7.0" />
      </prod>
      <prod vendor="zope" name="zope">
        <vers prev="1" num="2.2.4" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="6.0" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.2" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="6.2" edition="stable" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0129" published="2001-03-12" name="CVE-2001-0129" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Tinyproxy HTTP proxy 1.3.3 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long connect request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2217" source="BID" patch="1" adv="1">2217</ref>
      <ref url="http://www.debian.org/security/2001/dsa-018" source="DEBIAN" patch="1">DSA-018</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97975486527750&amp;w=2" source="BUGTRAQ">20010117 [pkc] remote heap overflow in tinyproxy</ref>
      <ref url="http://xforce.iss.net/static/5954.php" source="XF">tinyproxy-remote-bo(5954)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tinyproxy" name="tinyproxy">
        <vers prev="1" num="1.3.2" />
        <vers num="1.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0130" published="2001-03-12" name="CVE-2001-0130" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in HTML parser of the Lotus R5 Domino Server before 5.06, and Domino Client before 5.05, allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a malformed font size specifier.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://service1.symantec.com/sarc/sarc.nsf/info/html/Lotus.Domino.Denial.of.Service.Malformed.HTML.Email.html" source="MISC" adv="1">http://service1.symantec.com/sarc/sarc.nsf/info/html/Lotus.Domino.Denial.of.Service.Malformed.HTML.Email.html</ref>
      <ref url="http://xforce.iss.net/static/6207.php" source="XF">lotus-html-bo(6207)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lotus" name="domino_r5_client">
        <vers num="5.04" />
        <vers num="5.05" />
      </prod>
      <prod vendor="lotus" name="domino_r5_server">
        <vers num="5.04" />
        <vers num="5.05" />
        <vers num="5.06" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0131" published="2001-03-12" name="CVE-2001-0131" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2182" source="BID" patch="1" adv="1">2182</ref>
      <ref url="http://www.debian.org/security/2001/dsa-021" source="DEBIAN" patch="1" adv="1">DSA-021</ref>
      <ref url="http://xforce.iss.net/static/5926.php" source="XF">linux-apache-symlink(5926)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97916374410647&amp;w=2" source="BUGTRAQ" adv="1">20010110 Immunix OS Security update for lots of temp file problems</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="" />
      </prod>
      <prod vendor="immunix" name="immunix">
        <vers num="7.0_beta" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0132" published="2001-03-12" name="CVE-2001-0132" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">Interscan VirusWall 3.6.x and earlier follows symbolic links when uninstalling the product, which allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2213" source="BID" adv="1">2213</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0235.html" source="BUGTRAQ" adv="1">20010114 Trend Micro's VirusWall: Multiple vunerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="interscan_viruswall">
        <vers num="3.0.1" />
        <vers prev="1" num="3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0133" published="2001-03-12" name="CVE-2001-0133" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The web administration interface for Interscan VirusWall 3.6.x and earlier does not use encryption, which could allow remote attackers to obtain the administrator password to sniff the administrator password via the setpasswd.cgi program or other HTTP GET requests that contain base64 encoded usernames and passwords.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2212" source="BID" adv="1">2212</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0235.html" source="BUGTRAQ" adv="1">20010114 Trend Micro's VirusWall: Multiple vunerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="interscan_viruswall">
        <vers num="3.0.1" />
        <vers prev="1" num="3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0134" published="2001-03-12" name="CVE-2001-0134" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in cpqlogin.htm in web-enabled agents for various Compaq management software products such as Insight Manager and Management Agents allows remote attackers to execute arbitrary commands via a long user name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www5.compaq.com/products/servers/management/agentsecurity.html" source="COMPAQ" patch="1">SSRT0705</ref>
      <ref url="http://www.securityfocus.com/bid/2200" source="BID" patch="1" adv="1">2200</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97967435023835&amp;w=2" source="BUGTRAQ" adv="1">20010116 iXsecurity.20001120.compaq-authbo.a</ref>
    </refs>
    <vuln_soft>
      <prod vendor="compaq" name="armada_insight_manager">
        <vers num="4.20" />
        <vers num="4.20j" />
      </prod>
      <prod vendor="compaq" name="enterprise_volume_manager-command_scripter">
        <vers num="1.0" />
        <vers num="1.1" />
      </prod>
      <prod vendor="compaq" name="foundation_agents">
        <vers num="1.0" />
        <vers num="2.1" />
        <vers num="4.0" />
        <vers num="4.90" />
      </prod>
      <prod vendor="compaq" name="insight_management_agent">
        <vers num="4.37e" />
      </prod>
      <prod vendor="compaq" name="insight_management_desktop_web_agent">
        <vers num="3.7" />
      </prod>
      <prod vendor="compaq" name="insight_manager_lc">
        <vers num="1.3c" />
        <vers num="1.50a" />
      </prod>
      <prod vendor="compaq" name="insight_manager_xe">
        <vers num="1.0" />
        <vers num="1.21" />
      </prod>
      <prod vendor="compaq" name="intelligent_cluster_administrator">
        <vers num="1.0" />
        <vers num="2.1" />
      </prod>
      <prod vendor="compaq" name="management_agents">
        <vers num="4.30j" />
        <vers num="4.35j" />
        <vers num="4.36e" />
        <vers num="4.36j" />
      </prod>
      <prod vendor="compaq" name="open_san_manager">
        <vers num="1.0" />
      </prod>
      <prod vendor="compaq" name="sanworks_resource_monitor">
        <vers num="1.0" />
      </prod>
      <prod vendor="compaq" name="storage_allocation_reporter">
        <vers num="1.0" />
      </prod>
      <prod vendor="compaq" name="survey_utility">
        <vers num="2.17" />
        <vers num="2.18" />
        <vers num="2.33" />
      </prod>
      <prod vendor="compaq" name="system_healthcheck">
        <vers num="3.0" />
      </prod>
      <prod vendor="digital" name="unix">
        <vers num="4.0f" />
        <vers num="4.0g" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0135" published="2001-03-12" name="CVE-2001-0135" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The default installation of Ultraboard 2000 2.11 creates the Skins, Database, and Backups directories with world-writeable permissions, which could allow local users to modify sensitive information or possibly insert and execute CGI programs.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2197" source="BID" adv="1">2197</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97933458505857&amp;w=2" source="BUGTRAQ" adv="1">20010112 UltraBoard cgi directory permission problem</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ultrascripts" name="ultraboard">
        <vers num="2.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0136" published="2001-03-12" name="CVE-2001-0136" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Memory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of USER commands, and possibly SIZE commands if the server has been improperly installed.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5801.php" source="XF" adv="1">proftpd-size-memory-leak</ref>
      <ref url="http://www.securityfocus.com/archive/1/152206" source="BUGTRAQ">20001220 ProFTPD 1.2.0 Memory leakage - denial of service</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0132.html" source="BUGTRAQ" adv="1">20010110 Re: Memory leakage in ProFTPd leads to remote DoS (SIZE FTP); (Exploit Code) </ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0122.html" source="BUGTRAQ" adv="1">20010109 Memory leakage in ProFTPd leads to remote DoS (SIZE FTP); (Exploit Code) </ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-021.php3" source="MANDRAKE">MDKSA-2001:021</ref>
      <ref url="http://www.debian.org/security/2001/dsa-029" source="DEBIAN">DSA-029</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000380" source="CONECTIVA">CLA-2001:380</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0267.html" source="BUGTRAQ">20010213 Trustix Security Advisory - proftpd, kernel</ref>
    </refs>
    <vuln_soft>
      <prod vendor="proftpd_project" name="proftpd">
        <vers num="" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.2" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0137" published="2001-03-12" name="CVE-2001-0137" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Windows Media Player 7 allows remote attackers to execute malicious Java applets in Internet Explorer clients by enclosing the applet in a skin file named skin.wmz, then referencing that skin in the codebase parameter to an applet tag, aka the Windows Media Player Skins File Download" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2203" source="BID" patch="1" adv="1">2203</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97958100816503&amp;w=2" source="BUGTRAQ" adv="1">20010115 Windows Media Player 7 and IE java vulnerability - executing arbitrary programs </ref>
      <ref url="http://xforce.iss.net/static/5937.php" source="XF">win-mediaplayer-arbitrary-code(5937)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-010.asp" source="MS">MS01-010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_media_player">
        <vers num="7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0138" published="2001-03-12" name="CVE-2001-0138" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">privatepw program in wu-ftpd before 2.6.1-6 allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2189" source="BID" patch="1" adv="1">2189</ref>
      <ref url="http://xforce.iss.net/static/5915.php" source="XF">linux-wuftpd-privatepw-symlink(5915)</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-001.php3" source="MANDRAKE">MDKSA-2001-001</ref>
      <ref url="http://www.debian.org/security/2001/dsa-016" source="DEBIAN">DSA-016</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97916374410647&amp;w=2" source="BUGTRAQ">20010110 Immunix OS Security update for lots of temp file problems</ref>
    </refs>
    <vuln_soft>
      <prod vendor="immunix" name="immunix">
        <vers num="7.0_beta" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.2" edition="" />
        <vers num="2.2" edition=":powerpc" />
        <vers num="2.2" edition=":68k" />
        <vers num="2.2" edition=":alpha" />
        <vers num="2.2" edition=":arm" />
        <vers num="2.2" edition=":sparc" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="1.0.1" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0139" published="2001-03-12" name="CVE-2001-0139" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">inn 2.2.3 allows local users to overwrite arbitrary files via a symlink attack in some configurations.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2190" source="BID" patch="1" adv="1">2190</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-010.php3" source="MANDRAKE" patch="1" adv="1">MDKSA-2001:010</ref>
      <ref url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-001.0.txt" source="CALDERA" adv="1">CSSA-2001-001.0</ref>
      <ref url="http://xforce.iss.net/static/5916.php" source="XF">linux-inn-symlink(5916)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97916374410647&amp;w=2" source="BUGTRAQ">20010110 Immunix OS Security update for lots of temp file problems</ref>
    </refs>
    <vuln_soft>
      <prod vendor="caldera" name="openlinux_desktop">
        <vers num="2.3" />
      </prod>
      <prod vendor="immunix" name="immunix">
        <vers num="7.0_beta" />
      </prod>
      <prod vendor="caldera" name="openlinux_edesktop">
        <vers num="2.4" />
      </prod>
      <prod vendor="caldera" name="openlinux_eserver">
        <vers num="2.3" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.2" edition="" />
        <vers num="2.2" edition=":68k" />
        <vers num="2.2" edition=":alpha" />
        <vers num="2.2" edition=":arm" />
        <vers num="2.2" edition=":sparc" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0140" published="2001-03-12" name="CVE-2001-0140" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">arpwatch 2.1a4 allows local users to overwrite arbitrary files via a symlink attack in some configurations.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2183" source="BID" patch="1" adv="1">2183</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-002.php3" source="MANDRAKE" patch="1">MDKSA-2001:002</ref>
      <ref url="http://xforce.iss.net/static/5922.php" source="XF">tcpdump-arpwatch-symlink(5922)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97916374410647&amp;w=2" source="BUGTRAQ">20010110 Immunix OS Security update for lots of temp file problems</ref>
    </refs>
    <vuln_soft>
      <prod vendor="immunix" name="immunix">
        <vers num="7.0_beta" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0141" published="2001-03-12" name="CVE-2001-0141" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">mgetty 1.1.22 allows local users to overwrite arbitrary files via a symlink attack in some configurations.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2187" source="BID" patch="1" adv="1">2187</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-009.php3" source="MANDRAKE" patch="1">MDKSA-2001:009</ref>
      <ref url="http://www.debian.org/security/2001/dsa-011" source="DEBIAN" patch="1">DSA-011</ref>
      <ref url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-002.0.txt" source="CALDERA" patch="1">CSSA-2001-002.0</ref>
      <ref url="http://xforce.iss.net/static/5918.php" source="XF">linux-mgetty-symlink(5918)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-050.html" source="REDHAT">RHSA-2001:050</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97916374410647&amp;w=2" source="BUGTRAQ">20010110 Immunix OS Security update for lots of temp file problems</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gert_doering" name="mgetty">
        <vers num="1.1.22" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0142" published="2001-03-12" name="CVE-2001-0142" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">squid 2.3 and earlier allows local users to overwrite arbitrary files via a symlink attack in some configurations.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2184" source="BID" patch="1" adv="1">2184</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-003.php3" source="MANDRAKE" patch="1" adv="1">MDKSA-2001:003</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0212.html" source="BUGTRAQ" patch="1">20010112 Trustix Security Advisory - diffutils squid</ref>
      <ref url="http://xforce.iss.net/static/5921.php" source="XF">squid-email-symlink(5921)</ref>
      <ref url="http://www.debian.org/security/2001/dsa-019" source="DEBIAN">DSA-019</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97916374410647&amp;w=2" source="BUGTRAQ">20010110 Immunix OS Security update for lots of temp file problems</ref>
    </refs>
    <vuln_soft>
      <prod vendor="immunix" name="immunix">
        <vers num="7.0_beta" />
      </prod>
      <prod vendor="national_science_foundation" name="squid_web_proxy">
        <vers num="2.3_stable4" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.0" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="1.1" />
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0143" published="2001-03-12" name="CVE-2001-0143" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">vpop3d program in linuxconf 1.23r and earlier allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2186" source="BID" patch="1" adv="1">2186</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-011.php3" source="MANDRAKE" patch="1">MDKSA-2001:011</ref>
      <ref url="http://xforce.iss.net/static/5923.php" source="XF">linuxconf-vpop3d-symlink(5923)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97916374410647&amp;w=2" source="BUGTRAQ">20010110 Immunix OS Security update for lots of temp file problems</ref>
    </refs>
    <vuln_soft>
      <prod vendor="immunix" name="immunix">
        <vers num="7.0_beta" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0144" published="2001-03-12" name="CVE-2001-0144" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an integer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2001-35.html" source="CERT">CA-2001-35</ref>
      <ref url="http://www.securityfocus.com/bid/2347" source="BID" patch="1" adv="1">2347</ref>
      <ref url="http://razor.bindview.com/publish/advisories/adv_ssh1crc.html" source="BINDVIEW" patch="1" adv="1">20010208 Remote vulnerability in SSH daemon crc32 compensation attack detector</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98168366406903&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010208 [CORE SDI ADVISORY] SSH1 CRC-32 compensation attack detector</ref>
      <ref url="http://xforce.iss.net/static/6083.php" source="XF">ssh-deattack-overwrite-memory(6083)</ref>
      <ref url="http://www.osvdb.org/795" source="OSVDB">795</ref>
      <ref url="http://www.osvdb.org/503" source="OSVDB">503</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openssh">
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.2" />
      </prod>
      <prod vendor="ssh" name="ssh">
        <vers num="1.2.24" />
        <vers num="1.2.25" />
        <vers num="1.2.26" />
        <vers num="1.2.27" />
        <vers num="1.2.28" />
        <vers num="1.2.29" />
        <vers num="1.2.30" />
        <vers num="1.2.31" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0145" published="2001-05-03" name="CVE-2001-0145" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in VCard handler in Outlook 2000 and 98, and Outlook Express 5.x, allows an attacker to execute arbitrary commands via a malformed vCard birthday field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms01-012.asp" source="MS" patch="1" adv="1">MS01-012</ref>
      <ref url="http://www.atstake.com/research/advisories/2001/a022301-1.txt" source="ATSTAKE" patch="1" adv="1">A022301-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="outlook">
        <vers num="2000" />
        <vers num="98" />
      </prod>
      <prod vendor="microsoft" name="outlook_express">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0146" published="2001-06-02" name="CVE-2001-0146" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IIS 5.0 and Microsoft Exchange 2000 allow remote attackers to cause a denial of service (memory allocation error) by repeatedly sending a series of specially formatted URL's.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/796584" source="CERT-VN">VU#796584</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-014.asp" source="MS" patch="1" adv="1">MS01-014</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6172" source="XF">exchange-malformed-url-dos(6172)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6171" source="XF">iis-malformed-url-dos(6171)</ref>
      <ref url="http://www.securityfocus.com/bid/2441" source="BID">2441</ref>
      <ref url="http://www.securityfocus.com/bid/2440" source="BID">2440</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="2000" />
      </prod>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0147" published="2001-05-03" name="CVE-2001-0147" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Windows 2000 event viewer snap-in allows attackers to execute arbitrary commands via a malformed field that is improperly handled during the detailed view of event records.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-013.asp" source="MS" patch="1" adv="1">MS01-013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":professional" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0148" published="2001-06-02" name="CVE-2001-0148" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The WMP ActiveX Control in Windows Media Player 7 allows remote attackers to execute commands in Internet Explorer via javascript URLs, a variant of the "Frame Domain Verification" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-015.asp" source="MS" patch="1" adv="1">MS01-015</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0000.html" source="BUGTRAQ" patch="1" adv="1">20010101 Windows Media Player 7 and IE vulnerability - executing arbitrary programs</ref>
      <ref url="http://xforce.iss.net/static/6227.php" source="XF">media-player-execute-commands(6227)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_media_player">
        <vers num="7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0149" published="2001-06-02" name="CVE-2001-0149" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Windows Scripting Host in Internet Explorer 5.5 and earlier allows remote attackers to read arbitrary files via the GetObject Javascript function and the htmlfile ActiveX object.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-015.asp" source="MS" patch="1" adv="1">MS01-015</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=96999020527583&amp;w=2" source="NTBUGTRAQ" patch="1" adv="1">20000926 IE 5.5/Outlook Express security vulnerability - GetObject() expose user's files</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0305.html" source="BUGTRAQ" patch="1" adv="1">20000926 IE 5.5/Outlook Express security vulnerability - GetObject() expose user's files</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5293" source="XF">ie-getobject-expose-files(5293)</ref>
      <ref url="http://www.securityfocus.com/bid/1718" source="BID">1718</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers prev="1" num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0150" published="2001-06-02" name="CVE-2001-0150" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Internet Explorer 5.5 and earlier executes Telnet sessions using command line arguments that are specified by the web site, which could allow remote attackers to execute arbitrary commands if the IE client is using the Telnet client provided in Services for Unix (SFU) 2.0, which creates session transcripts.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-015.asp" source="MS" patch="1" adv="1">MS01-015</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6230" source="XF">ie-telnet-execute-commands(6230)</ref>
      <ref url="http://www.securityfocus.com/bid/2463" source="BID">2463</ref>
      <ref url="http://www.osvdb.org/7816" source="OSVDB">7816</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers prev="1" num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0151" published="2001-06-02" name="CVE-2001-0151" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IIS 5.0 allows remote attackers to cause a denial of service via a series of malformed WebDAV requests.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-016.asp" source="MS" patch="1" adv="1">MS01-016</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6205" source="XF">iis-webdav-dos(6205)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:90" source="OVAL" sig="1">oval:org.mitre.oval:def:90</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0152" published="2001-05-03" name="CVE-2001-0152" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The password protection option for the Compressed Folders feature in Plus! for Windows 98 and Windows Me writes password information to a file, which allows local users to recover the passwords and read the compressed folders.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms01-019.asp" source="MS" patch="1" adv="1">MS01-019</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="plus">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0153" published="2001-05-03" name="CVE-2001-0153" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in VB-TSQL debugger object (vbsdicli.exe) in Visual Studio 6.0 Enterprise Edition allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-018.asp" source="MS" patch="1" adv="1">MS01-018</ref>
      <ref url="http://razor.bindview.com/publish/advisories/adv_vbtsql.html" source="BINDVIEW" patch="1" adv="1">20010327 Remote buffer overflow in DCOM VB T-SQL debugger</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="visual_basic">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":enterprise" />
      </prod>
      <prod vendor="microsoft" name="visual_studio">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":enterprise" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0154" published="2001-05-03" name="CVE-2001-0154" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">HTML e-mail feature in Internet Explorer 5.5 and earlier allows attackers to execute attachments by setting an unusual MIME type for the attachment, which Internet Explorer does not process correctly.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2001-06.html" source="CERT">CA-2001-06</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-020.asp" source="MS" patch="1" adv="1">MS01-020</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98596775905044&amp;w=2" source="BUGTRAQ" adv="1">20010330 Incorrect MIME Header Can Cause IE to Execute E-mail Attachment</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6306" source="XF">ie-mime-execute-code(6306)</ref>
      <ref url="http://www.securityfocus.com/bid/2524" source="BID">2524</ref>
      <ref url="http://www.osvdb.org/7806" source="OSVDB">7806</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/l-066.shtml" source="CIAC">L-066</ref>
      <ref url="http://securitytracker.com/id?1001197" source="SECTRACK">1001197</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:141" source="OVAL" sig="1">oval:org.mitre.oval:def:141</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" />
        <vers prev="1" num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0155" published="2001-06-02" name="CVE-2001-0155" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in VShell SSH gateway 1.0.1 and earlier allows remote attackers to execute arbitrary commands via a user name that contains format string specifiers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vandyke.com/products/vshell/security102.html" source="CONFIRM">http://www.vandyke.com/products/vshell/security102.html</ref>
      <ref url="http://www.atstake.com/research/advisories/2001/a021601-1.txt" source="ATSTAKE">A021601-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="van_dyke_technologies" name="vshell">
        <vers prev="1" num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0156" published="2001-06-02" name="CVE-2001-0156" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">VShell SSH gateway 1.0.1 and earlier has a default port forwarding rule of 0.0.0.0/0.0.0.0, which could allow local users conduct arbitrary port forwarding to other systems.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.atstake.com/research/advisories/2001/a021601-1.txt" source="ATSTAKE" patch="1" adv="1">A021601-1</ref>
      <ref url="http://www.vandyke.com/products/vshell/security102.html" source="CONFIRM">http://www.vandyke.com/products/vshell/security102.html</ref>
      <ref url="http://xforce.iss.net/static/6148.php" source="XF">vshell-port-forwarding-rule(6148)</ref>
      <ref url="http://www.securityfocus.com/bid/2402" source="BID">2402</ref>
    </refs>
    <vuln_soft>
      <prod vendor="van_dyke_technologies" name="vshell">
        <vers num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0157" published="2001-06-02" name="CVE-2001-0157" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Debugging utility in the backdoor mode of Palm OS 3.5.2 and earlier allows attackers with physical access to a Palm device to bypass access restrictions and obtain passwords, even if the system lockout mechanism is enabled.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.atstake.com/research/advisories/2001/a030101-1.txt" source="ATSTAKE" patch="1" adv="1">A030101-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6196" source="XF">palm-debug-bypass-password(6196)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="palm" name="palm_os">
        <vers num="3.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0160" published="2001-01-01" name="CVE-2001-0160" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Lucent/ORiNOCO WaveLAN cards generate predictable Initialization Vector (IV) values for the Wireless Encryption Protocol (WEP) which allows remote attackers to quickly compile information that will let them decrypt messages.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cs.jhu.edu/~seny/pubs/wince802.pdf" source="MISC" adv="1">http://www.cs.jhu.edu/~seny/pubs/wince802.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lucent" name="wavelan">
        <vers num="" />
      </prod>
      <prod vendor="orinoco" name="orinoco_wavelan">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0161" published="2001-01-01" name="CVE-2001-0161" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco 340-series Aironet access point using firmware 11.01 does not use 6 of the 24 available IV bits for WEP encryption, which makes it easier for remote attackers to mount brute force attacks.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cs.jhu.edu/~seny/pubs/wince802.pdf" source="MISC" adv="1">http://www.cs.jhu.edu/~seny/pubs/wince802.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="aironet">
        <vers num="340-series" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0162" published="2001-01-01" name="CVE-2001-0162" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">WinCE 3.0.9348 generates predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cs.jhu.edu/~seny/pubs/wince802.pdf" source="MISC" adv="1">http://www.cs.jhu.edu/~seny/pubs/wince802.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_ce">
        <vers num="3.0.9348" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0163" published="2001-01-01" name="CVE-2001-0163" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Cisco AP340 base station produces predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cs.jhu.edu/~seny/pubs/wince802.pdf" source="MISC" adv="1">http://www.cs.jhu.edu/~seny/pubs/wince802.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="aironet_ap340">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0164" published="2001-06-02" name="CVE-2001-0164" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Netscape Directory Server 4.12 and earlier allows remote attackers to cause a denial of service or execute arbitrary commands via a malformed recipient field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.atstake.com/research/advisories/2001/a030701-1.txt" source="ATSTAKE" patch="1" adv="1">A030701-1</ref>
      <ref url="http://xforce.iss.net/static/6233.php" source="XF">netscape-directory-server-bo(6233)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="directory_server">
        <vers prev="1" num="4.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0165" published="2001-05-03" name="CVE-2001-0165" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in ximp40 shared library in Solaris 7 and Solaris 8 allows local users to gain privileges via a long "arg0" (process name) argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6039.php" source="XF" adv="1">solaris-ximp40-bo</ref>
      <ref url="http://www.securityfocus.com/bid/2322" source="BID" adv="1">2322</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0517.html" source="BUGTRAQ" adv="1">20010131 [SPSadvisory#40]Solaris7/8 ximp40 shared library buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0166" published="2001-03-26" name="CVE-2001-0166" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Macromedia Shockwave Flash plugin version 8 and earlier allows remote attackers to cause a denial of service via malformed tag length specifiers in a SWF file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5826.php" source="XF" adv="1">shockwave-flash-swf-bo</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0491.html" source="BUGTRAQ" adv="1">20001229 Shockwave Flash buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macromedia" name="shockwave_flash_plugin">
        <vers prev="1" num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0167" published="2001-05-03" name="CVE-2001-0167" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Buffer overflow in AT&amp;T WinVNC (Virtual Network Computing) client 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long rfbConnFailed packet with a long reason string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6025.php" source="XF" patch="1" adv="1">winvnc-client-bo</ref>
      <ref url="http://www.securityfocus.com/bid/2305" source="BID" patch="1" adv="1">2305</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98088315825366&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010129 [CORE SDI ADVISORY] WinVNC client buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="att" name="winvnc">
        <vers prev="1" num="3.3.3r7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0168" published="2001-05-03" name="CVE-2001-0168" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in AT&amp;T WinVNC (Virtual Network Computing) server 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long HTTP GET request when the DebugLevel registry key is greater than 0.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/598581" source="CERT-VN">VU#598581</ref>
      <ref url="http://www.securityfocus.com/bid/2306" source="BID" patch="1" adv="1">2306</ref>
      <ref url="http://marc.theaimsgroup.com/?l=vnc-list&amp;m=98080763005455&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010129 [CORE SDI ADVISORY] WinVNC server buffer overflow</ref>
      <ref url="http://xforce.iss.net/static/6026.php" source="XF" adv="1">winvnc-server-bo(6026)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="att" name="winvnc">
        <vers prev="1" num="3.3.3r7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0169" published="2001-03-26" name="CVE-2001-0169" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to overwrite arbitrary files by loading a library from /lib or /usr/lib.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2223" source="BID" patch="1" adv="1">2223</ref>
      <ref url="http://www.securityfocus.com/archive/1/157650" source="BUGTRAQ" patch="1">20010121 Trustix Security Advisory - glibc</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-002.html" source="REDHAT" patch="1" adv="1">RHSA-2001:002</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-012.php3?dis=7.2" source="MANDRAKE" patch="1" adv="1">MDKSA-2001:012</ref>
      <ref url="http://xforce.iss.net/static/5971.php" source="XF" adv="1">linux-glibc-preload-overwrite</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2001_001_glibc_txt.html" source="SUSE">SuSE-SA:2001:01</ref>
      <ref url="http://www.debian.org/security/2001/dsa-039" source="DEBIAN">DSA-039</ref>
      <ref url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-007.0.txt" source="CALDERA">CSSA-2001-007</ref>
      <ref url="http://archives.neohapsis.com/archives/linux/turbolinux/2001-q1/0004.html" source="TURBO">TLSA2000021-2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="1.0.1" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":i386" />
        <vers num="6.0" edition=":alpha" />
        <vers num="6.0" edition=":sparc" />
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":i386" />
        <vers num="6.1" edition=":alpha" />
        <vers num="6.1" edition=":sparc" />
        <vers num="6.2" edition="" />
        <vers num="6.2" edition=":alpha" />
        <vers num="6.2" edition=":sparc" />
        <vers num="6.2" edition=":i386" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="1.1" />
        <vers num="1.2" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux">
        <vers prev="1" num="6.0.5" />
        <vers num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0170" published="2001-03-26" name="CVE-2001-0170" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">glibc 2.1.9x and earlier does not properly clear the RESOLV_HOST_CONF, HOSTALIASES, or RES_OPTIONS environmental variables when executing setuid/setgid programs, which could allow local users to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2181" source="BID" patch="1" adv="1">2181</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-001.html" source="REDHAT" patch="1" adv="1">RHSA-2001:001</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0186.html" source="BUGTRAQ" patch="1" adv="1">20010110 [slackware-security] glibc 2.2 local vulnerability on setuid binaries</ref>
      <ref url="http://xforce.iss.net/static/5907.php" source="XF" adv="1">linux-glibc-read-files</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0131.html" source="BUGTRAQ" adv="1">20010110 Glibc Local Root Exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="immunix" name="immunix">
        <vers num="7.0_beta" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="4.0" />
        <vers num="4.0es" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="6.0" />
        <vers num="ecommerce" />
        <vers num="graficas" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.3" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":i386" />
        <vers num="7.0" edition=":alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0171" published="2001-05-03" name="CVE-2001-0171" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in SlimServe HTTPd 1.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6028.php" source="XF" adv="1">slimserve-httpd-dos</ref>
      <ref url="http://www.securityfocus.com/bid/2318" source="BID" adv="1">2318</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0505.html" source="BUGTRAQ" adv="1">20010130 DOS Vulnerability in SlimServe HTTPd </ref>
    </refs>
    <vuln_soft>
      <prod vendor="whitsoft" name="slimserve">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0172" published="2001-03-26" name="CVE-2001-0172" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in ReiserFS 3.5.28 in SuSE Linux allows local users to cause a denial of service and possibly execute arbitrary commands by via a long directory name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5910.php" source="XF" adv="1">suse-reiserfs-long-filenames</ref>
      <ref url="http://www.securityfocus.com/bid/2180" source="BID" adv="1">2180</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0127.html" source="BUGTRAQ" adv="1">20010109 major security bug in reiserfs (may affect SuSE Linux)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hans_reiser" name="reiserfs">
        <vers num="3.5.28" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0173" published="2001-05-03" name="CVE-2001-0173" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in qDecoder library 5.08 and earlier, as used in CrazyWWWBoard, CrazySearch, and other CGI programs, allows remote attackers to execute arbitrary commands via a long MIME Content-Type header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2329" source="BID" patch="1" adv="1">2329</ref>
      <ref url="http://xforce.iss.net/static/6033.php" source="XF" adv="1">crazywwwboard-qdecoder-bo</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0486.html" source="BUGTRAQ" adv="1">20010130 Nobreak Tecnologies CrazyWWWBoard Remote Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nobreak_technologies" name="crazywwwboard">
        <vers num="2000.0lepx" />
        <vers num="2000.0px" />
        <vers num="2000lepx" />
        <vers num="2000px" />
        <vers num="3.0.1" />
        <vers num="98" />
        <vers num="98pe" />
      </prod>
      <prod vendor="qdecoder" name="qdecoder">
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0174" published="2001-05-03" name="CVE-2001-0174" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Buffer overflow in Trend Micro Virus Buster 2001 8.00 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a large "To" address.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6034.php" source="XF" adv="1">virusbuster-mua-bo(6034)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0500.html" source="BUGTRAQ" adv="1">20010130 Security hole in Virus Buster 2001</ref>
      <ref url="http://www.osvdb.org/6138" source="OSVDB">6138</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="virus_buster_2001">
        <vers prev="1" num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0175" published="2001-03-26" name="CVE-2001-0175" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The caching module in Netscape Fasttrack Server 4.1 allows remote attackers to cause a denial of service (resource exhaustion) by requesting a large number of non-existent URLs.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5985.php" source="XF" adv="1">netscape-fasttrack-cache-dos(5985)</ref>
      <ref url="http://www.securityfocus.com/bid/2273" source="BID" adv="1">2273</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98035833331446&amp;w=2" source="BUGTRAQ" adv="1">20010124 iPlanet FastTrack/Enterprise 4.1 DoS clarifications</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98021351718874&amp;w=2" source="BUGTRAQ" adv="1">20010122 def-2001-05: Netscape Fasttrack Server Caching DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="fasttrack_server">
        <vers num="4.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0176" published="2001-03-26" name="CVE-2001-0176" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The setuid doroot program in Voyant Sonata 3.x executes arbitrary command line arguments, which allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2125" source="BID" adv="1">2125</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0278.html" source="BUGTRAQ" adv="1">20001218 More Sonata Conferencing software vulnerabilities.</ref>
      <ref url="http://xforce.iss.net/static/5787.php" source="XF">sonata-command-execute(5787)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="voyant_technologies" name="sonata">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0177" published="2001-03-26" name="CVE-2001-0177" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WebMaster ConferenceRoom 1.8.1 allows remote attackers to cause a denial of service via a buddy relationship between the IRC server and a server clone.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2178" source="BID" patch="1" adv="1">2178</ref>
      <ref url="http://xforce.iss.net/static/5909.php" source="XF" adv="1">conferenceroom-developer-dos</ref>
      <ref url="http://www.securityfocus.com/archive/1/155388" source="BUGTRAQ" adv="1">20010110 Vulnerable: Conference Room Professional-Developer Edititon.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webmaster" name="conferenceroom">
        <vers num="1.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0178" published="2001-03-26" name="CVE-2001-0178" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">kdesu program in KDE2 (KDE before 2.2.0-6) does not properly verify the owner of a UNIX socket that is used to send a password, which allows local users to steal passwords and gain privileges.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-018.php3?dis=7.2" source="MANDRAKE" patch="1" adv="1">MDKSA-2001:018</ref>
      <ref url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-005.0.txt" source="CALDERA" patch="1" adv="1">CSSA-2001-005.0</ref>
      <ref url="http://xforce.iss.net/static/5995.php" source="XF" adv="1">kde2-kdesu-retrieve-passwords</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2001_002_kdesu_txt.html" source="SUSE">SuSE-SA:2001:02</ref>
    </refs>
    <vuln_soft>
      <prod vendor="caldera" name="openlinux_edesktop">
        <vers num="2.4" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="6.0" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="6.1" />
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="1.0.1" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0179" published="2001-05-03" name="CVE-2001-0179" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Allaire JRun 3.0 allows remote attackers to list contents of the WEB-INF directory, and the web.xml file in the WEB-INF directory, via a malformed URL that contains a "."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.allaire.com/handlers/index.cfm?ID=19546&amp;Method=Full" source="ALLAIRE" patch="1" adv="1">ASB01-02</ref>
      <ref url="http://xforce.iss.net/static/6008.php" source="XF" adv="1">jrun-webinf-file-retrieval</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macromedia" name="jrun">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0180" published="2001-05-03" name="CVE-2001-0180" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Lars Ellingsen guestserver.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the "email" parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6027.php" source="XF" patch="1" adv="1">guestserver-cgi-execute-commands</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0471.html" source="BUGTRAQ" patch="1" adv="1">20010129 Remote Command Execution in guestserver.cgi + exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lars_ellingsen" name="guestserver">
        <vers prev="1" num="4.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0181" published="2001-03-26" name="CVE-2001-0181" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in the error logging code of DHCP server and client in Caldera Linux allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2215" source="BID" patch="1" adv="1">2215</ref>
      <ref url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-003.0.txt" source="CALDERA" patch="1" adv="1">CSSA-2001-003.0</ref>
      <ref url="http://xforce.iss.net/static/5953.php" source="XF" adv="1">dhcp-format-string</ref>
    </refs>
    <vuln_soft>
      <prod vendor="caldera" name="openlinux_desktop">
        <vers num="2.3" />
      </prod>
      <prod vendor="caldera" name="openlinux_edesktop">
        <vers num="2.4" />
      </prod>
      <prod vendor="caldera" name="openlinux_eserver">
        <vers num="2.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0182" published="2001-03-26" name="CVE-2001-0182" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">FireWall-1 4.1 with a limited-IP license allows remote attackers to cause a denial of service by sending a large number of spoofed IP packets with various source addresses to the inside interface, which floods the console with warning messages and consumes CPU resources.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2238" source="BID" patch="1" adv="1">2238</ref>
      <ref url="http://xforce.iss.net/static/5966.php" source="XF" adv="1">fw1-limited-license-dos</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0298.html" source="BUGTRAQ" adv="1">20010117 Licensing Firewall-1 DoS Attack</ref>
      <ref url="http://www.osvdb.org/1733" source="OSVDB">1733</ref>
    </refs>
    <vuln_soft>
      <prod vendor="checkpoint" name="firewall-1">
        <vers num="4.1" edition="sp2" />
        <vers num="4.1" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0183" published="2001-03-26" name="CVE-2001-0183" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">ipfw and ip6fw in FreeBSD 4.2 and earlier allows remote attackers to bypass access restrictions by setting the ECE flag in a TCP packet, which makes the packet appear to be part of an established connection.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2293" source="BID" patch="1" adv="1">2293</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:08.ipfw.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-01:08</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5998" source="XF">ipfw-bypass-firewall(5998)</ref>
      <ref url="http://www.security-express.com/archives/bugtraq/2001-01/0424.html" source="BUGTRAQ">20010125 ecepass - proof of concept code for FreeBSD ipfw bypass</ref>
      <ref url="http://www.osvdb.org/1743" source="OSVDB">1743</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/l-029.shtml" source="CIAC">L-029</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="3.5" />
        <vers num="3.5.1" />
        <vers num="4.0" edition="alpha" />
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0184" published="2001-03-26" name="CVE-2001-0184" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">eEye Iris 1.01 beta allows remote attackers to cause a denial of service via a malformed packet, which causes Iris to crash when a user views the packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5981.php" source="XF" adv="1">eeye-iris-dos</ref>
      <ref url="http://www.securityfocus.com/bid/2278" source="BID" adv="1">2278</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0352.html" source="BUGTRAQ" adv="1">20010121 eEye Iris the Network traffic analyser DoS</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0343.html" source="BUGTRAQ">20010121 eEye Iris the Network traffic analyser DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eeye_digital_security" name="iris">
        <vers num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0185" published="2001-03-26" name="CVE-2001-0185" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Netopia R9100 router version 4.6 allows authenticated users to cause a denial of service by using the router's telnet program to connect to the router's IP address, which causes a crash.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2287" source="BID" patch="1" adv="1">2287</ref>
      <ref url="http://xforce.iss.net/static/6001.php" source="XF" adv="1">netopia-telnet-dos</ref>
      <ref url="http://www.securityfocus.com/archive/1/157952" source="BUGTRAQ" adv="1">20010123 Make The Netopia R9100 Router To Crash</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netopia" name="r9100_router">
        <vers prev="1" num="4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0186" published="2001-05-03" name="CVE-2001-0186" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Free Java Web Server 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0061.html" source="BUGTRAQ" adv="1">20010204 Vulnerability in Free Java Web Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="free_java_web_server" name="free_java_web_server">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0187" published="2001-03-26" name="CVE-2001-0187" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in wu-ftp 2.6.1 and earlier, when running with debug mode enabled, allows remote attackers to execute arbitrary commands via a malformed argument that is recorded in a PASV port assignment.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2296" source="BID" patch="1" adv="1">2296</ref>
      <ref url="http://www.debian.org/security/2001/dsa-016" source="DEBIAN" patch="1" adv="1">DSA-016</ref>
      <ref url="http://xforce.iss.net/static/6020.php" source="XF" adv="1">wuftp-debug-format-string</ref>
      <ref url="ftp://ftp.wu-ftpd.org/pub/wu-ftpd/patches/apply_to_current/missing_format_strings.patch" source="CONFIRM">ftp://ftp.wu-ftpd.org/pub/wu-ftpd/patches/apply_to_current/missing_format_strings.patch</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000443" source="CONECTIVA">CLA-2001:443</ref>
    </refs>
    <vuln_soft>
      <prod vendor="washington_university" name="wu-ftpd">
        <vers num="2.4.1" />
        <vers num="2.4.2_beta18" edition="" />
        <vers num="2.4.2_beta18" edition=":academ" />
        <vers num="2.4.2_beta18_vr10" />
        <vers num="2.4.2_beta18_vr11" />
        <vers num="2.4.2_beta18_vr12" />
        <vers num="2.4.2_beta18_vr13" />
        <vers num="2.4.2_beta18_vr14" />
        <vers num="2.4.2_beta18_vr15" />
        <vers num="2.4.2_beta18_vr4" />
        <vers num="2.4.2_beta18_vr5" />
        <vers num="2.4.2_beta18_vr6" />
        <vers num="2.4.2_beta18_vr7" />
        <vers num="2.4.2_beta18_vr8" />
        <vers num="2.4.2_beta18_vr9" />
        <vers num="2.4.2_beta9" edition="" />
        <vers num="2.4.2_beta9" edition=":academ" />
        <vers num="2.4.2_vr16" />
        <vers num="2.4.2_vr17" />
        <vers num="2.5" />
        <vers num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0188" published="2001-03-26" name="CVE-2001-0188" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">GoodTech FTP server 3.0.1.2.1.0 and earlier allows remote attackers to cause a denial of service via a flood of connections to the server, which causes it to crash.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2270" source="BID" patch="1" adv="1">2270</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0350.html" source="BUGTRAQ" patch="1" adv="1">20010122 def-2001-03: GoodTech Systems FTP Connection DoS</ref>
      <ref url="http://xforce.iss.net/static/5984.php" source="XF" adv="1">goodtech-ftp-dos</ref>
    </refs>
    <vuln_soft>
      <prod vendor="goodtech" name="ftp_server_95_98">
        <vers num="3.0.1" />
      </prod>
      <prod vendor="goodtech" name="ftp_server_nt_2000">
        <vers num="3.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0189" published="2001-03-26" name="CVE-2001-0189" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in LocalWEB2000 HTTP server allows remote attackers to read arbitrary commands via a .. (dot dot) attack in an HTTP GET request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5982.php" source="XF" adv="1">localweb2k-directory-traversal</ref>
      <ref url="http://www.securityfocus.com/bid/2268" source="BID" adv="1">2268</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0346.html" source="BUGTRAQ" adv="1">20010119 LocalWEB2000 Directory Traversal Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intranet-server" name="localweb2000">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0190" published="2001-03-26" name="CVE-2001-0190" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in /usr/bin/cu in Solaris 2.8 and earlier, and possibly other operating systems, allows local users to gain privileges by executing cu with a long program name (arg0).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98028642319440&amp;w=2" source="BUGTRAQ" patch="1">20010123 Solaris /usr/bin/cu Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97983943716311&amp;w=2" source="BUGTRAQ" adv="1">20010117 Solaris /usr/bin/cu Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6224" source="XF">cu-argv-bo(6224)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.5.1" />
        <vers num="2.6" />
        <vers num="2.7" />
        <vers prev="1" num="2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0191" published="2001-05-03" name="CVE-2001-0191" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">gnuserv before 3.12, as shipped with XEmacs, does not properly check the specified length of an X Windows MIT-MAGIC-COOKIE cookie, which allows remote attackers to execute arbitrary commands via a buffer overflow, or brute force authentication by using a short cookie length.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-011.html" source="REDHAT" patch="1">RHSA-2001:011</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-010.html" source="REDHAT" patch="1">RHSA-2001:010</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-019.php3" source="MANDRAKE" patch="1">MDKSA-2001:019</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0030.html" source="BUGTRAQ" patch="1" adv="1">20010202 Remote vulnerability in gnuserv/XEmacs</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6056" source="XF">gnuserv-tcp-cookie-overflow(6056)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="andy_norman" name="gnuserv">
        <vers prev="1" num="3.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0192" published="2001-05-03" name="CVE-2001-0192" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflows in CTRLServer in XMail allows attackers to execute arbitrary commands via the cfgfileget or domaindel functions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xmailserver.org/XMail-Readme.txt" source="CONFIRM">http://xmailserver.org/XMail-Readme.txt</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0047.html" source="BUGTRAQ">20010201 XMail CTRLServer remote buffer overflow vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="davide_libenzi" name="xmail">
        <vers prev="1" num="0.66" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0193" published="2001-05-03" name="CVE-2001-0193" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in man in some Linux distributions allows local users to gain privileges via a malformed -l parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2327" source="BID" patch="1" adv="1">2327</ref>
      <ref url="http://www.debian.org/security/2001/dsa-028" source="DEBIAN" patch="1" adv="1">DSA-028</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98096782126481&amp;w=2" source="BUGTRAQ" adv="1">20010131 SuSe / Debian man package format string vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6059" source="XF">man-i-format-string(6059)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.2" edition="" />
        <vers num="2.2" edition=":powerpc" />
        <vers num="2.2" edition=":arm" />
        <vers num="2.2" edition=":68k" />
        <vers num="2.2" edition=":sparc" />
        <vers num="2.2" edition=":alpha" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="6.3" />
        <vers num="6.4" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0194" published="2001-05-03" name="CVE-2001-0194" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in httpGets function in CUPS 1.1.5 allows remote attackers to execute arbitrary commands via a long input line.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-020.php3" source="MANDRAKE" patch="1" adv="1">MDKSA-2001:020-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6043" source="XF">cups-httpgets-dos(6043)</ref>
      <ref url="http://www.osvdb.org/6064" source="OSVDB">6064</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easy_software_products" name="cups">
        <vers prev="1" num="1.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0195" published="2001-03-26" name="CVE-2001-0195" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">sash before 3.4-4 in Debian GNU/Linux does not properly clone /etc/shadow, which makes it world-readable and could allow local users to gain privileges via password cracking.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5994.php" source="XF" patch="1" adv="1">linux-sash-shadow-readable</ref>
      <ref url="http://www.debian.org/security/2001/dsa-015" source="DEBIAN" patch="1" adv="1">DSA-015</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0196" published="2001-05-03" name="CVE-2001-0196" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">inetd ident server in FreeBSD 4.x and earlier does not properly set group permissions, which allows remote attackers to read the first 16 bytes of files that are accessible by the wheel group.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2324" source="BID" patch="1" adv="1">2324</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:11.inetd.v1.1.asc" source="FREEBSD">FreeBSD-SA-01:11</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6052" source="XF">inetd-ident-read-files(6052)</ref>
      <ref url="http://www.osvdb.org/1753" source="OSVDB">1753</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.5" />
        <vers num="3.5.1" />
        <vers num="4.1.1" />
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0197" published="2001-03-26" name="CVE-2001-0197" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in print_client in icecast 1.3.8beta2 and earlier allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2264" source="BID" patch="1" adv="1">2264</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-004.html" source="REDHAT" patch="1">RHSA-2001:004</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000374" source="CONECTIVA" patch="1">CLA-2001:374</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0348.html" source="BUGTRAQ" patch="1" adv="1">20010121 [pkc] format bugs in icecast 1.3.8b2 and prior</ref>
      <ref url="http://xforce.iss.net/static/5978.php" source="XF" adv="1">icecast-format-string</ref>
    </refs>
    <vuln_soft>
      <prod vendor="icecast" name="icecast">
        <vers num="1.3.7" />
        <vers prev="1" num="1.3.8_beta2" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0198" published="2001-05-03" name="CVE-2001-0198" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Buffer overflow in QuickTime Player plugin 4.1.2 (Japanese) allows remote attackers to execute arbitrary commands via a long HREF parameter in an EMBED tag.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6040.php" source="XF" adv="1">quicktime-embedded-tag-bo</ref>
      <ref url="http://www.securityfocus.com/bid/2328" source="BID" adv="1">2328</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98096678523370&amp;w=2" source="BUGTRAQ" adv="1">20010131 [SPSadvisory#41]Apple Quick Time Plug-in Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="4.1.2" edition="" />
        <vers num="4.1.2" edition=":" />
        <vers num="4.1.2" edition="::japanese" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0199" published="2001-05-03" name="CVE-2001-0199" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in SEDUM HTTP Server 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack in the HTTP GET request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/651994" source="CERT-VN">VU#651994</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6063" source="XF">sedum-directory-traversal(6063)</ref>
      <ref url="http://www.securityfocus.com/bid/2335" source="BID" adv="1">2335</ref>
      <ref url="http://www.osvdb.org/14797" source="OSVDB">14797</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0064.html" source="BUGTRAQ" adv="1">20010204 Vulnerability in SEDUM HTTP Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="guido_frassetto" name="sedum">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0200" published="2001-05-03" name="CVE-2001-0200" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">HSWeb 2.0 HTTP server allows remote attackers to obtain the physical path of the server via a request to the /cgi/ directory, which will list the path if directory browsing is enabled.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2336" source="BID" adv="1">2336</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0052.html" source="BUGTRAQ" adv="1">20010204 Web root exposure in HSWeb Webserver</ref>
    </refs>
    <vuln_soft>
      <prod vendor="heat-on_software" name="hsweb">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0201" published="2001-03-26" name="CVE-2001-0201" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Postaci frontend for PostgreSQL does not properly filter characters such as semicolons, which could allow remote attackers to execute arbitrary SQL queries via the deletecontact.php program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/5972" source="XF">postaci-sql-command-injection</ref>
      <ref url="http://www.securityfocus.com/bid/2230" source="BID" adv="1">2230</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0287.html" source="BUGTRAQ" adv="1">20010117 Postaci allows arbitrary SQL query execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="umut_gokbayrak" name="postaci">
        <vers num="1.1.2" />
        <vers num="1.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0202" published="2001-05-03" name="CVE-2001-0202" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Picserver web server allows remote attackers to read arbitrary files via a .. (dot dot) attack in an HTTP GET request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2339" source="BID" adv="1">2339</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0073.html" source="BUGTRAQ" adv="1">20010205 Vulnerability in Picserver</ref>
    </refs>
    <vuln_soft>
      <prod vendor="informs" name="picserver">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0203" published="2001-03-26" name="CVE-2001-0203" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Watchguard Firebox II firewall allows users with read-only access to gain read-write access, and administrative privileges, by accessing a file that contains hashed passphrases, and using the hashes during authentication.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2284" source="BID" patch="1" adv="1">2284</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0342.html" source="BUGTRAQ" patch="1" adv="1">20010120 Watchguard Firewall Elevated Privilege Vulnerability</ref>
      <ref url="http://xforce.iss.net/static/5979.php" source="XF" adv="1">watchguard-firebox-obtain-passphrase</ref>
    </refs>
    <vuln_soft>
      <prod vendor="watchguard" name="firebox_ii">
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="4.3" />
        <vers num="4.4" />
        <vers num="4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0204" published="2001-06-02" name="CVE-2001-0204" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Watchguard Firebox II allows remote attackers to cause a denial of service by establishing multiple connections and sending malformed PPTP packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2369" source="BID" patch="1" adv="1">2369</ref>
      <ref url="http://www.securityfocus.com/archive/1/162965" source="BUGTRAQ" patch="1" adv="1">20010214 def-2001-07: Watchguard Firebox II PPTP DoS</ref>
      <ref url="http://xforce.iss.net/static/6109.php" source="XF">firebox-pptp-dos(6109)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="watchguard" name="firebox_ii">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0205" published="2001-05-03" name="CVE-2001-0205" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in AOLserver 3.2 and earlier allows remote attackers to read arbitrary files by inserting "..." into the requested pathname, a modified .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2343" source="BID" adv="1">2343</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98168216003867&amp;w=2" source="BUGTRAQ" adv="1">20010208 Vulnerability in AOLserver</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98148759123258&amp;w=2" source="BUGTRAQ" adv="1">20010206 Vulnerability in AOLserver</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aol" name="aol_server">
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0206" published="2001-06-02" name="CVE-2001-0206" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Soft Lite ServerWorx 3.00 allows remote attackers to read arbitrary files by inserting a .. (dot dot) or ... into the requested pathname of an HTTP GET request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0137.html" source="BUGTRAQ" patch="1" adv="1">20010207 Vulnerability in Soft Lite ServerWorx</ref>
      <ref url="http://www.securityfocus.com/bid/2346" source="BID" adv="1">2346</ref>
    </refs>
    <vuln_soft>
      <prod vendor="soft_lite" name="serverworx">
        <vers num="3.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0207" published="2001-03-26" name="CVE-2001-0207" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in bing allows remote attackers to execute arbitrary commands via a long hostname, which is copied to a small buffer after a reverse DNS lookup using the gethostbyaddr function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2279" source="BID" patch="1" adv="1">2279</ref>
      <ref url="http://xforce.iss.net/static/6036.php" source="XF" adv="1">linux-bing-bo</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0330.html" source="BUGTRAQ" adv="1">20010119 Buffer overflow in bing</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pierre_beyssac" name="bing">
        <vers prev="1" num="1.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0208" published="2001-06-02" name="CVE-2001-0208" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">MicroFocus Cobol 4.1, with the AppTrack feature enabled, installs the mfaslmf directory and the nolicense file with insecure permissions, which allows local users to gain privileges by modifying files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2359" source="BID" patch="1" adv="1">2359</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0205.html" source="BUGTRAQ" patch="1" adv="1">20010211 Security Hole in Microfocus Cobol</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microfocus" name="cobol">
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0209" published="2001-03-26" name="CVE-2001-0209" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Shoutcast Distributed Network Audio Server (DNAS) 1.7.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long description.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5965.php" source="XF" patch="1" adv="1">shoutcast-description-bo</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0305.html" source="BUGTRAQ">20010118 Shoutcast Server Buffer Crashes Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="shoutcast" name="dnas">
        <vers num="1.7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0210" published="2001-06-02" name="CVE-2001-0210" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in commerce.cgi CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack in the page parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/162259" source="BUGTRAQ" patch="1" adv="1">20010212 Commerce.cgi Directory Traversal</ref>
      <ref url="http://www.securityfocus.com/bid/2361" source="BID" adv="1">2361</ref>
    </refs>
    <vuln_soft>
      <prod vendor="carey_internet_service" name="commerce.cgi">
        <vers num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0211" published="2001-06-02" name="CVE-2001-0211" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in WebSPIRS 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the sp.nextform parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2362" source="BID" patch="1">2362</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0217.html" source="BUGTRAQ" adv="1">20010212 WebSPIRS CGI script "show files" Vulnerability.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="silverplatter" name="webspirs">
        <vers num="3.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0212" published="2001-06-02" name="CVE-2001-0212" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in HIS Auktion 1.62 allows remote attackers to read arbitrary files via a .. (dot dot) in the menue parameter, and possibly execute commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2367" source="BID" adv="1">2367</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0218.html" source="BUGTRAQ" adv="1">20010212 HIS Auktion 1.62: "show files" vulnerability and remote command execute.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="his" name="auktion">
        <vers num="1.62" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0213" published="2001-05-03" name="CVE-2001-0213" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in pi program in PlanetIntra 2.5 allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6002.php" source="XF" adv="1">planetintra-pi-bo</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0421.html" source="BUGTRAQ" adv="1">200101125 [SAFER] Security Bulletin 010125.EXP.1.12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="planet_intra" name="planet_intra">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0214" published="2001-06-02" name="CVE-2001-0214" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Way-board CGI program allows remote attackers to read arbitrary files by specifying the filename in the db parameter and terminating the filename with a null byte.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2370" source="BID" adv="1">2370</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0212.html" source="BUGTRAQ" adv="1">20010212 Way board: "show files" Vulnerability with null bite bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="way" name="way-board">
        <vers num="cgi" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0215" published="2001-06-02" name="CVE-2001-0215" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ROADS search.pl program allows remote attackers to read arbitrary files by specifying the file name in the form parameter and terminating the filename with a null byte.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2371" source="BID" patch="1" adv="1">2371</ref>
      <ref url="http://www.roads.lut.ac.uk/lists/open-roads/2001/02/0001.html" source="CONFIRM">http://www.roads.lut.ac.uk/lists/open-roads/2001/02/0001.html</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0213.html" source="BUGTRAQ" adv="1">20010212 ROADS search system "show files" Vulnerability with "null bite" bug</ref>
      <ref url="http://xforce.iss.net/static/6097.php" source="XF">roads-search-view-files(6097)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="martin_hamilton" name="roads">
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0216" published="2001-06-02" name="CVE-2001-0216" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PALS Library System pals-cgi program allows remote attackers to execute arbitrary commands via shell metacharacters in the documentName parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2372" source="BID" patch="1" adv="1">2372</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0220.html" source="BUGTRAQ" adv="1">20010212 PALS Library System "show files" Vulnerability and remote command execution</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6102" source="XF">webpals-library-cgi-url(6102)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mnscu_pals" name="webpals">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0217" published="2001-06-02" name="CVE-2001-0217" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in PALS Library System pals-cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the documentName parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2372" source="BID" patch="1" adv="1">2372</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0220.html" source="BUGTRAQ" adv="1">20010212 PALS Library System "show files" Vulnerability and remote command execution</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6102" source="XF">webpals-library-cgi-url(6102)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mnscu_pals" name="webpals">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0218" published="2001-05-03" name="CVE-2001-0218" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in mars_nwe 0.99.pl19 allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/freebsd/2001-02/0081.html" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-01:20</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0456.html" source="BUGTRAQ" patch="1">20010126 format string vulnerability in mars_nwe 0.99pl19</ref>
      <ref url="http://xforce.iss.net/static/6019.php" source="XF" adv="1">mars-nwe-format-string(6019)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="martin_stover" name="mars_nwe">
        <vers num="0.99_pl19" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0219" published="2001-03-26" name="CVE-2001-0219" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Vulnerability in Support Tools Manager (xstm,cstm,stm) in HP-UX 11.11 and earlier allows local users to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2239" source="BID" patch="1" adv="1">2239</ref>
      <ref url="http://archives.neohapsis.com/archives/hp/2001-q1/0016.html" source="HP" patch="1">HPSBUX0101-137</ref>
      <ref url="http://xforce.iss.net/static/5957.php" source="XF" adv="1">hp-stm-dos</ref>
      <ref url="http://www.osvdb.org/7030" source="OSVDB">7030</ref>
      <ref url="http://www.osvdb.org/7029" source="OSVDB">7029</ref>
      <ref url="http://www.osvdb.org/6991" source="OSVDB">6991</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.20" />
        <vers num="11.00" />
        <vers prev="1" num="11.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0220" published="2001-06-02" name="CVE-2001-0220" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in ja-elvis and ko-helvis ports of elvis allow local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/freebsd/2001-02/0082.html" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-01:21</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ja-elvis" name="ja-elvis">
        <vers prev="1" num="1.8.4_1" />
      </prod>
      <prod vendor="ko-helvis" name="ko-helvis">
        <vers prev="1" num="1.8h2_1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0221" published="2001-06-02" name="CVE-2001-0221" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in ja-xklock 2.7.1 and earlier allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/freebsd/2001-02/0079.html" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-01:19</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6073" source="XF">ja-xklock-bo(6073)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="ja-xklock">
        <vers prev="1" num="2.7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0222" published="2001-03-26" name="CVE-2001-0222" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">webmin 0.84 and earlier allows local users to overwrite and create arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-016.php3" source="MANDRAKE" patch="1">MDKSA-2001-016</ref>
      <ref url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-004.0.txt" source="CALDERA" patch="1" adv="1">CSSA-2001-004.0</ref>
      <ref url="http://xforce.iss.net/static/6011.php" source="XF" adv="1">linux-webmin-tmpfiles</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webmin" name="webmin">
        <vers num="0.83" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0223" published="2001-03-26" name="CVE-2001-0223" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in wwwwais allows remote attackers to execute arbitrary commands via a long QUERY_STRING (HTTP GET request).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5980.php" source="XF" adv="1">wwwwais-cgi-dos</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97984174724339&amp;w=2" source="BUGTRAQ">20010117 numerous holes</ref>
    </refs>
    <vuln_soft>
      <prod vendor="spawar.navy.mil" name="wwwwais.25.c">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0224" published="2001-06-02" name="CVE-2001-0224" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Muscat Empower CGI program allows remote attackers to obtain the absolute pathname of the server via an invalid request in the DB parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2374" source="BID" adv="1">2374</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0216.html" source="BUGTRAQ" adv="1">20010212 Vulnerability in Muscat Empower wich can print path to DB-dir.</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6093" source="XF">muskat-empower-url-dir(6093)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="brightstation" name="muscat_empower">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0225" published="2001-06-02" name="CVE-2001-0225" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">fortran math component in Infobot 0.44.5.3 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0127.html" source="BUGTRAQ" patch="1" adv="1">20010207 Infobot 0.44.5.3/below remotely vulnerable (also in FreeBSD ports tree)</ref>
      <ref url="http://www.securityfocus.com/bid/2349" source="BID" adv="1">2349</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lenzo" name="infobot">
        <vers num="0.44.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0226" published="2001-05-03" name="CVE-2001-0226" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in BiblioWeb web server 2.0 allows remote attackers tor ead arbitrary files via a .. (dot dot) or ... attack in an HTTP GET request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0075.html" source="BUGTRAQ" adv="1">20010205 Vulnerabilities in BiblioWeb Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="biblioscape" name="biblioweb_server">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0227" published="2001-05-03" name="CVE-2001-0227" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in BiblioWeb web server 2.0 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP GET request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0075.html" source="BUGTRAQ" adv="1">20010205 Vulnerabilities in BiblioWeb Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="biblioscape" name="biblioweb_server">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0228" published="2001-05-03" name="CVE-2001-0228" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in GoAhead web server 2.1 and earlier allows remote attackers to read arbitrary files via a .. attack in an HTTP GET request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0022.html" source="BUGTRAQ" patch="1" adv="1">20010202 GoAhead Web Server Directory Traversal Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="goahead_software" name="goahead_webserver">
        <vers num="v.2.0" />
        <vers num="v.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0229" published="2001-05-03" name="CVE-2001-0229" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Chili!Soft ASP for Linux before 3.6 does not properly set group privileges when running in inherited mode, which could allow attackers to gain privileges via malicious scripts.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0112.html" source="BUGTRAQ" adv="1">20010206 Security hole in ChiliSoft ASP on Linux.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="chilisoft">
        <vers prev="1" num="3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0230" published="2001-06-02" name="CVE-2001-0230" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in dc20ctrl before 0.4_1 in FreeBSD, and possibly other operating systems, allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/freebsd/2001-02/0083.html" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-01:22</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6077" source="XF">dc20ctrl-port-bo(6077)</ref>
      <ref url="http://www.osvdb.org/6081" source="OSVDB">6081</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers prev="1" num="0.4_1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0231" published="2001-03-26" name="CVE-2001-0231" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in newsdesk.cgi in News Desk 1.2 allows remote attackers to read arbitrary files via a .. in the "t" parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/496064" source="CERT-VN">VU#496064</ref>
      <ref url="http://xforce.iss.net/static/5898.php" source="XF" adv="1">newsdesk-cgi-read-files(5898)</ref>
      <ref url="http://www.securityfocus.com/bid/2172" source="BID" adv="1">2172</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0042.html" source="BUGTRAQ" adv="1">20010103 News Desk 1.2 CGI Vulnerbility</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibrow" name="news_desk">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0232" published="2001-03-26" name="CVE-2001-0232" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">newsdesk.cgi in News Desk 1.2 allows remote attackers to read arbitrary files via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0042.html" source="BUGTRAQ" adv="1">20010103 News Desk 1.2 CGI Vulnerbility</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibrow" name="news_desk">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0233" published="2001-03-26" name="CVE-2001-0233" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in micq client 0.4.6 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long Description field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-005.html" source="REDHAT" patch="1">RHSA-2001:005</ref>
      <ref url="http://www.debian.org/security/2001/dsa-012" source="DEBIAN" patch="1" adv="1">DSA-012</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0395.html" source="BUGTRAQ" patch="1" adv="1">20010124 patch Re: [PkC] Advisory #003: micq-0.4.6 remote buffer overflow</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:14.micq.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-01:14</ref>
      <ref url="http://xforce.iss.net/static/5962.php" source="XF" adv="1">micq-sprintf-remote-bo(5962)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0307.html" source="BUGTRAQ">20010118 [PkC] Advisory #003: micq-0.4.6 remote buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="matthew_smith" name="micq">
        <vers prev="1" num="0.4.6" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.2" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0234" published="2001-05-03" name="CVE-2001-0234" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">NewsDaemon before 0.21b allows remote attackers to execute arbitrary SQL queries and gain privileges via a malformed user_username parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0460.html" source="BUGTRAQ" patch="1" adv="1">20010126 NewsDaemon remote administrator access</ref>
      <ref url="http://xforce.iss.net/static/6010.php" source="XF" adv="1">newsdaemon-gain-admin-access</ref>
      <ref url="http://sourceforge.net/forum/forum.php?forum_id=60570" source="CONFIRM">http://sourceforge.net/forum/forum.php?forum_id=60570</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sourceforge" name="newsdaemon">
        <vers num="0.21b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0235" published="2001-03-26" name="CVE-2001-0235" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Vulnerability in crontab allows local users to read crontab files of other users by replacing the temporary file that is being edited while crontab is running.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2001/dsa-024" source="DEBIAN" patch="1" adv="1">DSA-024</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:09.crontab.v1.1.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-01:09</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6225" source="XF">crontab-read-files(6225)</ref>
      <ref url="http://www.securityfocus.com/bid/2332" source="BID">2332</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0236" published="2001-05-03" name="CVE-2001-0236" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Solaris snmpXdmid SNMP to DMI mapper daemon allows remote attackers to execute arbitrary commands via a long "indication" event.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2001-05.html" source="CERT" patch="1" adv="1">CA-2001-05</ref>
      <ref url="http://www.securityfocus.com/bid/2417" source="BID" adv="1">2417</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98462536724454&amp;w=2" source="BUGTRAQ" adv="1">20010314 Solaris /usr/lib/dmi/snmpXdmid vulnerability</ref>
      <ref url="http://xforce.iss.net/static/6245.php" source="XF">solaris-snmpxdmid-bo(6245)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/l-065.shtml" source="CIAC">L-065</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/207" source="SUN">00207</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0237" published="2001-06-27" name="CVE-2001-0237" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Memory leak in Microsoft 2000 domain controller allows remote attackers to cause a denial of service by repeatedly connecting to the Kerberos service and then disconnecting without sending any data.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms01-024.asp" source="MS" patch="1" adv="1">MS01-024</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98942093221908&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010509 def-2001-24: Windows 2000 Kerberos DoS</ref>
      <ref url="http://xforce.iss.net/static/6506.php" source="XF">win2k-kerberos-dos(6506)</ref>
      <ref url="http://www.securityfocus.com/bid/2707" source="BID">2707</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/l-079.shtml" source="CIAC">L-079</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":advanced_server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0238" published="2001-07-02" name="CVE-2001-0238" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Microsoft Data Access Component Internet Publishing Provider 8.103.2519.0 and earlier allows remote attackers to bypass Security Zone restrictions via WebDAV requests.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-022.asp" source="MS" patch="1" adv="1">MS01-022</ref>
      <ref url="http://xforce.iss.net/static/6405.php" source="XF">ms-dacipp-webdav-access(6405)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/l-074.shtml" source="CIAC">L-074</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_95">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0239" published="2001-07-02" name="CVE-2001-0239" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Microsoft Internet Security and Acceleration (ISA) Server 2000 Web Proxy allows remote attackers to cause a denial of service via a long web request with a specific type.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2600" source="BID" patch="1" adv="1">2600</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-021.asp" source="MS" patch="1" adv="1">MS01-021</ref>
      <ref url="http://www.securityfocus.com/archive/1/179986" source="BUGTRAQ" adv="1">20010427 Microsoft ISA Server Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/177160" source="BUGTRAQ" adv="1">20010417 [SX-20010320-2b] - Followup re. Microsoft ISA Server Denial of Service</ref>
      <ref url="http://www.securityfocus.com/archive/1/176912" source="BUGTRAQ" adv="1">20010416 [SX-20010320-2] - Microsoft ISA Server Denial of Service</ref>
      <ref url="http://xforce.iss.net/static/6383.php" source="XF">isa-web-proxy-dos(6383)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/l-073.shtml" source="CIAC">L-073</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="isa_server">
        <vers num="2000" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0240" published="2001-06-27" name="CVE-2001-0240" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Microsoft Word before Word 2002 allows attackers to automatically execute macros without warning the user via a Rich Text Format (RTF) document that links to a template with the embedded macro.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms01-028.asp" source="MS" patch="1" adv="1">MS01-028</ref>
      <ref url="http://xforce.iss.net/static/6571.php" source="XF">word-rtf-macro-execution(6571)</ref>
      <ref url="http://www.securityfocus.com/bid/2753" source="BID">2753</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="word">
        <vers num="2000" />
        <vers num="2001" edition="" />
        <vers num="2001" edition=":mac" />
        <vers num="97" />
        <vers num="98" edition="" />
        <vers num="98" edition=":mac" />
        <vers num="98" edition=":" />
        <vers num="98" edition="::japanese" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0241" published="2001-06-27" name="CVE-2001-0241" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Internet Printing ISAPI extension in Windows 2000 allows remote attackers to gain root privileges via a long print request that is passed to the extension through IIS 5.0.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2001-10.html" source="CERT">CA-2001-10</ref>
      <ref url="http://www.securityfocus.com/bid/2674" source="BID" patch="1" adv="1">2674</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms01-023.asp" source="MS" patch="1" adv="1">MS01-023</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98874912915948&amp;w=2" source="BUGTRAQ" adv="1">20010501 Windows 2000 IIS 5.0 Remote buffer overflow vulnerability (Remote SYSTEM Level Access)</ref>
      <ref url="http://xforce.iss.net/static/6485.php" source="XF">iis-isapi-printer-bo(6485)</ref>
      <ref url="http://www.osvdb.org/3323" source="OSVDB">3323</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1068" source="OVAL" sig="1">oval:org.mitre.oval:def:1068</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":server" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":professional" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0242" published="2001-06-27" name="CVE-2001-0242" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflows in Microsoft Windows Media Player 7 and earlier allow remote attackers to execute arbitrary commands via (1) a long version tag in an .ASX file, or (2) a long banner tag, a variant of the ".ASX Buffer Overrun" vulnerability as discussed in MS:MS00-090.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/187528" source="CERT-VN">VU#187528</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms01-029.asp" source="MS" patch="1" adv="1">MS01-029</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5574" source="XF">mediaplayer-asx-bo(5574)</ref>
      <ref url="http://www.securityfocus.com/bid/2686" source="BID">2686</ref>
      <ref url="http://www.securityfocus.com/bid/2677" source="BID" adv="1">2677</ref>
      <ref url="http://www.securityfocus.com/archive/1/183906" source="BUGTRAQ">20010506 Re: Microsoft Media Player ASX Parser buffer overflow vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/181419" source="BUGTRAQ">20010502 Microsoft Media Player ASX Parser buffer overflow vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_media_player">
        <vers num="6.3" />
        <vers num="6.4" />
        <vers num="7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0243" published="2001-06-27" name="CVE-2001-0243" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Windows Media Player 7 and earlier stores Internet shortcuts in a user's Temporary Files folder with a fixed filename instead of in the Internet Explorer cache, which causes the HTML in those shortcuts to run in the Local Computer Zone instead of the Internet Zone, which allows remote attackers to read certain files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms01-029.asp" source="MS" patch="1" adv="1">MS01-029</ref>
      <ref url="http://xforce.iss.net/static/6584.php" source="XF">mediaplayer-html-shortcut(6584)</ref>
      <ref url="http://www.securityfocus.com/bid/2765" source="BID">2765</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_media_player">
        <vers num="6.4" />
        <vers num="7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0244" published="2001-06-27" name="CVE-2001-0244" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Index Server 2.0 allows remote attackers to execute arbitrary commands via a long search parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms01-025.asp" source="MS" patch="1" adv="1">MS01-025</ref>
      <ref url="http://xforce.iss.net/static/6517.php" source="XF">winnt-indexserver-search-bo(6517)</ref>
      <ref url="http://www.securityfocus.com/bid/2709" source="BID">2709</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="index_server">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0245" published="2001-06-27" name="CVE-2001-0245" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Index Server 2.0 in Windows NT 4.0, and Indexing Service in Windows 2000, allows remote attackers to read server-side include files via a malformed search request, aka a new variant of the "Malformed Hit-Highlighting" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms01-025.asp" source="MS" patch="1" adv="1">MS01-025</ref>
      <ref url="http://xforce.iss.net/static/6518.php" source="XF">win-indexserver-view-files(6518)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="index_server">
        <vers num="2.0" />
      </prod>
      <prod vendor="microsoft" name="indexing_service">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0246" published="2001-06-27" name="CVE-2001-0246" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain, aka a variant of the "Frame Domain Verification" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-027.asp" source="MS" patch="1" adv="1">MS01-027</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" />
        <vers prev="1" num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0247" published="2001-06-18" name="CVE-2001-0247" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} sequence, as seen in (1) g_opendir, (2) g_lstat, (3) g_stat, and (4) the glob0 buffer as used in the glob functions glob2 and glob3.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2001-07.html" source="CERT" patch="1" adv="1">CA-2001-07</ref>
      <ref url="http://www.securityfocus.com/bid/2548" source="BID" patch="1" adv="1">2548</ref>
      <ref url="http://archives.neohapsis.com/archives/freebsd/2001-04/0466.html" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-01:33</ref>
      <ref url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-018.txt.asc" source="NETBSD" patch="1">NetBSD-SA2000-018</ref>
      <ref url="http://xforce.iss.net/static/6332.php" source="XF">ftp-glob-expansion(6332)</ref>
      <ref url="http://www.nai.com/research/covert/advisories/048.asp" source="NAI">20010409 Globbing Vulnerabilities in Multiple FTP Daemons</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20010802-01-P" source="SGI">20010802-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="5-1.2" />
        <vers num="5-1.2.1" />
        <vers num="5-1.2.2" />
        <vers num="5_1.1.1" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="2.2" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.8" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="3.5" />
        <vers num="3.5.1" />
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.2" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.2.1" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.5" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.6" />
        <vers num="2.7" />
        <vers num="2.8" />
      </prod>
      <prod vendor="sgi" name="irix">
        <vers num="6.1" />
        <vers num="6.5.1" />
        <vers num="6.5.10" />
        <vers num="6.5.11" />
        <vers num="6.5.2m" />
        <vers num="6.5.3" />
        <vers num="6.5.3f" />
        <vers num="6.5.3m" />
        <vers num="6.5.4" />
        <vers num="6.5.5" />
        <vers num="6.5.6" />
        <vers num="6.5.7" />
        <vers num="6.5.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0248" published="2001-06-18" name="CVE-2001-0248" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in FTP server in HPUX 11 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the STAT command, which uses glob to generate long strings.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2001-07.html" source="CERT" patch="1" adv="1">CA-2001-07</ref>
      <ref url="http://www.securityfocus.com/bid/2552" source="BID" patch="1" adv="1">2552</ref>
      <ref url="http://xforce.iss.net/static/6332.php" source="XF">ftp-glob-expansion(6332)</ref>
      <ref url="http://www.nai.com/research/covert/advisories/048.asp" source="NAI">20010409 Globbing Vulnerabilities in Multiple FTP Daemons</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.00" />
        <vers num="10.10" />
        <vers num="10.20" />
        <vers num="10.30" />
        <vers num="11.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0249" published="2001-06-18" name="CVE-2001-0249" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap overflow in FTP daemon in Solaris 8 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the LIST command, which uses glob to generate long strings.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2001-07.html" source="CERT" patch="1" adv="1">CA-2001-07</ref>
      <ref url="http://www.securityfocus.com/bid/2550" source="BID" patch="1" adv="1">2550</ref>
      <ref url="http://xforce.iss.net/static/6332.php" source="XF">ftp-glob-expansion(6332)</ref>
      <ref url="http://www.nai.com/research/covert/advisories/048.asp" source="NAI">20010409 Globbing Vulnerabilities in Multiple FTP Daemons</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.5.1" />
        <vers num="2.6" />
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0250" published="2001-06-02" name="CVE-2001-0250" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Web Publishing feature in Netscape Enterprise Server 4.x and earlier allows remote attackers to list arbitrary directories under the web server root via the INDEX command.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5997.php" source="XF" patch="1" adv="1">netscape-enterprise-list-directories</ref>
      <ref url="http://www.securityfocus.com/bid/2285" source="BID" patch="1" adv="1">2285</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0396.html" source="BUGTRAQ" patch="1" adv="1">20010124 [SAFER] Security Bulletin 010124.EXP.1.11</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="enterprise_server">
        <vers num="3.0" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0251" published="2001-06-02" name="CVE-2001-0251" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Web Publishing feature in Netscape Enterprise Server 3.x allows remote attackers to cause a denial of service via the REVLOG command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6003.php" source="XF" patch="1" adv="1">netscape-enterprise-revlog-dos</ref>
      <ref url="http://www.securityfocus.com/bid/2294" source="BID" patch="1" adv="1">2294</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0422.html" source="BUGTRAQ" patch="1" adv="1">20010125 [SAFER] Security Bulletin 010125.DOS.1.5</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="enterprise_server">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0252" published="2001-06-02" name="CVE-2001-0252" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">iPlanet (formerly Netscape) Enterprise Server 4.1 allows remote attackers to cause a denial of service via a long HTTP GET request that contains many "/../" (dot dot) sequences.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5983.php" source="XF" adv="1">netscape-enterprise-dot-dos</ref>
      <ref url="http://www.securityfocus.com/bid/2282" source="BID" adv="1">2282</ref>
      <ref url="http://www.securityfocus.com/archive/1/157641" source="BUGTRAQ" adv="1">20010122 def-2001-04: Netscape Enterprise Server Dot-DoS</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98035833331446&amp;w=2" source="BUGTRAQ" adv="1">20010124 iPlanet FastTrack/Enterprise 4.1 DoS clarifications</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iplanet" name="iplanet_enterprise_server">
        <vers num="4.1sp5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0253" published="2001-06-02" name="CVE-2001-0253" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in hsx.cgi program in iWeb Hyperseek 2000 allows remote attackers to read arbitrary files and directories via a .. (dot dot) attack in the show parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/146704" source="CERT-VN">VU#146704</ref>
      <ref url="http://www.securityfocus.com/bid/2314" source="BID" patch="1" adv="1">2314</ref>
      <ref url="http://xforce.iss.net/static/6012.php" source="XF" adv="1">hyperseek-cgi-reveal-info</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0463.html" source="BUGTRAQ" adv="1">20010128 Hyperseek 2000 Search Engine - "show directory &amp; files" bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iweb_systems" name="hyperseek">
        <vers num="2000" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0254" published="2001-06-02" name="CVE-2001-0254" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">FaSTream FTP++ Server 2.0 allows remote attackers to obtain the real pathname of the server via the "pwd" command.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98021181215325&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010119 Multiple Vulnerabilities In FaSTream FTP++ (+ ICS Tftpserver DoS)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fastream" name="ftp++_server">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0255" published="2001-06-02" name="CVE-2001-0255" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">FaSTream FTP++ Server 2.0 allows remote attackers to list arbitrary directories by using the "ls" command and including the drive letter name (e.g. C:) in the requested pathname.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5977.php" source="XF" patch="1" adv="1">fastream-ftp-path-disclosure</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98021181215325&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010119 Multiple Vulnerabilities In FaSTream FTP++ (+ ICS Tftpserver DoS)</ref>
      <ref url="http://www.securityfocus.com/bid/2267" source="BID" adv="1">2267</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fastream" name="fastream_ftp++_server">
        <vers num="2.0" />
      </prod>
      <prod vendor="fastream" name="fastream_ftp_server">
        <vers num="2.0beta_11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0256" published="2001-06-02" name="CVE-2001-0256" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">FaSTream FTP++ Server 2.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long username.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98021181215325&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010119 Multiple Vulnerabilities In FaSTream FTP++ (+ ICS Tftpserver DoS)</ref>
      <ref url="http://xforce.iss.net/static/5976.php" source="XF" adv="1">fastream-ftp-server-dos</ref>
      <ref url="http://www.securityfocus.com/bid/2261" source="BID" adv="1">2261</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fastream" name="ftp++_server">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0257" published="2001-06-02" name="CVE-2001-0257" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Easycom/Safecom Print Server Web service, version 404.590 and earlier, allows remote attackers to execute arbitrary commands via (1) a long URL or (2) a long HTTP header field such as "Host:".</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5988.php" source="XF" adv="1">easycom-safecom-url-bo</ref>
      <ref url="http://www.securityfocus.com/bid/2291" source="BID" adv="1">2291</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0375.html" source="BUGTRAQ" adv="1">20010123 def-2001-06: Easycom/Safecom 10/100 Multiple DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="i-data_international" name="easycom_safecom_print_server">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0258" published="2001-06-02" name="CVE-2001-0258" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Easycom/Safecom Print Server (firmware 404.590) PrintGuide server allows remote attackers to cause a denial of service via a large number of connections that send null characters.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5989.php" source="XF" adv="1">easycom-safecom-printguide-dos</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0375.html" source="BUGTRAQ" adv="1">20010123 def-2001-06: Easycom/Safecom 10/100 Multiple DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="i-data_international" name="easycom_safecom_print_server">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0259" published="2001-06-02" name="CVE-2001-0259" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">ssh-keygen in ssh 1.2.27 - 1.2.30 with Secure-RPC can allow local attackers to recover a SUN-DES-1 magic phrase generated by another user, which the attacker can use to decrypt that user's private key file.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5963.php" source="XF" patch="1" adv="1">ssh-rpc-private-key</ref>
      <ref url="http://www.securityfocus.com/bid/2222" source="BID" patch="1" adv="1">2222</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0262.html" source="BUGTRAQ" patch="1" adv="1">20010116 Bug in SSH1 secure-RPC support can expose users' private keys</ref>
      <ref url="http://www.ssh.com/products/ssh/patches/secureRPCvulnerability.html" source="CONFIRM" adv="1">http://www.ssh.com/products/ssh/patches/secureRPCvulnerability.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ssh" name="ssh">
        <vers num="1.2.27" />
        <vers num="1.2.28" />
        <vers num="1.2.29" />
        <vers num="1.2.30" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0260" published="2001-06-02" name="CVE-2001-0260" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Lotus Domino Mail Server 5.0.5 and earlier allows a remote attacker to crash the server or execute arbitrary code via a long "RCPT TO" command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5993.php" source="XF" patch="1" adv="1">lotus-domino-smtp-bo</ref>
      <ref url="http://www.securityfocus.com/bid/2283" source="BID" patch="1" adv="1">2283</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0360.html" source="BUGTRAQ" patch="1" adv="1">20010123 [SAFER] Security Bulletin 010123.EXP.1.10</ref>
      <ref url="http://www.osvdb.org/3321" source="OSVDB">3321</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lotus" name="domino_mail_server">
        <vers prev="1" num="5.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0261" published="2001-06-02" name="CVE-2001-0261" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Microsoft Windows 2000 Encrypted File System does not properly destroy backups of files that are encrypted, which allows a local attacker to recover the text of encrypted files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5973.php" source="XF" adv="1">win2k-efs-recover-data</ref>
      <ref url="http://www.securityfocus.com/bid/2243" source="BID" adv="1">2243</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98027311214976&amp;w=2" source="BUGTRAQ" adv="1">20010123 Reply to EFS note on Bugtraq</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97992179925715&amp;w=2" source="BUGTRAQ" adv="1">20010119 BugTraq: EFS Win 2000 flaw</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0262" published="2001-07-02" name="CVE-2001-0262" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Netscape SmartDownload 1.3 allows remote attackers (malicious web pages) to execute arbitrary commands via a long URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.atstake.com/research/advisories/2001/a041301-1.txt" source="ATSTAKE" patch="1" adv="1">A041301-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="smartdownload">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0263" published="2001-06-18" name="CVE-2001-0263" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Gene6 G6 FTP Server 2.0 (aka BPFTP Server 2.10) allows attackers to read file attributes outside of the web root via the (1) SIZE and (2) MDTM commands when the "show relative paths" option is not enabled.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.atstake.com/research/advisories/2001/a040301-1.txt" source="ATSTAKE" patch="1" adv="1">A040301-1</ref>
      <ref url="http://xforce.iss.net/static/6330.php" source="XF">bpftp-obtain-credentials(6330)</ref>
      <ref url="http://www.securityfocus.com/bid/2537" source="BID">2537</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gene6" name="g6_ftp_server">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0264" published="2001-06-18" name="CVE-2001-0264" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Gene6 G6 FTP Server 2.0 (aka BPFTP Server 2.10) allows remote attackers to obtain NETBIOS credentials by requesting information on a file that is in a network share, which causes the server to send the credentials to the host that owns the share, and allows the attacker to sniff the connection.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2534" source="BID" patch="1" adv="1">2534</ref>
      <ref url="http://www.atstake.com/research/advisories/2001/a040301-1.txt" source="ATSTAKE" patch="1" adv="1">A040301-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gene6" name="g6_ftp_server">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0265" published="2001-06-18" name="CVE-2001-0265" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">ASCII Armor parser in Windows PGP 7.0.3 and earlier allows attackers to create files in arbitrary locations via a malformed ASCII armored file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.atstake.com/research/advisories/2001/a040901-1.txt" source="ATSTAKE" patch="1" adv="1">A040901-1</ref>
      <ref url="http://xforce.iss.net/static/6643.php" source="XF">pgp-armor-code-execution(6643)</ref>
      <ref url="http://www.securityfocus.com/bid/2556" source="BID">2556</ref>
      <ref url="http://www.osvdb.org/1782" source="OSVDB">1782</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pgp" name="pgp">
        <vers num="5" />
        <vers prev="1" num="7.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0266" published="2001-05-03" name="CVE-2001-0266" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in Software Distributor SD-UX in HP-UX 11.0 and earlier allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/hp/2001-q1/0069.html" source="HP">HPSBUX0102-143</ref>
      <ref url="http://www.osvdb.org/6033" source="OSVDB">6033</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers prev="1" num="11.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0267" published="2001-05-03" name="CVE-2001-0267" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">NM debug in HP MPE/iX 6.5 and earlier does not properly handle breakpoints, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/hp/2001-q1/0050.html" source="HP" patch="1" adv="1">HPSBMP0102-008</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6226" source="XF">hp-nmdebug-gain-privileges(6226)</ref>
      <ref url="http://www.osvdb.org/6032" source="OSVDB">6032</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="mpe_ix">
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0268" published="2001-05-03" name="CVE-2001-0268" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The i386_set_ldt system call in NetBSD 1.5 and earlier, and OpenBSD 2.8 and earlier, when the USER_LDT kernel option is enabled, does not validate a call gate target, which allows local users to gain root privileges by creating a segment call gate in the Local Descriptor Table (LDT) with a target that specifies an arbitrary kernel address.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/358960" source="CERT-VN">VU#358960</ref>
      <ref url="http://archives.neohapsis.com/archives/netbsd/2001-q1/0093.html" source="NETBSD" patch="1" adv="1">NetBSD-SA:2001-002</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6222" source="XF">user-ldt-validation(6222)</ref>
      <ref url="http://www.securityfocus.com/bid/2739" source="BID">2739</ref>
      <ref url="http://www.osvdb.org/6141" source="OSVDB">6141</ref>
      <ref url="http://www.openbsd.org/errata.html#userldt" source="OPENBSD">20010302 The USER_LDT kernel option allows an attacker to gain access to privileged areas of kernel memory.</ref>
      <ref url="http://archives.neohapsis.com/archives/linux/caldera/2001-q4/0014.html" source="CALDERA">CSSA-2001-SCO.35</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0353.html" source="BUGTRAQ">20010219 Re: your mail</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netbsd" name="netbsd">
        <vers prev="1" num="1.5" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers prev="1" num="2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0269" published="2001-05-03" name="CVE-2001-0269" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">pam_ldap authentication module in Solaris 8 allows remote attackers to bypass authentication via a NULL password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0344.html" source="BUGTRAQ" patch="1" adv="1">20010217 Solaris 8 pam_ldap.so.1 module broken</ref>
      <ref url="http://xforce.iss.net/static/6440.php" source="XF">solaris-pamldap-bypass-authentication(6440)</ref>
      <ref url="http://www.osvdb.org/6030" source="OSVDB">6030</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0270" published="2001-05-03" name="CVE-2001-0270" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Marconi ASX-1000 ASX switches allow remote attackers to cause a denial of service in the telnet and web management interfaces via a malformed packet with the SYN-FIN and More Fragments attributes set.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2400" source="BID" patch="1" adv="1">2400</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0349.html" source="BUGTRAQ" patch="1" adv="1">20010219 Denial of Service Condition exists in Fore/Marconi ASX Switches</ref>
    </refs>
    <vuln_soft>
      <prod vendor="marconi" name="forethought">
        <vers num="6.2" />
      </prod>
      <prod vendor="marconi" name="asx-1000">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0271" published="2001-05-03" name="CVE-2001-0271" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">mailnews.cgi 1.3 and earlier allows remote attackers to execute arbitrary commands via a user name that contains shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0347.html" source="BUGTRAQ" adv="1">20010218 mailnews.cgi</ref>
      <ref url="http://www.securityfocus.com/bid/2391" source="BID">2391</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mailnews.cgi" name="mailnews.cgi">
        <vers prev="1" num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0272" published="2001-05-03" name="CVE-2001-0272" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in sendtemp.pl in W3.org Anaya Web development server allows remote attackers to read arbitrary files via a .. (dot dot) attack in the templ parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0259.html" source="BUGTRAQ" patch="1" adv="1">20010212 W3.ORG sendtemp.pl</ref>
    </refs>
    <vuln_soft>
      <prod vendor="w3.org" name="sendtemp.pl">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0273" published="2001-05-03" name="CVE-2001-0273" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">pgp4pine Pine/PGP interface version 1.75-6 does not properly check to see if a public key has expired when obtaining the keys via Gnu Privacy Guard (GnuPG), which causes the message to be sent in cleartext.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/566640" source="CERT-VN" adv="1">VU#566640</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0367.html" source="BUGTRAQ" patch="1" adv="1">20010220 [CryptNET Advisory] pgp4pine-1.75-6 - expired public keys</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6135" source="XF">pgp4pine-expired-keys(6135)</ref>
      <ref url="http://www.securityfocus.com/bid/2405" source="BID">2405</ref>
    </refs>
    <vuln_soft>
      <prod vendor="holger_lamm" name="pgp4pine">
        <vers num="1.75.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0274" published="2001-05-03" name="CVE-2001-0274" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">kicq IRC client 1.0.0, and possibly later versions, allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0536.html" source="BUGTRAQ" patch="1" adv="1">20010303 Re: Security hole in kicq</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0276.html" source="BUGTRAQ" patch="1" adv="1">20010214 Security hole in kicq</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6112" source="XF">kicq-execute-commands(6112)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kicq" name="kicq">
        <vers num="1.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0275" published="2001-05-03" name="CVE-2001-0275" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Moby Netsuite Web Server 1.02 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0346.html" source="BUGTRAQ" adv="1">20010219 NetSuite 1.02 web server vulnerabilty</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moby" name="netsuite_web_server">
        <vers num="1.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0276" published="2001-05-03" name="CVE-2001-0276" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">ext.dll in BadBlue 1.02.07 Personal Edition web server allows remote attackers to determine the physical path of the server by directly calling ext.dll without any arguments, which produces an error message that contains the path.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2390" source="BID" patch="1" adv="1">2390</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98263019502565&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010217 BadBlue Web Server Ext.dll Vulnerabilities</ref>
      <ref url="http://www.badblue.com/p010219.htm" source="CONFIRM">http://www.badblue.com/p010219.htm</ref>
      <ref url="http://xforce.iss.net/static/6130.php" source="XF">badblue-ext-reveal-path(6130)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="working_resources_inc." name="badblue">
        <vers num="1.2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0277" published="2001-05-03" name="CVE-2001-0277" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in ext.dll in BadBlue 1.02.07 Personal Edition allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2392" source="BID" patch="1" adv="1">2392</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98263019502565&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010217 BadBlue Web Server Ext.dll Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="working_resources_inc." name="badblue">
        <vers num="1.2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0278" published="2001-05-03" name="CVE-2001-0278" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Vulnerability in linkeditor in HP MPE/iX 6.5 and earlier allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/hp/2001-q1/0050.html" source="HP" patch="1" adv="1">HPSBMP0102-009</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6223" source="XF">hp-linkeditor-gain-privileges(6223)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="mpe_ix">
        <vers prev="1" num="6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0279" published="2001-05-03" name="CVE-2001-0279" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in sudo earlier than 1.6.3p6 allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-024.php3" source="MANDRAKE" patch="1" adv="1">MDKSA-2001:024</ref>
      <ref url="http://www.debian.org/security/2001/dsa-031" source="DEBIAN" patch="1" adv="1">DSA-031</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0414.html" source="BUGTRAQ" patch="1">20010222 Sudo version 1.6.3p6 now available (fwd)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-019.html" source="REDHAT">RHSA-2001:019</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-018.html" source="REDHAT">RHSA-2001:018</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000381" source="CONECTIVA">CLA-2001:381</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0437.html" source="BUGTRAQ">20010225 [slackware-security] buffer overflow in sudo fixed</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0427.html" source="BUGTRAQ">20010226 Trustix Security Advisory - sudo</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.2" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0280" published="2001-05-03" name="CVE-2001-0280" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in MERCUR SMTP server 3.30 allows remote attackers to execute arbitrary commands via a long EXPN command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0413.html" source="BUGTRAQ" adv="1">20010223 Mercur Mailserver 3.3 buffer overflow with EXPN</ref>
      <ref url="http://xforce.iss.net/static/6149.php" source="XF">mercur-expn-bo(6149)</ref>
      <ref url="http://www.osvdb.org/6027" source="OSVDB">6027</ref>
    </refs>
    <vuln_soft>
      <prod vendor="atrium_software" name="mercur">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0281" published="2001-05-03" name="CVE-2001-0281" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in DbgPrint function, used in debug messages for some Windows NT drivers (possibly when called through DebugMessage), may allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0379.html" source="BUGTRAQ" adv="1">20010221 NT drivers are potentially vulnerable to format string bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0282" published="2001-05-03" name="CVE-2001-0282" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SEDUM 2.1 HTTP server allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0419.html" source="BUGTRAQ" adv="1">20010223 SEDUM v2.1 HTTPd - Denial of Service</ref>
    </refs>
    <vuln_soft>
      <prod vendor="guido_frassetto" name="sedum">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0283" published="2001-05-03" name="CVE-2001-0283" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in SunFTP build 9 allows remote attackers to read arbitrary files via .. (dot dot) characters in various commands, including (1) GET, (2) MKDIR, (3) RMDIR, (4) RENAME, or (5) PUT.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0523.html" source="BUGTRAQ" adv="1">20010302 Sunftp build9(1) - ftp server Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sun_ftp">
        <vers num="build_9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0284" published="2001-05-03" name="CVE-2001-0284" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in IPSEC authentication mechanism for OpenBSD 2.8 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a malformed Authentication header (AH) IPv4 option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/6026" source="OSVDB">6026</ref>
      <ref url="http://www.openbsd.org/errata.html#ipsec_ah" source="OPENBSD">20010302 Insufficient checks in the IPSEC AH IPv4 option handling code can lead to a buffer overrun in the kernel.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers prev="1" num="2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0285" published="2001-05-03" name="CVE-2001-0285" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in A1 HTTP server 1.0a allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0457.html" source="BUGTRAQ" adv="1">20010226 A1 Server v1.0a HTTPd (DoS &amp; Dir Traversal)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="a1webserver" name="http_server">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0286" published="2001-05-03" name="CVE-2001-0286" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in A1 HTTP server 1.0a allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0457.html" source="BUGTRAQ" adv="1">20010226 A1 Server v1.0a HTTPd (DoS &amp; Dir Traversal)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="a1webserver" name="http_server">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0287" published="2001-05-03" name="CVE-2001-0287" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">VERITAS Cluster Server (VCS) 1.3.0 on Solaris allows local users to cause a denial of service (system panic) via the -L option to the lltstat command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://seer.support.veritas.com/docs/234326.htm" source="CONFIRM" adv="1">http://seer.support.veritas.com/docs/234326.htm</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0528.html" source="BUGTRAQ" adv="1">20010302 Option to VERITAS Cluster Server (VCS) lltstat command will panic system.</ref>
      <ref url="http://www.osvdb.org/6025" source="OSVDB">6025</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec_veritas" name="cluster_server">
        <vers num="1.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0288" published="2001-05-03" name="CVE-2001-0288" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cisco switches and routers running IOS 12.1 and earlier produce predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/ios-tcp-isn-random-pub.shtml" source="CISCO" patch="1" adv="1">20010228 Cisco IOS Software TCP Initial Sequence Number Randomization Improvements</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers prev="1" num="12.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0289" published="2001-05-03" name="CVE-2001-0289" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Joe text editor 2.8 searches the current working directory (CWD) for the .joerc configuration file, which could allow local users to gain privileges of other users by placing a Trojan Horse .joerc file into a directory, then waiting for users to execute joe from that directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-026.php3" source="MANDRAKE" patch="1" adv="1">MDKSA-2001:026</ref>
      <ref url="http://www.debian.org/security/2001/dsa-041" source="DEBIAN" patch="1" adv="1">DSA-041</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0490.html" source="BUGTRAQ" patch="1" adv="1">20010228 Joe's Own Editor File Handling Error</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-024.html" source="REDHAT">RHSA-2001:024</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joseph_allen" name="joe">
        <vers num="2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0290" published="2001-05-03" name="CVE-2001-0290" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Vulnerability in Mailman 2.0.1 and earlier allows list administrators to obtain user passwords.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0031.html" source="BUGTRAQ" adv="1">20010306 [Mailman-Announce] ANNOUNCE Mailman 2.0.2 (important privacy patch)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="mailman">
        <vers prev="1" num="2.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0291" published="2001-05-03" name="CVE-2001-0291" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in post-query sample CGI program allows remote attackers to execute arbitrary commands via an HTTP POST request that contains at least 10001 parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0003.html" source="BUGTRAQ" adv="1">20010305 Remote buffer overflow condition in post-query (CGI).</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0292" published="2001-05-03" name="CVE-2001-0292" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP-Nuke 4.4.1a allows remote attackers to modify a user's email address and obtain the password by guessing the user id (UID) and calling user.php with the saveuser operator.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0525.html" source="BUGTRAQ" adv="1">20010302 PHPNUKE4.4.1a Advisory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="4.4.1a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0293" published="2001-05-03" name="CVE-2001-0293" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in FtpXQ FTP server 2.0.93 allows remote attackers to read arbitrary files via a .. (dot dot) in the GET command.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2426" source="BID" adv="1">2426</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0508.html" source="BUGTRAQ" adv="1">20010228 Vulnerability in FtpXQ Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="datawizard" name="ftpxq">
        <vers num="2.0.93" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0294" published="2001-05-03" name="CVE-2001-0294" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in TYPSoft FTP Server 0.85 allows remote attackers to read arbitrary files via (1) a .. (dot dot) in a GET command, or (2) a ... in a CWD command.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0511.html" source="BUGTRAQ" adv="1">20010228 Vulnerability in TYPSoft FTP Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typsoft" name="typsoft_ftp_server">
        <vers num="0.85" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0295" published="2001-05-03" name="CVE-2001-0295" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in War FTP 1.67.04 allows remote attackers to list directory contents and possibly read files via a "dir *./../.." command.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2444" source="BID" patch="1" adv="1">2444</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98390925726814&amp;w=2" source="BUGTRAQ" adv="1">20010306 Warftp 1.67b04 Directory Traversal</ref>
      <ref url="http://www.osvdb.org/874" source="OSVDB">874</ref>
      <ref url="http://support.jgaa.com/?cmd=ShowArticle&amp;ID=31" source="CONFIRM">http://support.jgaa.com/?cmd=ShowArticle&amp;ID=31</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jarle_aase" name="war_ftpd">
        <vers num="1.67b04" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0296" published="2001-05-03" name="CVE-2001-0296" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in WFTPD Pro 3.00 allows remote attackers to execute arbitrary commands via a long CWD command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0531.html" source="BUGTRAQ" adv="1">20010303 WFTPD Pro 3.00 R1 Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="texas_imperial_software" name="wftpd_pro">
        <vers num="3.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0297" published="2001-05-03" name="CVE-2001-0297" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Simple Server HTTPd 1.0 (originally Free Java Server) allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2415" source="BID" adv="1">2415</ref>
      <ref url="http://www.securityfocus.com/archive/1/165523" source="BUGTRAQ" adv="1">20010224 The Simple Server HTTPd Directory Traversal</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dattaraj_rao" name="simple_server">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0298" published="2001-05-03" name="CVE-2001-0298" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in WebReflex 1.55 HTTPd allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2425" source="BID" adv="1">2425</ref>
      <ref url="http://www.securityfocus.com/archive/1/165671" source="BUGTRAQ">20010227 WebReflex 1.55 HTTPd DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sapio_design_ltd" name="webreflex">
        <vers num="1.55" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0299" published="2001-06-02" name="CVE-2001-0299" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Voyager web administration server for Nokia IP440 allows local users to cause a denial of service, and possibly execute arbitrary commands, via a long URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2054" source="BID" patch="1" adv="1">2054</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97603879517777&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20001205 Nokia firewalls - Response from Nokia</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97535202912588&amp;w=2" source="BUGTRAQ" adv="1">20001127 Nokia firewalls</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5640" source="XF">nokia-ip440-bo(5640)</ref>
      <ref url="http://www.osvdb.org/6020" source="OSVDB">6020</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nokia" name="ip440_firewall_vpn_appliance">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0300" published="2001-06-02" name="CVE-2001-0300" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">oidldapd 2.1.1.1 in Oracle 8.1.7 records log files in a directory (ldaplog) that has world-writable permissions, which may allow local users to delete logs and/or overwrite other files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/610904" source="CERT-VN">VU#610904</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0434.html" source="BUGTRAQ" patch="1" adv="1">20001222 vulnerability #2 in Oracle Internet Directory 2.1.1.1 in Oracle 8.1.7</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/5804" source="XF">oracle-oidldap-write-permission(5804)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="internet_directory">
        <vers num="2.1.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0301" published="2001-05-03" name="CVE-2001-0301" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Analog before 4.16 allows remote attackers to execute arbitrary commands by using the ALIAS command to construct large strings.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2377" source="BID" patch="1" adv="1">2377</ref>
      <ref url="http://www.debian.org/security/2001/dsa-033" source="DEBIAN" patch="1" adv="1">DSA-033</ref>
      <ref url="http://www.analog.cx/security2.html" source="CONFIRM" patch="1" adv="1">http://www.analog.cx/security2.html</ref>
      <ref url="http://archives.neohapsis.com/archives/linux/redhat/2001-q1/0056.html" source="REDHAT" patch="1" adv="1">RHSA-2001:017</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0264.html" source="BUGTRAQ" patch="1" adv="1">20010213 Security advisory for analog</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6105" source="XF">analog-alias-bo(6105)</ref>
      <ref url="http://www.osvdb.org/1762" source="OSVDB">1762</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stephen_turner" name="analog">
        <vers prev="1" num="4.15" />
        <vers prev="1" num="4.90_beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0302" published="2001-05-03" name="CVE-2001-0302" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in tstisapi.dll in Pi3Web 1.0.1 web server allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long URL.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2381" source="BID" patch="1" adv="1">2381</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0316.html" source="BUGTRAQ" adv="1">20010215 Vulnerabilities in Pi3Web Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pi3" name="pi3web">
        <vers num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0303" published="2001-05-03" name="CVE-2001-0303" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">tstisapi.dll in Pi3Web 1.0.1 web server allows remote attackers to determine the physical path of the server via a URL that requests a non-existent file.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2381" source="BID" patch="1" adv="1">2381</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0316.html" source="BUGTRAQ" adv="1">20010215 Vulnerabilities in Pi3Web Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pi3" name="pi3web">
        <vers num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0304" published="2001-05-03" name="CVE-2001-0304" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Caucho Resin 1.2.2 allows remote attackers to read arbitrary files via a "\.." (dot dot) in a URL request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2384" source="BID" patch="1" adv="1">2384</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98229372610440&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010216 Vulnerability in Resin Webserver</ref>
    </refs>
    <vuln_soft>
      <prod vendor="caucho_technology" name="resin">
        <vers num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0305" published="2001-05-03" name="CVE-2001-0305" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in store.cgi in Thinking Arts ES.One package allows remote attackers to read arbitrary files via a .. (dot dot) in the StartID parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2385" source="BID" adv="1">2385</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0324.html" source="BUGTRAQ" adv="1">20010216 Thinking Arts Store.cgi Directory Traversal</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thinking_arts" name="es.one">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0306" published="2001-05-03" name="CVE-2001-0306" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in ITAfrica WEBactive HTTP Server 1.00 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2386" source="BID" adv="1">2386</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0332.html" source="BUGTRAQ" adv="1">20010216 WEBactive HTTP Server 1.0 Directory Traversal</ref>
    </refs>
    <vuln_soft>
      <prod vendor="itafrica" name="webactive">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0307" published="2001-05-03" name="CVE-2001-0307" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Bajie HTTP JServer 0.78, and other versions before 0.80, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP request for a CGI program that does not exist.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0314.html" source="BUGTRAQ" patch="1" adv="1">20010216 Vulnerabilities in Bajie Http JServer</ref>
      <ref url="http://www.geocities.com/gzhangx/websrv/docs/security.html" source="CONFIRM">http://www.geocities.com/gzhangx/websrv/docs/security.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bajie" name="java_http_server">
        <vers prev="1" num="0.79" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0308" published="2001-05-03" name="CVE-2001-0308" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">UploadServlet in Bajie HTTP JServer 0.78, and possibly other versions before 0.80, allows remote attackers to execute arbitrary commands by calling the servlet to upload a program, then using a ... (modified ..) to access the file that was created for the program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2388" source="BID" adv="1">2388</ref>
      <ref url="http://www.geocities.com/gzhangx/websrv/docs/security.html" source="CONFIRM">http://www.geocities.com/gzhangx/websrv/docs/security.html</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0314.html" source="BUGTRAQ" adv="1">20010216 Vulnerabilities in Bajie Http JServer</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bajie" name="java_http_server">
        <vers prev="1" num="0.79" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0309" published="2001-06-02" name="CVE-2001-0309" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">inetd in Red Hat 6.2 does not properly close sockets for internal services such as chargen, daytime, echo, etc., which allows remote attackers to cause a denial of service via a series of connections to the internal services.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-006.html" source="REDHAT" patch="1" adv="1">RHSA-2001:006</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6380" source="XF">inetd-internal-socket-dos(6380)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0310" published="2001-06-02" name="CVE-2001-0310" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">sort in FreeBSD 4.1.1 and earlier, and possibly other operating systems, uses predictable temporary file names and does not properly handle when the temporary file already exists, which causes sort to crash and possibly impacts security-sensitive scripts.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6038.php" source="XF" patch="1" adv="1">sort-temp-file-abort</ref>
      <ref url="http://www.securityfocus.com/bid/3960" source="BID">3960</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:13.sort.asc" source="FREEBSD">FreeBSD-SA-01:13</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.5.1" />
        <vers num="4.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0311" published="2001-06-02" name="CVE-2001-0311" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Vulnerability in OmniBackII A.03.50 in HP 11.x and earlier allows attackers to gain unauthorized access to an OmniBack client.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/6434" source="XF">omniback-unauthorized-access(6434)</ref>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0102-142" source="HP">HPSBUX0102-142</ref>
      <ref url="http://archives.neohapsis.com/archives/hp/2001-q1/0023.html" source="HPBUG">PHSS_22915</ref>
      <ref url="http://archives.neohapsis.com/archives/hp/2001-q1/0022.html" source="HPBUG">PHSS_22914</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="omniback_ii">
        <vers num="a.03.50" />
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers prev="1" num="11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0312" published="2001-06-02" name="CVE-2001-0312" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IBM WebSphere plugin for Netscape Enterprise server allows remote attackers to read source code for JSP files via an HTTP request that contains a host header that references a host that is not in WebSphere's host aliases list, which will bypass WebSphere processing.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0446.html" source="BUGTRAQ" patch="1" adv="1">20010125 Yet Another IBM WebSphere Showcode Vulerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_plugin">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0313" published="2001-06-02" name="CVE-2001-0313" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Borderware Firewall Server 6.1.2 allows remote attackers to cause a denial of service via a ping to the broadcast address of the public network on which the server is placed, which causes the server to continuously send pings (echo requests) to the network.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6004.php" source="XF" adv="1">borderware-ping-dos</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98053139231392&amp;w=2" source="BUGTRAQ" adv="1">20010126 Borderware v6.1.2 ping DoS vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="borderware" name="firewall_server">
        <vers num="6.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0314" published="2001-06-02" name="CVE-2001-0314" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in www.tol module in America Online (AOL) 5.0 may allow remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long URL in a link.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6009.php" source="XF" adv="1">aol-malformed-url-dos</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98053366805491&amp;w=2" source="BUGTRAQ" adv="1">20010125 America Online 5.0 contains a buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aol" name="aol_server">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0315" published="2001-06-02" name="CVE-2001-0315" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The locking feature in mIRC 5.7 allows local users to bypass the password mechanism by modifying the LockOptions registry key.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6013.php" source="XF" adv="1">mirc-bypass-password</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98053777917287&amp;w=2" source="BUGTRAQ">20010125 mIRC allows password protection to be bypassed</ref>
    </refs>
    <vuln_soft>
      <prod vendor="khaled_mardam-bey" name="mirc">
        <vers prev="1" num="5.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0316" published="2001-05-03" name="CVE-2001-0316" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Linux kernel 2.4 and 2.2 allows local users to read kernel memory and possibly gain privileges via a negative argument to the sysctl call.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.caldera.com/support/security/advisories/CSSA-2001-009.0.txt" source="CALDERA" patch="1" adv="1">CSSA-2001-009</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0267.html" source="BUGTRAQ" patch="1" adv="1">20010213 Trustix Security Advisory - proftpd, kernel</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6079" source="XF">linux-sysctl-read-memory(6079)</ref>
      <ref url="http://www.securityfocus.com/bid/2364" source="BID">2364</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-013.html" source="REDHAT">RHSA-2001:013</ref>
      <ref url="http://www.osvdb.org/6017" source="OSVDB">6017</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.2.0" />
        <vers num="2.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0317" published="2001-05-03" name="CVE-2001-0317" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">Race condition in ptrace in Linux kernel 2.4 and 2.2 allows local users to gain privileges by using ptrace to track and modify a running setuid process.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.caldera.com/support/security/advisories/CSSA-2001-009.0.txt" source="CALDERA" patch="1" adv="1">CSSA-2001-009</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0267.html" source="BUGTRAQ" patch="1" adv="1">20010213 Trustix Security Advisory - proftpd, kernel</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6080" source="XF">linux-ptrace-modify-process(6080)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-013.html" source="REDHAT">RHSA-2001:013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.2.0" />
        <vers num="2.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0318" published="2001-06-02" name="CVE-2001-0318" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in ProFTPD 1.2.0rc2 may allow attackers to execute arbitrary commands by shutting down the FTP server while using a malformed working directory (cwd).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-021.php3" source="MANDRAKE" patch="1" adv="1">MDKSA-2001:021</ref>
      <ref url="http://www.debian.org/security/2001/dsa-029" source="DEBIAN" patch="1" adv="1">DSA-029</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0117.html" source="BUGTRAQ" patch="1" adv="1">20010206 Response to ProFTPD issues</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6433" source="XF">proftpd-format-string(6433)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97916525715657&amp;w=2" source="BUGTRAQ">20010110 proftpd 1.2.0rc2 -- example of bad coding</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000380" source="CONECTIVA">CLA-2001:380</ref>
    </refs>
    <vuln_soft>
      <prod vendor="proftpd_project" name="proftpd">
        <vers num="1.2.0_rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0319" published="2001-05-03" name="CVE-2001-0319" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">orderdspc.d2w macro in IBM Net.Commerce 3.x allows remote attackers to execute arbitrary SQL queries by inserting them into the order_rn option of the report capability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2350" source="BID">2350</ref>
      <ref url="http://www-4.ibm.com/software/webservers/commerce/netcomletter.html" source="CONFIRM" adv="1">http://www-4.ibm.com/software/webservers/commerce/netcomletter.html</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0072.html" source="BUGTRAQ" adv="1">20010205 IBM NetCommerce Security</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6067" source="XF">ibm-netcommerce-reveal-information(6067)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="net.commerce">
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":start" />
        <vers num="3.1" edition=":pro" />
        <vers num="3.1.1" edition="" />
        <vers num="3.1.1" edition=":pro" />
        <vers num="3.1.1" edition=":start" />
        <vers num="3.1.2" edition="" />
        <vers num="3.1.2" edition=":start" />
        <vers num="3.1.2" edition=":pro" />
        <vers num="3.2" edition="" />
        <vers num="3.2" edition=":pro" />
        <vers num="3.2" edition=":start" />
      </prod>
      <prod vendor="ibm" name="net.commerce_hosting_server">
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers num="3.2" />
      </prod>
      <prod vendor="ibm" name="websphere_commerce_suite">
        <vers num="3.1.2" edition="" />
        <vers num="3.1.2" edition=":service_provider" />
        <vers num="3.2" edition="" />
        <vers num="3.2" edition=":service_provider" />
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":start" />
        <vers num="4.1" edition=":marketplace" />
        <vers num="4.1" edition=":pro" />
        <vers num="4.1.1" edition="" />
        <vers num="4.1.1" edition=":start" />
        <vers num="4.1.1" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0320" published="2001-05-03" name="CVE-2001-0320" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">bb_smilies.php and bbcode_ref.php in PHP-Nuke 4.4 allows remote attackers to read arbitrary files and gain PHP administrator privileges by inserting a null character and .. (dot dot) sequences into a malformed username argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0425.html" source="BUGTRAQ" adv="1">20010223 Yet another hole in PHP-Nuke</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="4.0.4" />
        <vers num="4.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0321" published="2001-05-03" name="CVE-2001-0321" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">opendir.php script in PHP-Nuke allows remote attackers to read arbitrary files by specifying the filename as an argument to the requesturl parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0214.html" source="BUGTRAQ" adv="1">20010212 Fwd: Re: phpnuke, security problem...</ref>
      <ref url="http://xforce.iss.net/static/6512.php" source="XF">phpnuke-opendir-read-files(6512)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="8.0_final" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0322" published="2001-06-02" name="CVE-2001-0322" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">MSHTML.DLL HTML parser in Internet Explorer 4.0, and other versions, allows remote attackers to cause a denial of service (application crash) via a script that creates and deletes an object that is associated with the browser window object.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5938.php" source="XF" adv="1">ie-mshtml-dos</ref>
      <ref url="http://www.securityfocus.com/bid/2202" source="BID" adv="1">2202</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97958685100219&amp;w=2" source="BUGTRAQ" adv="1">20010115 Stack Overflow in MSHTML.DLL</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="4.0" />
      </prod>
      <prod vendor="microsoft" name="outlook">
        <vers num="2000" />
      </prod>
      <prod vendor="microsoft" name="outlook_express">
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0323" published="2001-06-02" name="CVE-2001-0323" modified="2005-10-20" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The ICMP path MTU (PMTU) discovery feature in various UNIX systems allows remote attackers to cause a denial of service by spoofing "ICMP Fragmentation needed but Don't Fragment (DF) set" packets between two target hosts, which could cause one host to lower its MTU when transmitting to the other host.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5975.php" source="XF" adv="1">icmp-pmtu-dos</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97958349623450&amp;w=2" source="BUGTRAQ" adv="1">20010115 ICMP fragmentation required but DF set problems.</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0324" published="2001-05-03" name="CVE-2001-0324" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Windows 98 and Windows 2000 Java clients allow remote attackers to cause a denial of service via a Java applet that opens a large number of UDP sockets, which prevents the host from establishing any additional UDP connections, and possibly causes a crash.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2340" source="BID" adv="1">2340</ref>
      <ref url="http://archives.neohapsis.com/archives/win2ksecadvice/2001-q1/0060.html" source="BUGTRAQ" adv="1">20010206 Windows client UDP exhaustion denial of service</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0325" published="2001-05-03" name="CVE-2001-0325" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in QNX RTP 5.60 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a large number of arguments to the stat command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2342" source="BID" adv="1">2342</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0031.html" source="BUGTRAQ" adv="1">20010202 QNX RTP ftpd stack overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qnx" name="rtp">
        <vers num="5.60" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0326" published="2001-05-03" name="CVE-2001-0326" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Oracle Java Virtual Machine (JVM ) for Oracle 8.1.7 and Oracle Application Server 9iAS Release 1.0.2.0.1 allows remote attackers to read arbitrary files via the .jsp and .sqljsp file extensions when the server is configured to use the &lt;&lt;ALL FILES>> FilePermission.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0255.html" source="BUGTRAQ" patch="1" adv="1">20010212 Solution for Potential Vunerability in Granting FilePermission to Oracle Java Virtual Machine</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6438" source="XF">oracle-jvm-file-permissions(6438)</ref>
      <ref url="http://www.osvdb.org/5706" source="OSVDB">5706</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="release_1.0.2.0.1" />
      </prod>
      <prod vendor="oracle" name="oracle8i">
        <vers num="8.1.7_r3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0327" published="2001-07-02" name="CVE-2001-0327" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to retrieve sensitive data from memory allocation pools, or cause a denial of service, via a URL-encoded Host: header in the HTTP request, which reveals memory in the Location: header that is returned by the server.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/276767" source="CERT-VN">VU#276767</ref>
      <ref url="http://www.atstake.com/research/advisories/2001/a041601-1.txt" source="ATSTAKE" patch="1" adv="1">A041601-1</ref>
      <ref url="http://www.iplanet.com/products/iplanet_web_enterprise/iwsalert4.16.html" source="CONFIRM">http://www.iplanet.com/products/iplanet_web_enterprise/iwsalert4.16.html</ref>
      <ref url="http://www.osvdb.org/5704" source="OSVDB">5704</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iplanet" name="iplanet_web_server">
        <vers prev="1" num="4.1_enterprise" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0328" published="2001-06-27" name="CVE-2001-0328" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">TCP implementations that use random increments for initial sequence numbers (ISN) can allow remote attackers to perform session hijacking or disruption by injecting a flood of packets with a range of ISN values, one of which may match the expected ISN.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2001-09.html" source="CERT" patch="1" adv="1">CA-2001-09</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4922" source="OVAL">oval:org.mitre.oval:def:4922</ref>
      <ref url="http://securityreason.com/securityalert/57" source="SREASON">57</ref>
      <ref url="http://secunia.com/advisories/8044" source="SECUNIA">8044</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20030201-01-P" source="SGI">20030201-01-P</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0329" published="2001-06-27" name="CVE-2001-0329" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Bugzilla 2.10 allows remote attackers to execute arbitrary commands via shell metacharacters in a username that is then processed by (1) the Bugzilla_login cookie in post_bug.cgi, or (2) the who parameter in process_bug.cgi.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.atstake.com/research/advisories/2001/a043001-1.txt" source="ATSTAKE" patch="1" adv="1">A043001-1</ref>
      <ref url="http://www.securityfocus.com/bid/1199" source="BID">1199</ref>
      <ref url="http://www.mozilla.org/projects/bugzilla/security2_12.html" source="CONFIRM">http://www.mozilla.org/projects/bugzilla/security2_12.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="2.10" />
        <vers num="2.4" />
        <vers num="2.6" />
        <vers num="2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0330" published="2001-06-27" name="CVE-2001-0330" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Bugzilla 2.10 allows remote attackers to access sensitive information, including the database username and password, via an HTTP request for the globals.pl file, which is normally returned by the web server without being executed.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2671" source="BID" patch="1" adv="1">2671</ref>
      <ref url="http://www.atstake.com/research/advisories/2001/a043001-1.txt" source="ATSTAKE" patch="1" adv="1">A043001-1</ref>
      <ref url="http://xforce.iss.net/static/6489.php" source="XF">bugzilla-gobalpl-gain-information(6489)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="2.10" />
        <vers num="2.4" />
        <vers num="2.6" />
        <vers num="2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0331" published="2001-06-27" name="CVE-2001-0331" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Embedded Support Partner (ESP) daemon (rpc.espd) in IRIX 6.5.8 and earlier allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/258632" source="CERT-VN">VU#258632</ref>
      <ref url="http://xforce.iss.net/alerts/advise76.php" source="ISS" adv="1">20010509 Remote Buffer Overflow Vulnerability in IRIX Embedded Support Partner Infrastructure	</ref>
      <ref url="http://xforce.iss.net/static/6502.php" source="XF">irix-espd-bo(6502)</ref>
      <ref url="http://www.securityfocus.com/bid/2714" source="BID">2714</ref>
      <ref url="http://www.osvdb.org/1822" source="OSVDB">1822</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20010501-01-P" source="SGI">20010501-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.5.5" />
        <vers prev="1" num="6.5.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0332" published="2001-06-27" name="CVE-2001-0332" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain using MSScriptControl.ScriptControl and GetObject, aka a variant of the "Frame Domain Verification" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-027.asp" source="MS" patch="1" adv="1">MS01-027</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98609031517525&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010330 Security bug in Internet Explorer - MSScriptControl.ScriptControl</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" />
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0333" published="2001-06-27" name="CVE-2001-0333" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2001-12.html" source="CERT">CA-2001-12</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-026.asp" source="MS" patch="1" adv="1">MS01-026</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98992056521300&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010515 NSFOCUS SA2001-02 : Microsoft IIS CGI Filename Decode Error Vulnerability</ref>
      <ref url="http://xforce.iss.net/static/6534.php" source="XF">iis-url-decoding(6534)</ref>
      <ref url="http://www.securityfocus.com/bid/2708" source="BID">2708</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:78" source="OVAL" sig="1">oval:org.mitre.oval:def:78</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:37" source="OVAL" sig="1">oval:org.mitre.oval:def:37</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1051" source="OVAL" sig="1">oval:org.mitre.oval:def:1051</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1018" source="OVAL" sig="1">oval:org.mitre.oval:def:1018</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
        <vers prev="1" num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0334" published="2001-06-27" name="CVE-2001-0334" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">FTP service in IIS 5.0 and earlier allows remote attackers to cause a denial of service via a wildcard sequence that generates a long string when it is expanded.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-026.asp" source="MS" patch="1" adv="1">MS01-026</ref>
      <ref url="http://xforce.iss.net/static/6535.php" source="XF">iis-ftp-wildcard-dos(6535)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers prev="1" num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0335" published="2001-06-27" name="CVE-2001-0335" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">FTP service in IIS 5.0 and earlier allows remote attackers to enumerate Guest accounts in trusted domains by preceding the username with a special sequence of characters.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-026.asp" source="MS" patch="1" adv="1">MS01-026</ref>
      <ref url="http://xforce.iss.net/static/6545.php" source="XF">iis-ftp-domain-authentication(6545)</ref>
      <ref url="http://www.securityfocus.com/bid/2719" source="BID">2719</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers prev="1" num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0336" published="2001-06-27" name="CVE-2001-0336" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Microsoft MS00-060 patch for IIS 5.0 and earlier introduces an error which allows attackers to cause a denial of service via a malformed request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-026.asp" source="MS" patch="1" adv="1">MS01-026</ref>
      <ref url="http://xforce.iss.net/static/6858.php" source="XF">iis-crosssitescripting-patch-dos(6858)</ref>
      <ref url="http://www.osvdb.org/5693" source="OSVDB">5693</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers prev="1" num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0337" published="2001-06-27" name="CVE-2001-0337" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Microsoft MS01-014 and MS01-016 patches for IIS 5.0 and earlier introduce a memory leak which allows attackers to cause a denial of service via a series of requests.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-026.asp" source="MS" patch="1" adv="1">MS01-026</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers prev="1" num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0338" published="2001-06-27" name="CVE-2001-0338" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Internet Explorer 5.5 and earlier does not properly validate digital certificates when Certificate Revocation List (CRL) checking is enabled, which could allow remote attackers to spoof trusted web sites, aka the "Server certificate validation vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-027.asp" source="MS" patch="1" adv="1">MS01-027</ref>
      <ref url="http://xforce.iss.net/static/6555.php" source="XF">ie-crl-certificate-spoofing(6555)</ref>
      <ref url="http://www.securityfocus.com/bid/2735" source="BID">2735</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/l-087.shtml" source="CIAC">L-087</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" />
        <vers prev="1" num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0339" published="2001-06-27" name="CVE-2001-0339" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Internet Explorer 5.5 and earlier allows remote attackers to display a URL in the address bar that is different than the URL that is actually being displayed, which could be used in web site spoofing attacks, aka the "Web page spoofing vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-027.asp" source="MS" patch="1" adv="1">MS01-027</ref>
      <ref url="http://xforce.iss.net/static/6556.php" source="XF">ie-html-url-spoofing(6556)</ref>
      <ref url="http://www.securityfocus.com/bid/2737" source="BID">2737</ref>
      <ref url="http://www.osvdb.org/5694" source="OSVDB">5694</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/l-087.shtml" source="CIAC">L-087</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1096" source="OVAL" sig="1">oval:org.mitre.oval:def:1096</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers prev="1" num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0340" published="2001-07-21" name="CVE-2001-0340" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">An interaction between the Outlook Web Access (OWA) service in Microsoft Exchange 2000 Server and Internet Explorer allows attackers to execute malicious script code against a user's mailbox via a message attachment that contains HTML code, which is executed automatically.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-030.asp" source="MS" patch="1" adv="1">MS01-030</ref>
      <ref url="http://xforce.iss.net/static/6652.php" source="XF">exchange-owa-script-execution(6652)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/l-091.shtml" source="CIAC">L-091</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="2000" />
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0341" published="2001-07-21" name="CVE-2001-0341" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Visual Studio RAD Support sub-component of FrontPage Server Extensions allows remote attackers to execute arbitrary commands via a long registration request (URL) to fp30reg.dll.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2906" source="BID" patch="1" adv="1">2906</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-035.asp" source="MS" patch="1" adv="1">MS01-035</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=99348216322147&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010625 NSFOCUS SA2001-03 : Microsoft FrontPage 2000 Server Extensions Buffer Overflow Vulnerability</ref>
      <ref url="http://xforce.iss.net/static/6730.php" source="XF">frontpage-ext-rad-bo(6730)</ref>
      <ref url="http://www.osvdb.org/577" source="OSVDB">577</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="frontpage_server_extensions">
        <vers num="2000" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":advanced_server" />
        <vers num="" edition=":professional" />
        <vers num="" edition=":datacenter_server" />
        <vers num="" edition=":server" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":terminal_server" />
        <vers num="4.0" edition=":server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:server" />
        <vers num="4.0" edition="sp1:enterprise_server" />
        <vers num="4.0" edition="sp1:workstation" />
        <vers num="4.0" edition="sp1:terminal_server" />
        <vers num="4.0" edition="sp2" />
        <vers num="4.0" edition="sp2:workstation" />
        <vers num="4.0" edition="sp2:enterprise_server" />
        <vers num="4.0" edition="sp2:server" />
        <vers num="4.0" edition="sp2:terminal_server" />
        <vers num="4.0" edition="sp3" />
        <vers num="4.0" edition="sp3:workstation" />
        <vers num="4.0" edition="sp3:enterprise_server" />
        <vers num="4.0" edition="sp3:server" />
        <vers num="4.0" edition="sp3:terminal_server" />
        <vers num="4.0" edition="sp4" />
        <vers num="4.0" edition="sp4:workstation" />
        <vers num="4.0" edition="sp4:enterprise_server" />
        <vers num="4.0" edition="sp4:terminal_server" />
        <vers num="4.0" edition="sp4:server" />
        <vers num="4.0" edition="sp5" />
        <vers num="4.0" edition="sp5:workstation" />
        <vers num="4.0" edition="sp5:enterprise_server" />
        <vers num="4.0" edition="sp5:server" />
        <vers num="4.0" edition="sp5:terminal_server" />
        <vers num="4.0" edition="sp6" />
        <vers num="4.0" edition="sp6:enterprise_server" />
        <vers num="4.0" edition="sp6:terminal_server" />
        <vers num="4.0" edition="sp6:server" />
        <vers num="4.0" edition="sp6:workstation" />
        <vers num="4.0" edition="sp6a" />
        <vers num="4.0" edition="sp6a:enterprise_server" />
        <vers num="4.0" edition="sp6a:workstation" />
        <vers num="4.0" edition="sp6a:server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0344" published="2001-07-21" name="CVE-2001-0344" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">An SQL query method in Microsoft SQL Server 2000 Gold and 7.0 using Mixed Mode allows local database users to gain privileges by reusing a cached connection of the sa administrator account.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms01-032.asp" source="MS" patch="1" adv="1">MS01-032</ref>
      <ref url="http://xforce.iss.net/static/6684.php" source="XF">mssql-cached-connection-access(6684)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/l-095.shtml" source="CIAC">L-095</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:71" source="OVAL" sig="1">oval:org.mitre.oval:def:71</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="sql_server">
        <vers num="2000" edition="gold" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0345" published="2001-07-21" name="CVE-2001-0345" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Windows 2000 telnet service allows attackers to prevent idle Telnet sessions from timing out, causing a denial of service by creating a large number of idle sessions.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-031.asp" source="MS" patch="1" adv="1">MS01-031</ref>
      <ref url="http://xforce.iss.net/static/6667.php" source="XF">win2k-telnet-idle-sessions-dos(6667)</ref>
      <ref url="http://www.securityfocus.com/bid/2843" source="BID">2843</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0346" published="2001-07-21" name="CVE-2001-0346" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Handle leak in Microsoft Windows 2000 telnet service allows attackers to cause a denial of service by starting a large number of sessions and terminating them.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6668.php" source="XF">win2k-telnet-handle-leak-dos(6668)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-031.asp" source="MS">MS01-031</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0347" published="2001-07-21" name="CVE-2001-0347" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Information disclosure vulnerability in Microsoft Windows 2000 telnet service allows remote attackers to determine the existence of user accounts such as Guest, or log in to the server without specifying the domain name, via a malformed userid.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-031.asp" source="MS" patch="1" adv="1">MS01-031</ref>
      <ref url="http://xforce.iss.net/static/6665.php" source="XF">win2k-telnet-domain-authentication(6665)</ref>
      <ref url="http://www.securityfocus.com/bid/2847" source="BID">2847</ref>
      <ref url="http://www.osvdb.org/5686" source="OSVDB">5686</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/l-092.shtml" source="CIAC">L-092</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0348" published="2001-07-21" name="CVE-2001-0348" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Windows 2000 telnet service allows attackers to cause a denial of service (crash) via a long logon command that contains a backspace.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-031.asp" source="MS" patch="1" adv="1">MS01-031</ref>
      <ref url="http://xforce.iss.net/static/6666.php" source="XF">win2k-telnet-username-dos(6666)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/l-092.shtml" source="CIAC">L-092</ref>
      <ref url="http://razor.bindview.com/publish/advisories/adv_mstelnet.html" source="BINDVIEW">20010608 Range checking fault condition in Microsoft Windows 2000 Telnet server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0349" published="2001-07-21" name="CVE-2001-0349" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the first of two variants of this vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/587587" source="CERT-VN">VU#587587</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-031.asp" source="MS" patch="1" adv="1">MS01-031</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6664" source="XF">win2k-telnet-pipe-privileges(6664)</ref>
      <ref url="http://www.securityfocus.com/bid/2849" source="BID">2849</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0350" published="2001-07-21" name="CVE-2001-0350" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the second of two variants of this vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-031.asp" source="MS" patch="1" adv="1">MS01-031</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6664" source="XF">win2k-telnet-pipe-privileges(6664)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0351" published="2001-07-21" name="CVE-2001-0351" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Microsoft Windows 2000 telnet service allows a local user to make a certain system call that allows the user to terminate a Telnet session and cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-031.asp" source="MS" patch="1" adv="1">MS01-031</ref>
      <ref url="http://xforce.iss.net/static/6669.php" source="XF">win2k-telnet-system-call-dos(6669)</ref>
      <ref url="http://www.securityfocus.com/bid/2846" source="BID">2846</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/l-092.shtml" source="CIAC">L-092</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0352" published="2001-07-21" name="CVE-2001-0352" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SNMP agents in 3Com AirConnect AP-4111 and Symbol 41X1 Access Point allow remote attackers to obtain the WEP encryption key by reading it from a MIB when the value should be write-only, via (1) dot11WEPDefaultKeyValue in the dot11WEPDefaultKeysTable of the IEEE 802.11b MIB, or (2) ap128bWepKeyValue in the ap128bWEPKeyTable in the Symbol MIB.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs />
    <vuln_soft>
      <prod vendor="symbol" name="41x1_access_point">
        <vers num="" />
      </prod>
      <prod vendor="3com" name="3crwe747a">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0353" published="2001-07-21" name="CVE-2001-0353" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the line printer daemon (in.lpd) for Solaris 8 and earlier allows local and remote attackers to gain root privileges via a "transfer job" routine.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2001-15.html" source="CERT">CA-2001-15</ref>
      <ref url="http://xforce.iss.net/static/6718.php" source="XF" patch="1" adv="1">solaris-lpd-bo(6718)</ref>
      <ref url="http://xforce.iss.net/alerts/advise80.php" source="ISS" patch="1" adv="1">20010619 Remote Buffer Overflow Vulnerability in Solaris Print Protocol Daemon</ref>
      <ref url="http://www.securityfocus.com/bid/2894" source="BID">2894</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/206" source="SUN">00206</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0354" published="2001-07-02" name="CVE-2001-0354" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">TheNet CheckBO 1.56 allows remote attackers to cause a denial of service via a flood of characters to the TCP ports which it is listening on.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2634" source="BID" adv="1">2634</ref>
      <ref url="http://www.securityfocus.com/archive/1/178061" source="BUGTRAQ" adv="1">20010420 CheckBO Win9x memo overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thenet" name="checkbo">
        <vers num="1.56" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0355" published="2001-06-27" name="CVE-2001-0355" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Novell Groupwise 5.5 (sp1 and sp2) allows a remote user to access arbitrary files via an implementation error in Groupwise system policies.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98185226715517&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010210 Novell Groupwise Client Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="groupwise">
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0357" published="2001-08-22" name="CVE-2001-0357" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">FormMail.pl in FormMail 1.6 and earlier allows a remote attacker to send anonymous email (spam) by modifying the recipient and message parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6242.php" source="XF" patch="1" adv="1">formmail-anonymous-flooding(6242)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98433523520344&amp;w=2" source="BUGTRAQ" adv="1">20010310 CORRECTION to CODE: FormMail.pl can be used to send anonymous email </ref>
    </refs>
    <vuln_soft>
      <prod vendor="matt_wright" name="formmail">
        <vers prev="1" num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0358" published="2001-06-27" name="CVE-2001-0358" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflows in Sierra Half-Life build 1573 and earlier allow remote attackers to execute arbitrary code via (1) a long map command, (2) a long exec command, or (3) long input in a configuration file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6221.php" source="XF" adv="1">halflife-config-file-bo</ref>
      <ref url="http://xforce.iss.net/static/6218.php" source="XF" adv="1">halflife-map-bo</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0111.html" source="BUGTRAQ" adv="1">20010309 Advisory: Half-life server buffer overflows and formatting vulnerabilities </ref>
    </refs>
    <vuln_soft>
      <prod vendor="sierra" name="half-life">
        <vers prev="1" num="1573" />
      </prod>
      <prod vendor="valve_software" name="half-life">
        <vers prev="1" num="1573" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0359" published="2001-06-27" name="CVE-2001-0359" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in Sierra Half-Life build 1573 and earlier allows a remote attacker to execute arbitrary code via the map command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6220.php" source="XF" adv="1">halflife-map-format-string</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0111.html" source="BUGTRAQ" adv="1">20010309 Advisory: Half-life server buffer overflows and formatting vulnerabilities </ref>
    </refs>
    <vuln_soft>
      <prod vendor="sierra" name="half-life">
        <vers prev="1" num="1573" />
      </prod>
      <prod vendor="valve_software" name="half-life_dedicated_server">
        <vers prev="1" num="1573" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0360" published="2001-06-27" name="CVE-2001-0360" modified="2009-04-03" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in help.cgi in Ikonboard 2.1.7b and earlier allows a remote attacker to read arbitrary files via a .. (dot dot) attack in the helpon parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6216.php" source="XF" patch="1" adv="1">ikonboard-cgi-read-files</ref>
      <ref url="http://www.securityfocus.com/bid/2471" source="BID" patch="1" adv="1">2471</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0124.html" source="BUGTRAQ" adv="1">20010311 Ikonboard v2.1.7b "show files" vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ikonboard.com" name="ikonboard">
        <vers prev="1" num="2.1.7b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0361" published="2001-06-27" name="CVE-2001-0361" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.9" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Implementations of SSH version 1.5, including (1) OpenSSH up to version 2.3.0, (2) AppGate, and (3) ssh-1 up to version 1.2.31, in certain configurations, allow a remote attacker to decrypt and/or alter traffic via a "Bleichenbacher attack" on PKCS#1 version 1.5.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2344" source="BID" patch="1" adv="1">2344</ref>
      <ref url="http://xforce.iss.net/static/6082.php" source="XF">ssh-session-key-recovery(6082)</ref>
      <ref url="http://www.osvdb.org/2116" source="OSVDB">2116</ref>
      <ref url="http://www.novell.com/linux/security/advisories/adv004_ssh.html" source="SUSE">SuSE-SA:2001:04</ref>
      <ref url="http://www.debian.org/security/2001/dsa-086" source="DEBIAN">DSA-086</ref>
      <ref url="http://www.debian.org/security/2001/dsa-027" source="DEBIAN">DSA-027</ref>
      <ref url="http://www.debian.org/security/2001/dsa-023" source="DEBIAN">DSA-023</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/l-047.shtml" source="CIAC">L-047</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98158450021686&amp;w=2" source="BUGTRAQ">20010207 [CORE SDI ADVISORY] SSH1 session key recovery vulnerability</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:24.ssh.asc" source="FREEBSD">FreeBSD-SA-01:24</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openssh">
        <vers num="1.2.3" />
        <vers num="2.1" />
        <vers num="2.1.1" />
      </prod>
      <prod vendor="ssh" name="ssh">
        <vers prev="1" num="1.2.31" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0364" published="2001-06-27" name="CVE-2001-0364" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SSH Communications Security sshd 2.4 for Windows allows remote attackers to create a denial of service via a large number of simultaneous connections.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6241.php" source="XF" patch="1" adv="1">ssh-ssheloop-dos(6241)</ref>
      <ref url="http://www.securityfocus.com/bid/2477" source="BID" adv="1">2477</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98467799732241&amp;w=2" source="BUGTRAQ" adv="1">20010315 Remote DoS attack against SSH Secure Shell for Windows Servers</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ssh" name="ssh2">
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0365" published="2001-06-27" name="CVE-2001-0365" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Eudora before 5.1 allows a remote attacker to execute arbitrary code, when the 'Use Microsoft Viewer' and 'allow executables in HTML content' options are enabled, via an HTML email message containing Javascript, with ActiveX controls and malicious code within IMG tags.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6262.php" source="XF" patch="1" adv="1">eudora-html-execute-code(6262)</ref>
      <ref url="http://www.securityfocus.com/bid/2490" source="BID" patch="1" adv="1">2490</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98503741910995&amp;w=2" source="BUGTRAQ" adv="1">20010318 feeble.you!dora.exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qualcomm" name="eudora">
        <vers num="5.0.2" />
        <vers prev="1" num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0366" published="2001-06-27" name="CVE-2001-0366" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">saposcol in SAP R/3 Web Application Server Demo before 1.5 trusts the PATH environmental variable to find and execute the expand program, which allows local users to obtain root access by modifying the PATH to point to a Trojan horse expand program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2662" source="BID" patch="1" adv="1">2662</ref>
      <ref url="http://www.securityfocus.com/archive/1/180498" source="BUGTRAQ" patch="1" adv="1">20010429 SAP R/3 Web Application Server Demo for Linux: root exploit</ref>
      <ref url="ftp://ftp.sap.com/pub/linuxlab/saptools/README.saposcol" source="CONFIRM">ftp://ftp.sap.com/pub/linuxlab/saptools/README.saposcol</ref>
      <ref url="http://xforce.iss.net/static/6487.php" source="XF">linux-sap-execute-code(6487)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sap" name="sap_r_3_web_application_server_demo">
        <vers prev="1" num="1.5" />
      </prod>
      <prod vendor="sap" name="saposcol">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":linux" />
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":linux" />
        <vers num="1.2" edition="" />
        <vers num="1.2" edition=":linux" />
        <vers num="1.3" edition="" />
        <vers num="1.3" edition=":linux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0367" published="2001-06-27" name="CVE-2001-0367" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Mirabilis ICQ WebFront Plug-in ICQ2000b Build 3278 allows a remote attacker to create a denial of service via HTTP URL requests containing a large number of % characters.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2664" source="BID" adv="1">2664</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98847544303438&amp;w=2" source="BUGTRAQ" adv="1">20010428 Mirabilis ICQ WebFront Plug-in Denial of Service</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mirabilis" name="icq">
        <vers num="2000.0b_build3278" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0368" published="2001-06-27" name="CVE-2001-0368" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in BearShare 2.2.2 and earlier allows a remote attacker to read certain files via a URL containing a series of . characters, a variation of the .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2672" source="BID" patch="1" adv="1">2672</ref>
      <ref url="http://www.securityfocus.com/archive/1/180644" source="BUGTRAQ" patch="1" adv="1">20010430 A Serious Security Vulnerability Found in BearShare (Directory Traversal)</ref>
      <ref url="http://xforce.iss.net/static/6481.php" source="XF">bearshare-dot-download-files(6481)</ref>
      <ref url="http://www.osvdb.org/1810" source="OSVDB">1810</ref>
    </refs>
    <vuln_soft>
      <prod vendor="free_peers" name="bearshare">
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers prev="1" num="2.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0369" published="2001-06-27" name="CVE-2001-0369" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in lpsched on DGUX version R4.20MU06 and MU02 allows a local attacker to obtain root access via a long command line argument (non-existent printer name).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6258.php" source="XF" patch="1" adv="1">dgux-lpsched-bo</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98511407131984&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010319 DGUX lpsched buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digital" name="unix">
        <vers num="mu02" />
        <vers num="r4.20mu06" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0370" published="2001-06-27" name="CVE-2001-0370" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">fcheck prior to 2.57.59 calls the file signature checking program insecurely, which can allow a local user to run arbitrary commands via a file name that contains shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6256.php" source="XF" patch="1" adv="1">fcheck-open-execute-commands</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98521301510554&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010320 fcheck prior to 2.07.59 - vulnerability - improper use of perl 'magic open'</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michael_a._gumienny" name="fcheck">
        <vers prev="1" num="2.57.59" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0371" published="2001-06-18" name="CVE-2001-0371" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">Race condition in the UFS and EXT2FS file systems in FreeBSD 4.2 and earlier, and possibly other operating systems, makes deleted data available to user processes before it is zeroed out, which allows a local user to access otherwise restricted information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6268.php" source="XF" patch="1" adv="1">ufs-ext2fs-data-disclosure(6268)</ref>
      <ref url="http://archives.neohapsis.com/archives/freebsd/2001-03/0403.html" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-01:30</ref>
      <ref url="http://www.osvdb.org/5682" source="OSVDB">5682</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers prev="1" num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0372" published="2001-06-18" name="CVE-2001-0372" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Akopia Interchange 4.5.3 through 4.6.3 installs demo stores with a default group account :backup with no password, which allows a remote attacker to gain administrative access via the demo stores (1) barry, (2) basic, or (3) construct.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2499" source="BID" patch="1" adv="1">2499</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0337.html" source="BUGTRAQ" patch="1" adv="1">20010323 FW: Akopia Interchange E-commerce Package Demo Files Vulnerability</ref>
      <ref url="http://xforce.iss.net/static/6273.php" source="XF">akopia-interchange-gain-access(6273)</ref>
      <ref url="http://lists.akopia.com/pipermail/interchange-announce/2001/000009.html" source="CONFIRM">http://lists.akopia.com/pipermail/interchange-announce/2001/000009.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="akopia" name="akopia_interchange">
        <vers num="4.5.3" />
        <vers prev="1" num="4.6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0373" published="2001-06-18" name="CVE-2001-0373" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The default configuration of the Dr. Watson program in Windows NT and Windows 2000 generates user.dmp crash dump files with world-readable permissions, which could allow a local user to gain access to sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2501" source="BID" patch="1" adv="1">2501</ref>
      <ref url="http://xforce.iss.net/static/6275.php" source="XF" adv="1">win-userdmp-insecure-permission(6275)</ref>
      <ref url="http://www.osvdb.org/5683" source="OSVDB">5683</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0336.html" source="BUGTRAQ">20010323 NT crash dump files insecure by default</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0374" published="2001-06-18" name="CVE-2001-0374" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The HTTP server in Compaq web-enabled management software for (1) Foundation Agents, (2) Survey, (3) Power Manager, (4) Availability Agents, (5) Intelligent Cluster Administrator, and (6) Insight Manager can be used as a generic proxy server, which allows remote attackers to bypass access restrictions via the management port, 2301.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6264.php" source="XF" patch="1" adv="1">compaq-wbm-bypass-proxy</ref>
      <ref url="http://www.compaq.com/products/servers/management/mgtsw-advisory.html" source="COMPAQ" patch="1" adv="1">SSRT0715</ref>
      <ref url="http://archives.neohapsis.com/archives/vuln-dev/2001-q1/0779.html" source="BUGTRAQ" adv="1">20010322 Compaq Insight Manager Proxy Vuln </ref>
    </refs>
    <vuln_soft>
      <prod vendor="compaq" name="web-enabled_management">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0375" published="2001-06-18" name="CVE-2001-0375" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco PIX Firewall 515 and 520 with 5.1.4 OS running aaa authentication to a TACACS+ server allows remote attackers to cause a denial of service via a large number of authentication requests.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2551" source="BID" patch="1" adv="1">2551</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98658271707833&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010406 PIX Firewall 5.1 DoS Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6353" source="XF" adv="1">cisco-pix-tacacs-dos(6353)</ref>
      <ref url="http://www.cisco.com/warp/public/707/pixfirewall-authen-flood-pub.shtml" source="CISCO">20011003 Cisco PIX Firewall Authentication Denial of Service Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="pix_firewall_515">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="pix_firewall_520">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0376" published="2001-06-18" name="CVE-2001-0376" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SonicWALL Tele2 and SOHO firewalls with 6.0.0.0 firmware using IPSEC with IKE pre-shared keys do not allow for the use of full 128 byte IKE pre-shared keys, which is the intended design of the IKE pre-shared key, and only support 48 byte keys.  This allows a remote attacker to brute force attack the pre-shared keys with significantly less resources than if the full 128 byte IKE pre-shared keys were used.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0403.html" source="BUGTRAQ" patch="1" adv="1">20010327 SonicWall IKE pre-shared key length bug and security concern</ref>
      <ref url="http://xforce.iss.net/static/6304.php" source="XF" adv="1">sonicwall-ike-shared-keys</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sonicwall" name="soho2">
        <vers num="6.0.0" />
      </prod>
      <prod vendor="sonicwall" name="tele2">
        <vers num="6.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0377" published="2001-06-18" name="CVE-2001-0377" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Infradig Inframail prior to 3.98a allows a remote attacker to create a denial of service via a malformed POST request which includes a space followed by a large string.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6297.php" source="XF" patch="1" adv="1">inframail-post-dos(6297)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0428.html" source="BUGTRAQ" patch="1" adv="1">20010328 Inframail Denial of Service Vulnerability</ref>
      <ref url="http://www.osvdb.org/5685" source="OSVDB">5685</ref>
    </refs>
    <vuln_soft>
      <prod vendor="infradig" name="inframail">
        <vers prev="1" num="3.97a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0378" published="2001-06-27" name="CVE-2001-0378" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">readline prior to 4.1, in OpenBSD 2.8 and earlier, creates history files with insecure permissions, which allows a local attacker to recover potentially sensitive information via readline history files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.8/common/024_readline.patch" source="CONFIRM" patch="1">ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.8/common/024_readline.patch</ref>
      <ref url="http://xforce.iss.net/static/6586.php" source="XF">bsd-readline-permissions(6586)</ref>
      <ref url="http://www.osvdb.org/5680" source="OSVDB">5680</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers prev="1" num="2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0379" published="2001-06-18" name="CVE-2001-0379" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Vulnerability in the newgrp program included with HP9000 servers running HP-UX 11.11 allows a local attacker to obtain higher access rights.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/249224" source="CERT-VN">VU#249224</ref>
      <ref url="http://archives.neohapsis.com/archives/hp/2001-q1/0101.html" source="HP" patch="1" adv="1">HPSBUX0103-147</ref>
      <ref url="http://xforce.iss.net/static/6282.php" source="XF">hp-newgrp-additional-privileges(6282)</ref>
      <ref url="http://www.osvdb.org/5681" source="OSVDB">5681</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0380" published="2001-06-18" name="CVE-2001-0380" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Crosscom/Olicom XLT-F running XL 80 IM Version 5.5 Build Level 2 allows a remote attacker SNMP read and write access via a default, undocumented community string 'ILMI'.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5718" source="OVAL">oval:org.mitre.oval:def:5718</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0364.html" source="BUGTRAQ" adv="1">200103 ILMI community in olicom/crosscomm routers</ref>
    </refs>
    <vuln_soft>
      <prod vendor="crosscom_olicom" name="xlt-f">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0381" published="2001-06-27" name="CVE-2001-0381" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The OpenPGP PGP standard allows an attacker to determine the private signature key via a cryptanalytic attack in which the attacker alters the encrypted private key file and captures a single message signed with the signature key.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/6558" source="XF">openpgp-private-key-disclosure(6558)</ref>
      <ref url="http://www.securityfocus.com/bid/2673" source="BID">2673</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-063.html" source="REDHAT">RHSA-2001:063</ref>
      <ref url="http://www.osvdb.org/11966" source="OSVDB">11966</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0311.html" source="BUGTRAQ" adv="1">20010322 Re: Yes, they have found a serious PGP vulnerability...sort of </ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0274.html" source="BUGTRAQ" adv="1">20010320 Yes, they have found a serious PGP vulnerability...sort of</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0252.html" source="BUGTRAQ" adv="1">20010319 Have they found a serious PGP vulnerability?! </ref>
      <ref url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2001-017.0.txt" source="CALDERA">CSSA-2001-017.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pgp" name="openpgp">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0382" published="2001-06-18" name="CVE-2001-0382" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Computer Associates CCC\Harvest 5.0 for Windows NT/2000 uses weak encryption for passwords, which allows a remote attacker to gain privileges on the application.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2001-q2/0001.html" source="NTBUGTRAQ" patch="1" adv="1">20010327 CA CCC\Harvest exploit </ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="ccc_harvest">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0383" published="2001-06-18" name="CVE-2001-0383" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">banners.php in PHP-Nuke 4.4 and earlier allows remote attackers to modify banner ad URLs by directly calling the Change operation, which does not require authentication.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://phpnuke.org/download.php?dcategory=Fixes" source="CONFIRM">http://phpnuke.org/download.php?dcategory=Fixes</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0017.html" source="BUGTRAQ" adv="1">20010401 Php-nuke exploit...</ref>
      <ref url="http://xforce.iss.net/static/6342.php" source="XF">php-nuke-url-redirect(6342)</ref>
      <ref url="http://www.securityfocus.com/bid/2544" source="BID">2544</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers prev="1" num="4.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0384" published="2001-07-02" name="CVE-2001-0384" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">ppd in Reliant Sinix allows local users to corrupt arbitrary files via a symlink attack in the /tmp/ppd.trace file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2606" source="BID" adv="1">2606</ref>
      <ref url="http://www.securityfocus.com/archive/1/176709" source="BUGTRAQ">20010414 Re: Reliant Unix 5.43 / 5.44 ICMP port unreachable problem</ref>
    </refs>
    <vuln_soft>
      <prod vendor="siemens" name="reliant_unix">
        <vers prev="1" num="5.45" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0385" published="2001-07-02" name="CVE-2001-0385" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">GoAhead webserver 2.1 allows remote attackers to cause a denial of service via an HTTP request to the /aux directory.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2607" source="BID" adv="1">2607</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0281.html" source="BUGTRAQ" adv="1">20010417 Advisory for GoAhead Webserver v2.1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6400" source="XF">goahead-aux-dos(6400)</ref>
      <ref url="http://www.osvdb.org/6664" source="OSVDB">6664</ref>
    </refs>
    <vuln_soft>
      <prod vendor="goahead_software" name="goahead_webserver">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0386" published="2001-07-02" name="CVE-2001-0386" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">AnalogX SimpleServer:WWW 1.08 allows remote attackers to cause a denial of service via an HTTP request to the /aux directory.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2608" source="BID" patch="1" adv="1">2608</ref>
      <ref url="http://www.securityfocus.com/archive/1/177156" source="BUGTRAQ" adv="1">20010417 Advisory for SimpleServer:WWW (analogX)</ref>
      <ref url="http://xforce.iss.net/static/6395.php" source="XF">analogx-simpleserver-aux-dos(6395)</ref>
      <ref url="http://www.osvdb.org/3781" source="OSVDB">3781</ref>
    </refs>
    <vuln_soft>
      <prod vendor="analogx" name="simpleserver_www">
        <vers prev="1" num="1.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0387" published="2001-07-02" name="CVE-2001-0387" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in hfaxd in HylaFAX before 4.1.b2_2 allows local users to gain privileges via the -q command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2574" source="BID" patch="1" adv="1">2574</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-041.php3" source="MANDRAKE" patch="1" adv="1">MDKSA-2001:041</ref>
      <ref url="http://lists.suse.com/archives/suse-security-announce/2001-Apr/0005.html" source="SUSE" patch="1" adv="1">SuSE-SA:2001:15</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0236.html" source="BUGTRAQ" patch="1" adv="1">20010415 **SECURITY ADVISORY** - HylaFAX format string vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/175963" source="BUGTRAQ" adv="1">20010412 HylaFAX vulnerability</ref>
      <ref url="http://xforce.iss.net/static/6377.php" source="XF">hylafax-hfaxd-format-string(6377)</ref>
      <ref url="http://www.osvdb.org/5679" source="OSVDB">5679</ref>
      <ref url="http://archives.neohapsis.com/archives/freebsd/2001-04/0606.html" source="FREEBSD">FreeBSD-SA-01:34</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hylafax" name="hylafax">
        <vers num="4.0_pl0" />
        <vers num="4.0_pl1" />
        <vers num="4.0_pl2" />
        <vers num="4.1_beta1" />
        <vers num="4.1_beta2" />
        <vers num="4.1_beta3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0388" published="2001-06-27" name="CVE-2001-0388" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">time server daemon timed allows remote attackers to cause a denial of service via malformed packets.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6228.php" source="XF" patch="1" adv="1">timed-remote-dos(6228)</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-034.php3" source="MANDRAKE" patch="1" adv="1">MDKSA-2001:034</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:28.timed.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-01:28</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2001_007_nkitserv.html" source="SUSE">SuSE-SA:2001:07</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers prev="1" num="4.1" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
        <vers num="7.0" />
        <vers num="7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0389" published="2001-07-02" name="CVE-2001-0389" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to determine the real path of the server by directly calling the macro.d2w macro with a NOEXISTINGHTMLBLOCK argument.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2587" source="BID" adv="1">2587</ref>
      <ref url="http://www.securityfocus.com/archive/1/176100" source="BUGTRAQ">20010413 [LoWNOISE] IBM Websphere/NetCommerce3 DoS and one more.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="net.commerce">
        <vers num="3.1.2" />
      </prod>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="5.1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0390" published="2001-07-02" name="CVE-2001-0390" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to cause a denial of service by directly calling the macro.d2w macro with a long string of %0a characters.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2588" source="BID" adv="1">2588</ref>
      <ref url="http://www.securityfocus.com/archive/1/176100" source="BUGTRAQ">20010413 [LoWNOISE] IBM Websphere/NetCommerce3 DoS and one more.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="net.commerce">
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.1.1" />
        <vers num="3.1.2" />
      </prod>
      <prod vendor="ibm" name="net.commerce_hosting_server">
        <vers num="3.1.1" />
        <vers num="3.1.2" />
      </prod>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="5.1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0391" published="2001-07-02" name="CVE-2001-0391" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Xitami 2.5d4 and earlier allows remote attackers to crash the server via an HTTP request to the /aux directory.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0277.html" source="BUGTRAQ">20010417 Advisory for Xitami 2.4d7, 2.5d4</ref>
    </refs>
    <vuln_soft>
      <prod vendor="imatix" name="xitami">
        <vers num="2.4d7" edition="" />
        <vers num="2.4d7" edition=":windows" />
        <vers num="2.5d4" edition="" />
        <vers num="2.5d4" edition=":windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0392" published="2001-06-18" name="CVE-2001-0392" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Navision Financials Server 2.60 and earlier allows remote attackers to cause a denial of service by sending a null character and a long string to the server port (2407), which causes the server to crash.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2539" source="BID" patch="1" adv="1">2539</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98633100728473&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010403 def-2001-17: Navision Financials Server DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="navision" name="financials_server">
        <vers num="2.50" />
        <vers prev="1" num="2.60" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0393" published="2001-06-18" name="CVE-2001-0393" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Navision Financials Server 2.0 allows remote attackers to cause a denial of service via a series of connections to the server without providing a username/password combination, which consumes the license limits.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98637870623514&amp;w=2" source="BUGTRAQ" adv="1">20010404 Re: def-2001-17: Navision Financials Server DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="navision" name="financials_server">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0394" published="2001-08-22" name="CVE-2001-0394" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Remote manager service in Website Pro 3.0.37 allows remote attackers to cause a denial of service via a series of malformed HTTP requests to the /dyn directory.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0425.html" source="BUGTRAQ" patch="1" adv="1">20010328 def-2001-15: Website Pro Remote Manager DoS</ref>
      <ref url="http://xforce.iss.net/static/6295.php" source="XF" adv="1">website-pro-remote-dos(6295)</ref>
      <ref url="http://www.osvdb.org/5669" source="OSVDB">5669</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oreilly" name="website_pro">
        <vers num="3.0.37" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0395" published="2001-07-02" name="CVE-2001-0395" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Lightwave ConsoleServer 3200 does not disconnect users after unsuccessful login attempts, which could allow remote attackers to conduct brute force password guessing.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2578" source="BID" patch="1" adv="1">2578</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0170.html" source="BUGTRAQ" adv="1">20010410 Console 3200 telnetd problem.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lightwave" name="consoleserver">
        <vers num="3200" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0396" published="2001-07-02" name="CVE-2001-0396" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The pre-login mode in the System Administrator interface of Lightwave ConsoleServer 3200 allows remote attackers to obtain sensitive information such as system status, configuration, and users.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2578" source="BID" patch="1" adv="1">2578</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0170.html" source="BUGTRAQ" adv="1">20010410 Console 3200 telnetd problem.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lightwave" name="consoleserver">
        <vers num="3200" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0397" published="2001-06-18" name="CVE-2001-0397" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Silent Runner Collector (SRC) 1.6.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long SMTP HELO command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0454.html" source="BUGTRAQ" adv="1">20010329 Silent Runner Collector - HELO buffer overflow vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="silent_runner" name="silent_runner_collector_src">
        <vers num="1.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0398" published="2001-06-18" name="CVE-2001-0398" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The BAT! mail client allows remote attackers to bypass user warnings of an executable attachment and execute arbitrary commands via an attachment whose file name contains many spaces, which also causes the BAT!  to misrepresent the attachment's type with a different icon.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2530" source="BID" patch="1" adv="1">2530</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0013.html" source="BUGTRAQ" adv="1">20010402 ~..~!guano</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ritlabs" name="the_bat">
        <vers num="1.011" />
        <vers num="1.015" />
        <vers num="1.028" />
        <vers num="1.029" />
        <vers num="1.031" />
        <vers num="1.032" />
        <vers num="1.035" />
        <vers num="1.036" />
        <vers num="1.037" />
        <vers num="1.039" />
        <vers num="1.041" />
        <vers num="1.043" />
        <vers num="1.0_build1336" />
        <vers num="1.0_build1349" />
        <vers num="1.1" />
        <vers num="1.101" />
        <vers num="1.14" />
        <vers num="1.15" />
        <vers num="1.17" />
        <vers num="1.18" />
        <vers num="1.19" />
        <vers num="1.21" />
        <vers num="1.22" />
        <vers num="1.31" />
        <vers num="1.32" />
        <vers num="1.33" />
        <vers num="1.34" />
        <vers num="1.35" />
        <vers num="1.36" />
        <vers num="1.39" />
        <vers num="1.41" />
        <vers num="1.42" />
        <vers num="1.42f" />
        <vers num="1.43" />
        <vers num="1.44" />
        <vers num="1.45" />
        <vers num="1.46" />
        <vers num="1.47" />
        <vers num="1.48" />
        <vers num="1.49" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0399" published="2001-06-18" name="CVE-2001-0399" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Caucho Resin 1.3b1 and earlier allows remote attackers to read source code for Javabean files by inserting a .jsp before the WEB-INF specifier in an HTTP request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2533" source="BID" patch="1" adv="1">2533</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98633597813833&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010403 CHINANSL Security Advisory(CSA-200111)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="caucho_technology" name="resin">
        <vers num="1.2" />
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0400" published="2001-07-02" name="CVE-2001-0400" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">nph-maillist.pl allows remote attackers to execute arbitrary commands via shell metacharacters ("`") in the email address.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2563" source="BID" patch="1" adv="1">2563</ref>
      <ref url="http://www.securityfocus.com/archive/1/175506" source="BUGTRAQ" adv="1">20010410 CGI - nph-maillist.pl vulnerability...</ref>
    </refs>
    <vuln_soft>
      <prod vendor="matt_tourtillott" name="nph-maillist">
        <vers num="3.0" />
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0401" published="2001-06-18" name="CVE-2001-0401" modified="2009-07-21" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in tip in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0394.html" source="BUGTRAQ" patch="1" adv="1">20010327 Solaris /usr/bin/tip Vulnerability</ref>
      <ref url="http://xforce.iss.net/static/6284.php" source="XF" adv="1">solaris-tip-bo</ref>
      <ref url="http://www.securityfocus.com/bid/2475" source="BID">2475</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.5" />
        <vers num="2.5.1" />
        <vers num="2.6" />
        <vers num="7.0" />
        <vers prev="1" num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0402" published="2001-06-18" name="CVE-2001-0402" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">IPFilter 3.4.16 and earlier does not include sufficient session information in its cache, which allows remote attackers to bypass access restrictions by sending fragmented packets to a restricted port after sending unfragmented packets to an unrestricted port.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98679734015538&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010408 A fragmentation attack against IP Filter</ref>
      <ref url="http://archives.neohapsis.com/archives/freebsd/2001-04/0338.html" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-01:32</ref>
      <ref url="http://xforce.iss.net/static/6331.php" source="XF">ipfilter-access-ports(6331)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="darren_reed" name="ipfilter">
        <vers prev="1" num="3.4.16" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers prev="1" num="4.1" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0403" published="2001-06-18" name="CVE-2001-0403" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">/opt/JSparm/bin/perfmon program in Solaris allows local users to create arbitrary files as root via the Logging File option in the GUI.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0326.html" source="BUGTRAQ" patch="1" adv="1">20010323 [ Hackerslab bug_paper ] SunOS application perfmon vulnerability</ref>
      <ref url="http://xforce.iss.net/static/6267.php" source="XF" adv="1">solaris-perfmon-create-files</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0404" published="2001-06-18" name="CVE-2001-0404" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in JavaServer Web Dev Kit (JSWDK) 1.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request to the WEB-INF directory.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98583089425166&amp;w=2" source="BUGTRAQ" adv="1">20010328 CHINANSL Security Advisory(CSA-200106)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="javaserver_web_dev_kit">
        <vers num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0405" published="2001-07-02" name="CVE-2001-0405" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">ip_conntrack_ftp in the IPTables firewall for Linux 2.4 allows remote attackers to bypass access restrictions for an FTP server via a PORT command that lists an arbitrary IP address and port number, which is added to the RELATED table and allowed by the firewall.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2602" source="BID" patch="1" adv="1">2602</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0271.html" source="BUGTRAQ" patch="1" adv="1">20010416 Tempest Security Techonologies -- Adivsory #01/2001 -- Linux IPTables</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-052.html" source="REDHAT" adv="1">RHSA-2001:052</ref>
      <ref url="http://xforce.iss.net/static/6390.php" source="XF">linux-netfilter-iptables(6390)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-084.html" source="REDHAT">RHSA-2001:084</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-071.php3" source="MANDRAKE">MDKSA-2001:071</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1" />
        <vers num="2.4.1" />
        <vers num="2.4.2" />
        <vers num="2.4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0406" published="2001-07-02" name="CVE-2001-0406" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Samba before 2.2.0 allows local attackers to overwrite arbitrary files via a symlink attack using (1) a printer queue query, (2) the more command in smbclient, or (3) the mput command in smbclient.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/670568" source="CERT-VN">VU#670568</ref>
      <ref url="http://www.debian.org/security/2001/dsa-048" source="DEBIAN" patch="1" adv="1">DSA-048</ref>
      <ref url="http://www.caldera.com/support/security/advisories/CSSA-2001-015.0.txt" source="CALDERA" patch="1" adv="1">CSSA-2001-015.0</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0326.html" source="BUGTRAQ" patch="1" adv="1">20010418 PROGENY-SA-2001-05: Samba /tmp vulnerabilities</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0319.html" source="BUGTRAQ" patch="1" adv="1">20010418 TSLSA-#2001-0005 - samba</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0305.html" source="BUGTRAQ" patch="1" adv="1">20010417 Samba 2.0.8 security fix</ref>
      <ref url="http://www.securityfocus.com/bid/2617" source="BID">2617</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-040.php3" source="MANDRAKE">MDKSA-2001:040</ref>
      <ref url="http://archives.neohapsis.com/archives/freebsd/2001-04/0608.html" source="FREEBSD">FreeBSD-SA-01:36</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000395" source="CONECTIVA">CLA-2001:395</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers prev="1" num="2.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0407" published="2001-06-27" name="CVE-2001-0407" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Directory traversal vulnerability in MySQL before 3.23.36 allows local users to modify arbitrary files and gain privileges by creating a database whose name starts with .. (dot dot).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0396.html" source="BUGTRAQ" patch="1" adv="1">20010327 MySQL 3.23.36 is relased (fwd)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0237.html" source="BUGTRAQ" adv="1">20010318 potential vulnerability of mysqld running with root privileges (can be used as good DoS or r00t expoloit)</ref>
      <ref url="http://xforce.iss.net/static/6617.php" source="XF">mysql-dot-directory-traversal(6617)</ref>
      <ref url="http://www.securityfocus.com/bid/2522" source="BID">2522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers prev="1" num="3.23.36" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0408" published="2001-06-18" name="CVE-2001-0408" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">vim (aka gvim) processes VIM control codes that are embedded in a file, which could allow attackers to execute arbitrary commands when another user opens a file containing malicious VIM control codes.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2510" source="BID" patch="1" adv="1">2510</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-008.html" source="REDHAT" patch="1" adv="1">RHSA-2001:008</ref>
      <ref url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-014.0.txt" source="CALDERA" patch="1" adv="1">CSSA-2001-014.0</ref>
      <ref url="http://xforce.iss.net/static/6259.php" source="XF">vim-elevate-privileges(6259)</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2001_012_vim.html" source="SUSE">SuSE-SA:2001:12</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-035.php3" source="MANDRAKE">MDKSA-2001:035</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98593106111968&amp;w=2" source="BUGTRAQ">20010329 Immunix OS Security update for vim</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vim_development_group" name="vim">
        <vers num="5.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0409" published="2001-06-18" name="CVE-2001-0409" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">vim (aka gvim) allows local users to modify files being edited by other users via a symlink attack on the backup and swap files, when the victim is editing the file in a world writable directory.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-014.0.txt" source="CALDERA" patch="1" adv="1">CSSA-2001-014.0</ref>
      <ref url="http://xforce.iss.net/static/6628.php" source="XF">vim-tmp-symlink(6628)</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2001_012_vim.html" source="SUSE">SuSE-SA:2001:12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vim_development_group" name="vim">
        <vers num="5.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0410" published="2001-06-18" name="CVE-2001-0410" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Trend Micro Virus Buster 2001 8.02 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long "From" header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98593642520755&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010330 Virus Buster 2001(ver8.02) Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="virus_buster_2001">
        <vers num="8.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0411" published="2001-06-18" name="CVE-2001-0411" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Reliant Unix 5.44 and earlier allows remote attackers to cause a denial of service via an ICMP port unreachable packet, which causes Reliant to drop all connections to the source address of the packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98658209505849&amp;w=2" source="BUGTRAQ" adv="1">20010406 Reliant Unix 5.43 / 5.44 ICMP port unreachable problem</ref>
    </refs>
    <vuln_soft>
      <prod vendor="siemens" name="reliant_unix">
        <vers num="5.44" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0412" published="2001-06-18" name="CVE-2001-0412" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Cisco Content Services (CSS) switch products 11800 and earlier, aka Arrowpoint, allows local users to gain privileges by entering debug mode.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/arrowpoint-useraccnt-debug-pub.shtml" source="CISCO" patch="1" adv="1">20010404 Cisco Content Services Switch User Account Vulnerability</ref>
      <ref url="http://xforce.iss.net/static/6322.php" source="XF">cisco-css-elevate-privileges(6322)</ref>
      <ref url="http://www.securityfocus.com/bid/2559" source="BID">2559</ref>
      <ref url="http://www.osvdb.org/1784" source="OSVDB">1784</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="content_services_switch_11050">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="content_services_switch_11150">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="content_services_switch_11800">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0413" published="2001-06-18" name="CVE-2001-0413" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BinTec X4000 Access router, and possibly other versions, allows remote attackers to cause a denial of service via a SYN port scan, which causes the router to hang.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98659862317070&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010406 X4000 DoS: Details and workaround</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0145.html" source="BUGTRAQ" patch="1" adv="1">20010410 BinTec Router DoS: Workaround and Details</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98644414226344&amp;w=2" source="BUGTRAQ" adv="1">20010404 BinTec X4000 Access Router DoS Vulnerability</ref>
      <ref url="http://xforce.iss.net/static/6323.php" source="XF">bintec-x4000-nmap-dos(6323)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98697054804197&amp;w=2" source="BUGTRAQ">20010409 BINTEC X1200</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bintec" name="x1000">
        <vers num="" />
      </prod>
      <prod vendor="bintec" name="x1200">
        <vers num="" />
      </prod>
      <prod vendor="bintec" name="x4000">
        <vers num="5.1.6_patch_10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0414" published="2001-06-18" name="CVE-2001-0414" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in ntpd ntp daemon 4.0.99k and earlier (aka xntpd and xntp3) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long readvar argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2540" source="BID" patch="1" adv="1">2540</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-036.php3" source="MANDRAKE" patch="1" adv="1">MDKSA-2001:036</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98651866104663&amp;w=2" source="DEBIAN" adv="1">DSA-045</ref>
      <ref url="http://xforce.iss.net/static/6321.php" source="XF">ntpd-remote-bo(6321)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-045.html" source="REDHAT">RHSA-2001:045</ref>
      <ref url="http://www.osvdb.org/805" source="OSVDB">805</ref>
      <ref url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-013.0.txt" source="CALDERA">CSSA-2001-013</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98684532921941&amp;w=2" source="BUGTRAQ">20010409 ntpd - new Debian 2.2 (potato) version is also vulnerable</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98684202610470&amp;w=2" source="BUGTRAQ">20010409 PROGENY-SA-2001-02: ntpd remote buffer overflow</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98683952401753&amp;w=2" source="BUGTRAQ">20010409 ntp-4.99k23.tar.gz is available</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98679815917014&amp;w=2" source="BUGTRAQ">20010408 [slackware-security] buffer overflow fix for NTP</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98659782815613&amp;w=2" source="BUGTRAQ">20010406 Immunix OS Security update for ntp and xntp3</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98654963328381&amp;w=2" source="BUGTRAQ">20010405 Re: ntpd =&lt; 4.0.99k remote buffer overflow]</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98642418618512&amp;w=2" source="BUGTRAQ">20010404 ntpd =&lt; 4.0.99k remote buffer overflow</ref>
      <ref url="http://lists.suse.com/archives/suse-security-announce/2001-Apr/0000.html" source="SUSE">SuSE-SA:2001:10</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000392" source="CONECTIVA">CLA-2001:392</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0314.html" source="BUGTRAQ">20010418 IBM MSS Outside Advisory Redistribution: IBM AIX: Buffer Overflow Vulnerability in (x)ntp</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0225.html" source="BUGTRAQ">20010413 PROGENY-SA-2001-02A: [UPDATE] ntpd remote buffer overflow</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0127.html" source="BUGTRAQ">20010409 [ESA-20010409-01] xntp buffer overflow</ref>
      <ref url="ftp://ftp.sco.com/SSE/sse074.ltr" source="SCO">SSE074</ref>
      <ref url="ftp://ftp.sco.com/SSE/sse073.ltr" source="SCO">SSE073</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA2001-004.txt.asc" source="NETBSD">NetBSD-SA2001-004</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:31.ntpd.asc" source="FREEBSD">FreeBSD-SA-01:31</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3831" source="OVAL" sig="1">oval:org.mitre.oval:def:3831</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dave_mills" name="ntpd">
        <vers num="4.0.99" />
        <vers num="4.0.99a" />
        <vers num="4.0.99b" />
        <vers num="4.0.99c" />
        <vers num="4.0.99d" />
        <vers num="4.0.99e" />
        <vers num="4.0.99f" />
        <vers num="4.0.99g" />
        <vers num="4.0.99h" />
        <vers num="4.0.99i" />
        <vers num="4.0.99j" />
        <vers prev="1" num="4.0.99k" />
      </prod>
      <prod vendor="dave_mills" name="xntp3">
        <vers num="5.93" />
        <vers num="5.93a" />
        <vers num="5.93b" />
        <vers num="5.93c" />
        <vers num="5.93d" />
        <vers num="5.93e" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0415" published="2001-06-27" name="CVE-2001-0415" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">REDIPlus program, REDI.exe, stores passwords and user names in cleartext in the StartLog.txt log file, which allows local users to gain access to other accounts.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6276.php" source="XF" patch="1" adv="1">rediplus-weak-security</ref>
      <ref url="http://www.securityfocus.com/bid/2495" source="BID" patch="1" adv="1">2495</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0275.html" source="BUGTRAQ" patch="1" adv="1">20010320 Password stored in clear text vulnerability in real time stock trading program</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redi" name="rediplus">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0416" published="2001-06-27" name="CVE-2001-0416" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">sgml-tools (aka sgmltools) before 1.0.9-15 creates temporary files with insecure permissions, which allows other users to read files that are being processed by sgml-tools.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-027.html" source="REDHAT" patch="1" adv="1">RHSA-2001:027</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-030.php3" source="MANDRAKE" patch="1" adv="1">MDKSA-2001:030</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98477491130367&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010316 Immunix OS Security update for sgml-tools</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000390" source="CONECTIVA" patch="1" adv="1">CLA-2001:390</ref>
      <ref url="http://www.debian.org/security/2001/dsa-038" source="DEBIAN" adv="1">DSA-038</ref>
      <ref url="http://xforce.iss.net/static/6201.php" source="XF">sgmltools-symlink</ref>
      <ref url="http://www.securityfocus.com/bid/2683" source="BID">2683</ref>
      <ref url="http://www.securityfocus.com/bid/2506" source="BID">2506</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2001_016_sgmltool_txt.html" source="SUSE">SuSE-SA:2001:16</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="sgml-tools">
        <vers num="1.0.9.15" />
      </prod>
      <prod vendor="immunix" name="immunix">
        <vers num="6.2" />
        <vers num="7.0" />
        <vers num="7.0_beta" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0417" published="2001-06-27" name="CVE-2001-0417" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Kerberos 4 (aka krb4) allows local users to overwrite arbitrary files via a symlink attack on new ticket files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0078.html" source="BUGTRAQ" patch="1" adv="1">20010307 Security advisory: Unsafe temporary file handling in krb4</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-025.html" source="REDHAT">RHSA-2001:025</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="4" />
        <vers num="5-1.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0418" published="2001-07-02" name="CVE-2001-0418" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">content.pl script in NCM Content Management System allows remote attackers to read arbitrary contents of the content database by inserting SQL characters into the id parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2584" source="BID" patch="1" adv="1">2584</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0223.html" source="BUGTRAQ" adv="1">20010413 Exploitable NCM.at - Content Management System</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ncm" name="ncm_content_management_system">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0419" published="2001-07-02" name="CVE-2001-0419" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in shared library ndwfn4.so for iPlanet Web Server (iWS) 4.1, when used as a web listener for Oracle application server 4.0.8.2, allows remote attackers to execute arbitrary commands via a long HTTP request that is passed to the application server, such as /jsp/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2569" source="BID" adv="1">2569</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98692227816141&amp;w=2" source="BUGTRAQ" adv="1">20010410 Oracle Application Server shared library buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="4.0.8.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0420" published="2001-06-18" name="CVE-2001-0420" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in talkback.cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the article parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2547" source="BID" patch="1" adv="1">2547</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0128.html" source="BUGTRAQ" patch="1" adv="1">20010409 talkback.cgi vulnerability may allow users to read any file</ref>
    </refs>
    <vuln_soft>
      <prod vendor="way_to_the_web" name="talkback">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0421" published="2001-07-02" name="CVE-2001-0421" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">FTP server in Solaris 8 and earlier allows local and remote attackers to cause a core dump in the root directory, possibly with world-readable permissions, by providing a valid username with an invalid password followed by a CWD ~ command, which could release sensitive information such as shadowed passwords, or fill the disk partition.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2601" source="BID" adv="1">2601</ref>
      <ref url="http://www.securityfocus.com/archive/1/177200" source="BUGTRAQ">20010417 Re: SUN SOLARIS 5.6/5.7 FTP Globbing Exploit !</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" />
        <vers prev="1" num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0422" published="2001-07-02" name="CVE-2001-0422" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Xsun in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2561" source="BID" patch="1" adv="1">2561</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0158.html" source="BUGTRAQ" patch="1" adv="1">20010410 Solaris Xsun buffer overflow vulnerability</ref>
      <ref url="http://xforce.iss.net/static/6343.php" source="XF">solaris-xsun-home-bo(6343)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:555" source="OVAL" sig="1">oval:org.mitre.oval:def:555</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.5.1" />
        <vers num="2.6" />
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0423" published="2001-07-02" name="CVE-2001-0423" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in ipcs in Solaris 7 x86 allows local users to execute arbitrary code via a long TZ (timezone) environmental variable, a different vulnerability than CAN-2002-0093.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2581" source="BID" patch="1" adv="1">2581</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0217.html" source="BUGTRAQ" patch="1" adv="1">20010412 Solaris ipcs vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6369" source="XF" adv="1">solaris-ipcs-bo(6369)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0424" published="2001-07-02" name="CVE-2001-0424" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">BubbleMon 1.31 does not properly drop group privileges before executing programs, which allows local users to execute arbitrary commands with the kmem group id.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2609" source="BID" patch="1" adv="1">2609</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98744422105430&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010415 BubbleMon 1.31</ref>
    </refs>
    <vuln_soft>
      <prod vendor="timecop" name="bubblemon">
        <vers num="1.0" />
        <vers num="1.0pl1" />
        <vers num="1.0pl2" />
        <vers num="1.0pl3" />
        <vers num="1.0pl4" />
        <vers num="1.0pl6" />
        <vers num="1.0pl7" />
        <vers num="1.0pl8" />
        <vers num="1.0pl9" />
        <vers num="1.1" />
        <vers num="1.1test1" />
        <vers num="1.1test2" />
        <vers num="1.1test3" />
        <vers num="1.1test4" />
        <vers num="1.1test5" />
        <vers num="1.1test6" />
        <vers num="1.1test7" />
        <vers num="1.2" />
        <vers num="1.21" />
        <vers num="1.21test1" />
        <vers num="1.22" />
        <vers num="1.23" />
        <vers num="1.2test1" />
        <vers num="1.3" />
        <vers num="1.31" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="6.2" edition="stable" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0425" published="2001-06-27" name="CVE-2001-0425" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">AdLibrary.pm in AdCycle 0.78b allows remote attackers to gain privileges to AdCycle via a malformed Agent: header in the HTTP request, which is inserted into a resulting SQL query that is used to verify login information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/163942" source="BUGTRAQ" patch="1" adv="1">20010219 Adcycle 0.78b Authentication</ref>
      <ref url="http://www.securityfocus.com/bid/2393" source="BID" adv="1">2393</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adcycle" name="adcycle">
        <vers num="0.77" />
        <vers num="0.78b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0426" published="2001-07-02" name="CVE-2001-0426" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in dtsession on Solaris, and possibly other operating systems, allows local users to gain privileges via a long LANG environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0203.html" source="BUGTRAQ" adv="1">20010411 [LSD] Solaris kcsSUNWIOsolf.so and dtsession vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0427" published="2001-06-18" name="CVE-2001-0427" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via a flood of invalid login requests to (1) the SSL service, or (2) the telnet service, which do not properly disconnect the user after several failed login attempts.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/vpn3k-telnet-vuln-pub.shtml" source="CISCO" patch="1" adv="1">20010328 VPN3000 Concentrator TELNET Vulnerability</ref>
      <ref url="http://xforce.iss.net/static/6298.php" source="XF">cisco-vpn-telnet-dos(6298)</ref>
      <ref url="http://www.osvdb.org/5643" source="OSVDB">5643</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="vpn_3000_concentrator">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="vpn_3005_concentrator">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="vpn_3015_concentrator">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="vpn_3030_concentator">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="vpn_3060_concentrator">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="vpn_3080_concentrator">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0428" published="2001-07-02" name="CVE-2001-0428" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via an IP packet with an invalid IP option.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2573" source="BID" patch="1" adv="1">2573</ref>
      <ref url="http://www.cisco.com/warp/public/707/vpn3k-ipoptions-vuln-pub.shtml" source="CISCO" patch="1" adv="1">20010412 VPN 3000 Concentrator IP Options Vulnerability</ref>
      <ref url="http://xforce.iss.net/static/6360.php" source="XF">cisco-vpn-ip-dos(6360)</ref>
      <ref url="http://www.osvdb.org/1786" source="OSVDB">1786</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="vpn_3000_concentrator">
        <vers num="2.5.2.a" />
        <vers num="2.5.2.b" />
        <vers num="2.5.2.c" />
        <vers num="2.5.2.d" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0429" published="2001-07-02" name="CVE-2001-0429" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco Catalyst 5000 series switches 6.1(2) and earlier will forward an 802.1x frame on a Spanning Tree Protocol (STP) blocked port, which causes a network storm and a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2604" source="BID" patch="1" adv="1">2604</ref>
      <ref url="http://www.cisco.com/warp/public/707/cat5k-8021x-vuln-pub.shtml" source="CISCO" patch="1" adv="1">20010416 Catalyst 5000 Series 802.1x Vulnerability</ref>
      <ref url="http://xforce.iss.net/static/6379.php" source="XF">cisco-catalyst-8021x-dos(6379)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/l-072.shtml" source="CIAC">L-072</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="catos">
        <vers num="4.5(11)" />
        <vers num="4.5.10" />
        <vers num="5.5(4b)" />
        <vers num="5.5(6)" />
        <vers num="6.1(1c)" />
        <vers num="6.1(2)" />
        <vers num="6.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0430" published="2001-07-02" name="CVE-2001-0430" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Vulnerability in exuberant-ctags before 3.2.4-0.1 insecurely creates temporary files.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/vendor/2001-q2/0005.html" source="DEBIAN" adv="1">DSA-046</ref>
      <ref url="http://xforce.iss.net/static/6388.php" source="XF">exuberant-ctags-symlink(6388)</ref>
      <ref url="http://www.osvdb.org/5642" source="OSVDB">5642</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.2" />
        <vers prev="1" num="3.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0431" published="2001-07-02" name="CVE-2001-0431" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Vulnerability in iPlanet Web Server Enterprise Edition 4.x.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.iplanet.com/products/iplanet_web_enterprise/iwsalert4.16.html" source="BUGTRAQ" patch="1" adv="1">20010417 iPlanet Web Server 4.x Product Alert</ref>
      <ref url="http://www.iplanet.com/products/iplanet_web_enterprise/iwsalert4.16.html" source="CONFIRM">http://www.iplanet.com/products/iplanet_web_enterprise/iwsalert4.16.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iplanet" name="iplanet_web_server">
        <vers num="4.x_enterprise" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0432" published="2001-07-02" name="CVE-2001-0432" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflows in various CGI programs in the remote administration service for Trend Micro Interscan VirusWall 3.01 allow remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2579" source="BID" patch="1" adv="1">2579</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0218.html" source="BUGTRAQ" adv="1">20010413 Trend Micro Interscan VirusWall 3.01 vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="interscan_viruswall">
        <vers num="3.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0433" published="2001-06-18" name="CVE-2001-0433" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Savant 3.0 web server allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long Host HTTP header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98655083231635&amp;w=2" source="BUGTRAQ" adv="1">20010405 Savant 3.0 Denial Of Service</ref>
    </refs>
    <vuln_soft>
      <prod vendor="micheal_lamont" name="savant_webserver">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0434" published="2001-07-02" name="CVE-2001-0434" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The LogDataListToFile ActiveX function used in (1) Knowledge Center and (2) Back web components of Compaq Presario computers allows remote attackers to modify arbitrary files and cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://ftp.support.compaq.com/patches/.new/html/SSRT0716-01.shtml" source="COMPAQ" patch="1" adv="1">SSRT0716</ref>
      <ref url="http://xforce.iss.net/static/6355.php" source="XF">compaq-activex-dos(6355)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="compaq" name="presario">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0435" published="2001-07-02" name="CVE-2001-0435" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The split key mechanism used by PGP 7.0 allows a key share holder to obtain access to the entire key by setting the "Cache passphrase while logged on" option and capturing the passphrases of other share holders as they authenticate.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98691775527457&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010410 [wsir-01/02-03] PGP 7.0 Split Key/Cached Passphrase Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pgp" name="pgp">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0436" published="2001-07-02" name="CVE-2001-0436" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">dcboard.cgi in DCForum 2000 1.0 allows remote attackers to execute arbitrary commands by uploading a Perl program to the server and using a .. (dot dot) in the AZ parameter to reference the program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2611" source="BID" patch="1" adv="1">2611</ref>
      <ref url="http://www.dcscripts.com/FAQ/sec_2001_03_31.html" source="CONFIRM" patch="1">http://www.dcscripts.com/FAQ/sec_2001_03_31.html</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0269.html" source="BUGTRAQ" patch="1" adv="1">20010416 qDefense Advisory: DCForum allows remote read/write/execute</ref>
      <ref url="http://xforce.iss.net/static/6392.php" source="XF">dcforum-az-expr(6392)</ref>
      <ref url="http://www.osvdb.org/3862" source="OSVDB">3862</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dcscripts" name="dcforum">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="6.0" />
      </prod>
      <prod vendor="dcscripts" name="dcforum_2000">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0437" published="2001-07-02" name="CVE-2001-0437" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">upload_file.pl in DCForum 2000 1.0 allows remote attackers to upload arbitrary files without authentication by setting the az parameter to upload_file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2611" source="BID" patch="1" adv="1">2611</ref>
      <ref url="http://www.dcscripts.com/FAQ/sec_2001_03_31.html" source="CONFIRM" patch="1" adv="1">http://www.dcscripts.com/FAQ/sec_2001_03_31.html</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0269.html" source="BUGTRAQ" patch="1" adv="1">20010416 qDefense Advisory: DCForum allows remote read/write/execute</ref>
      <ref url="http://xforce.iss.net/static/6393.php" source="XF">dcforum-az-file-upload(6393)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dcscripts" name="dcforum">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="6.0" />
      </prod>
      <prod vendor="dcscripts" name="dcforum_2000">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0438" published="2001-07-02" name="CVE-2001-0438" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Preview version of Timbuktu for Mac OS X allows local users to modify System Preferences without logging in via the About Timbuktu menu.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0337.html" source="BUGTRAQ" adv="1">20010418 Hole in Netopia's Mac OS X Timbuktu</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netopia" name="timbuktu_mac">
        <vers num="initial" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0439" published="2001-07-02" name="CVE-2001-0439" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">licq before 1.0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6261.php" source="XF" patch="1" adv="1">licq-url-execute-commands(6261)</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-032.php3" source="MANDRAKE" patch="1" adv="1">MDKSA-2001:032</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000389" source="CONECTIVA" patch="1">CLA-2001:389</ref>
      <ref url="http://archives.neohapsis.com/archives/freebsd/2001-04/0607.html" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-01:35</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-023.html" source="REDHAT">RHSA-2001:023</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-022.html" source="REDHAT">RHSA-2001:022</ref>
      <ref url="http://www.osvdb.org/5641" source="OSVDB">5641</ref>
    </refs>
    <vuln_soft>
      <prod vendor="licq" name="licq">
        <vers prev="1" num="1.0.2" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="4.0" />
        <vers num="4.0es" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.0" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.5.1" />
        <vers num="4.2" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="1.0.1" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0440" published="2001-07-02" name="CVE-2001-0440" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in logging functions of licq before 1.0.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-032.php3" source="MANDRAKE" patch="1" adv="1">MDKSA-2001:032</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000389" source="CONECTIVA" patch="1" adv="1">CLA-2001:389</ref>
      <ref url="http://archives.neohapsis.com/archives/freebsd/2001-04/0607.html" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-01:35</ref>
      <ref url="http://xforce.iss.net/static/6645.php" source="XF">licq-logging-bo(6645)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-023.html" source="REDHAT">RHSA-2001:023</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-022.html" source="REDHAT">RHSA-2001:022</ref>
      <ref url="http://www.osvdb.org/5601" source="OSVDB">5601</ref>
    </refs>
    <vuln_soft>
      <prod vendor="licq" name="licq">
        <vers prev="1" num="1.0.2" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="4.0" />
        <vers num="4.0es" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="6.0" />
        <vers num="ecommerce" />
        <vers num="prg_graficos" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0441" published="2001-06-27" name="CVE-2001-0441" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in (1) wrapping and (2) unwrapping functions of slrn news reader before 0.9.7.0 allows remote attackers to execute arbitrary commands via a long message header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-028.html" source="REDHAT" patch="1" adv="1">RHSA-2001:028</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-028.php3" source="MANDRAKE" patch="1" adv="1">MDKSA-2001:028</ref>
      <ref url="http://www.debian.org/security/2001/dsa-040" source="DEBIAN" patch="1" adv="1">DSA-040</ref>
      <ref url="http://archives.neohapsis.com/archives/freebsd/2001-04/0610.html" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-01:37</ref>
      <ref url="http://xforce.iss.net/static/6213.php" source="XF">slrn-wrapping-bo</ref>
      <ref url="http://www.securityfocus.com/bid/2493" source="BID">2493</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98471253131191&amp;w=2" source="BUGTRAQ">20010316 Immunix OS Security update for slrn</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000383" source="CONECTIVA">CLA-2001:383</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers prev="1" num="2.2" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="1.0.1" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="6.2" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0442" published="2001-06-27" name="CVE-2001-0442" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Mercury MTA POP3 server for NetWare 1.48 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long APOP command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2641" source="BID" patch="1" adv="1">2641</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0378.html" source="BUGTRAQ" adv="1">20010421 Mercury for NetWare POP3 server vulnerable to remote buffer overflow</ref>
      <ref url="http://www.iss.net/security_center/static/6444.php" source="XF">mercury-mta-bo(6444)</ref>
      <ref url="http://online.securityfocus.com/archive/1/179217" source="BUGTRAQ">20010424 Re: Mercury for NetWare POP3 server vulnerable to remote buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="david_harris" name="mercury_nlm">
        <vers num="1.45" />
        <vers num="1.46" />
        <vers num="1.47" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0443" published="2001-07-02" name="CVE-2001-0443" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in QPC QVT/Net Popd 4.20 in QVT/Net 5.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via (1) a long username, or (2) a long password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0227.html" source="BUGTRAQ" adv="1">20010413 QPC POPd Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qpc_software" name="qvt_net">
        <vers num="5.0" />
      </prod>
      <prod vendor="qpc_software" name="qvt_term_plus">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0444" published="2001-07-02" name="CVE-2001-0444" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Cisco CBOS 2.3.0.053 sends output of the "sh nat" (aka "show nat") command to the terminal of the next user who attempts to connect to the router via telnet, which could allow that user to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2635" source="BID" adv="1">2635</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0380.html" source="BUGTRAQ" adv="1">20010420 Bug in Cisco CBOS v2.3.0.053</ref>
      <ref url="http://xforce.iss.net/static/6453.php" source="XF">cisco-cbos-gain-information(6453)</ref>
      <ref url="http://www.osvdb.org/1796" source="OSVDB">1796</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="cbos">
        <vers num="2.3.053" />
        <vers num="2.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0446" published="2001-06-18" name="CVE-2001-0446" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IBM WCS (WebSphere Commerce Suite) 4.0.1 with Application Server 3.0.2 allows remote attackers to read source code for .jsp files by appending a / to the requested URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98583082225053&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010328 CHINANSL Security Advisory(CSA-200107)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_commerce_suite">
        <vers num="4.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0447" published="2001-06-18" name="CVE-2001-0447" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Web configuration server in 602Pro LAN SUITE allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP request containing "%2e" (dot dot) characters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2514" source="BID" adv="1">2514</ref>
      <ref url="http://www.securityfocus.com/archive/1/171418" source="BUGTRAQ" adv="1">20010326 602Pro Lansuite Denial Of Service 1.0.34</ref>
    </refs>
    <vuln_soft>
      <prod vendor="software602" name="602pro_lan_suite">
        <vers num="2000a_2000.0.1.34" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0448" published="2001-06-18" name="CVE-2001-0448" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Web configuration server in 602Pro LAN SUITE allows remote attackers to cause a denial of service via an HTTP GET HTTP request to the aux directory, and possibly other directories with legacy DOS device names.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/171418" source="BUGTRAQ" adv="1">20010326 602Pro Lansuite Denial Of Service 1.0.34</ref>
    </refs>
    <vuln_soft>
      <prod vendor="software602" name="602pro_lan_suite">
        <vers prev="1" num="2000a_1.0.34" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0449" published="2001-06-27" name="CVE-2001-0449" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in WinZip 8.0 allows attackers to execute arbitrary commands via a long file name that is processed by the /zipandemail command line option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6191.php" source="XF" adv="1">winzip-zipandemail-bo(6191)</ref>
      <ref url="http://www.securityfocus.com/archive/1/166211" source="BUGTRAQ" adv="1">20010302 def-2001-09: Winzip32 zipandemail Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="winzip" name="winzip">
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0450" published="2001-06-27" name="CVE-2001-0450" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Transsoft FTP Broker before 5.5 allows attackers to (1) delete arbitrary files via DELETE, or (2) list arbitrary directories via LIST, via a .. (dot dot) in the file name.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6190.php" source="XF" adv="1">broker-ftp-delete-files</ref>
      <ref url="http://xforce.iss.net/static/6189.php" source="XF" adv="1">broker-ftp-list-directories</ref>
      <ref url="http://www.ftp-broker.com/cgibin/Pageexe.exe?H=4143&amp;P=0&amp;C=0" source="CONFIRM" adv="1">http://www.ftp-broker.com/cgibin/Pageexe.exe?H=4143&amp;P=0&amp;C=0</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0533.html" source="BUGTRAQ" adv="1">20010303 Broker Ftp Server 5.0 Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="transsoft" name="broker_ftp_server">
        <vers prev="1" num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0451" published="2001-06-27" name="CVE-2001-0451" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">INDEXU 2.0 beta and earlier allows remote attackers to bypass authentication and gain privileges by setting the cookie_admin_authenticated cookie value to 1.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6202.php" source="XF" patch="1" adv="1">indexu-gain-access</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sentraweb" name="indexu">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="2.0beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0452" published="2001-06-27" name="CVE-2001-0452" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BRS WebWeaver FTP server before 0.64 Beta allows remote attackers to obtain the real pathname of the server via a "CD *" command followed by an ls command.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/180506" source="BUGTRAQ" patch="1" adv="1">20010428 Vulnerabilities in BRS WebWeaver</ref>
      <ref url="http://www.securityfocus.com/bid/2676" source="BID" adv="1">2676</ref>
      <ref url="http://members.nbci.com/_XMCM/BSoutham/WebWeaver/WebWeaverHistory.html" source="CONFIRM">http://members.nbci.com/_XMCM/BSoutham/WebWeaver/WebWeaverHistory.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="brs" name="webweaver">
        <vers num="0.49_beta" />
        <vers num="0.50_beta" />
        <vers num="0.51_beta" />
        <vers num="0.52_beta" />
        <vers num="0.60_beta" />
        <vers num="0.61_beta" />
        <vers num="0.62_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0453" published="2001-06-27" name="CVE-2001-0453" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in BRS WebWeaver HTTP server allows remote attackers to read arbitrary files via a .. (dot dot) attack in the (1) syshelp, (2) sysimages, or (3) scripts directories.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0519.html" source="BUGTRAQ" patch="1" adv="1">20010428 Vulnerabilities in BRS WebWeaver </ref>
      <ref url="http://www.securityfocus.com/bid/2675" source="BID">2675</ref>
      <ref url="http://members.nbci.com/_XMCM/BSoutham/WebWeaver/WebWeaverHistory.html" source="CONFIRM">http://members.nbci.com/_XMCM/BSoutham/WebWeaver/WebWeaverHistory.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="brs" name="webweaver">
        <vers num="0.49_beta" />
        <vers num="0.50_beta" />
        <vers num="0.51_beta" />
        <vers num="0.52_beta" />
        <vers num="0.60_beta" />
        <vers num="0.61_beta" />
        <vers num="0.62_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0454" published="2001-06-27" name="CVE-2001-0454" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in SlimServe HTTPd 1.1a allows remote attackers to read arbitrary files via a ... (modified dot dot) in the HTTP request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0532.html" source="BUGTRAQ" patch="1" adv="1">20010303 SlimServe HTTPd ver. 1.1a Directory Traversal</ref>
      <ref url="http://xforce.iss.net/static/6186.php" source="XF" adv="1">slimserve-httpd-directory-traversal</ref>
    </refs>
    <vuln_soft>
      <prod vendor="whitsoft" name="slimserve">
        <vers prev="1" num="1.1a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0455" published="2001-06-27" name="CVE-2001-0455" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cisco Aironet 340 Series wireless bridge before 8.55 does not properly disable access to the web interface, which allows remote attackers to modify its configuration.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6200.php" source="XF" patch="1" adv="1">cisco-aironet-web-access(6200)</ref>
      <ref url="http://www.cisco.com/warp/public/707/Aironet340-pub.shtml" source="CISCO" patch="1" adv="1">20010307 Access to the Cisco Aironet 340 Series Wireless Bridge via Web Interface</ref>
      <ref url="http://www.osvdb.org/5597" source="OSVDB">5597</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="aironet_340">
        <vers prev="1" num="8.55" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0456" published="2001-06-27" name="CVE-2001-0456" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">postinst installation script for Proftpd in Debian 2.2 does not properly change the "run as uid/gid root" configuration when the user enables anonymous access, which causes the server to run at a higher privilege than intended.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6208.php" source="XF" patch="1" adv="1">proftpd-postinst-root(6208)</ref>
      <ref url="http://www.debian.org/security/2001/dsa-032" source="DEBIAN" patch="1" adv="1">DSA-032</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0457" published="2001-06-27" name="CVE-2001-0457" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">man2html before 1.5-22 allows remote attackers to cause a denial of service (memory exhaustion).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6211.php" source="XF" patch="1" adv="1">man2html-remote-dos(6211)</ref>
      <ref url="http://www.debian.org/security/2001/dsa-035" source="DEBIAN" patch="1" adv="1">DSA-035</ref>
      <ref url="http://www.osvdb.org/5631" source="OSVDB">5631</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0458" published="2001-06-27" name="CVE-2001-0458" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in ePerl before 2.2.14-0.7 allow local and remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6198.php" source="XF" patch="1" adv="1">linux-eperl-bo</ref>
      <ref url="http://www.securityfocus.com/bid/2464" source="BID" patch="1" adv="1">2464</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-027.php3" source="MANDRAKE" patch="1" adv="1">MDKSA-2001:027</ref>
      <ref url="http://www.debian.org/security/2001/dsa-034" source="DEBIAN" patch="1" adv="1">DSA-034</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2001_008_eperl.html" source="SUSE">SuSE-SA:2001:08</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ralf_s._engelschall" name="eperl">
        <vers num="2.2.12" />
        <vers num="2.2.13" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="2.2" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="6.3" />
        <vers num="6.4" />
        <vers num="7.0" />
        <vers num="7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0459" published="2001-06-27" name="CVE-2001-0459" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflows in ascdc Afterstep while running setuid allows local users to gain root privileges via a long (1) -d option, (2) -m option, or (3) -f option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6204.php" source="XF" adv="1">ascdc-afterstep-bo</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98408897106411&amp;w=2" source="BUGTRAQ">20010308 ascdc Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="afterstep.org" name="afterstep">
        <vers num="" />
      </prod>
      <prod vendor="rob_malda" name="ascdc">
        <vers num="0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0460" published="2001-06-27" name="CVE-2001-0460" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Websweeper 4.0 does not limit the length of certain HTTP headers, which allows remote attackers to cause a denial of service (memory exhaustion) via an extremely large HTTP Referrer: header.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/167406" source="BUGTRAQ" patch="1" adv="1">20010308 def-2001-10: Websweeper Infinite HTTP Request DoS</ref>
      <ref url="http://xforce.iss.net/static/6214.php" source="XF" adv="1">websweeper-http-dos</ref>
    </refs>
    <vuln_soft>
      <prod vendor="baltimore_technologies" name="websweeper">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0461" published="2001-06-27" name="CVE-2001-0461" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">template.cgi in Free On-Line Dictionary of Computing (FOLDOC) allows remote attackers to read files and execute commands via shell metacharacters in the argument to template.cgi.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6217.php" source="XF" patch="1" adv="1">foldoc-cgi-execute-commands</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0109.html" source="BUGTRAQ" patch="1" adv="1">20010309 Cgisecurity.com advisory #4 The Free On-line Dictionary of Computing</ref>
      <ref url="http://wombat.doc.ic.ac.uk/foldoc/index.html" source="CONFIRM">http://wombat.doc.ic.ac.uk/foldoc/index.html</ref>
      <ref url="http://www.osvdb.org/5591" source="OSVDB">5591</ref>
    </refs>
    <vuln_soft>
      <prod vendor="denis_howe" name="foldoc">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0462" published="2001-06-27" name="CVE-2001-0462" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Perl web server 0.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2648" source="BID" adv="1">2648</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0426.html" source="BUGTRAQ" adv="1">20010424 Advisory for perl webserver</ref>
      <ref url="http://xforce.iss.net/static/6451.php" source="XF">perl-webserver-directory-traversal(6451)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="spencer_christensen" name="perl_web_server">
        <vers num="0.0.1" />
        <vers num="0.0.2" />
        <vers num="0.0.3" />
        <vers num="0.0.4" />
        <vers num="0.0.9" />
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0463" published="2001-06-27" name="CVE-2001-0463" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in cal_make.pl in PerlCal allows remote attackers to read arbitrary files via a .. (dot dot) in the p0 parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2663" source="BID" patch="1" adv="1">2663</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0506.html" source="BUGTRAQ" patch="1" adv="1">20010427 PerlCal (CGI) show files vulnerability</ref>
      <ref url="http://xforce.iss.net/static/6480.php" source="XF">perlcal-calmake-directory-traversal(6480)</ref>
      <ref url="http://www.perlcal.com/calendar/docs/bugs.txt" source="CONFIRM">http://www.perlcal.com/calendar/docs/bugs.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="acme_labs" name="perlcal">
        <vers num="2.13" />
        <vers num="2.18" />
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.6" />
        <vers num="2.7" />
        <vers num="2.80" />
        <vers num="2.9" />
        <vers num="2.95" />
        <vers num="2.9a" />
        <vers num="2.9b" />
        <vers num="2.9c" />
        <vers num="2.9d" />
        <vers num="2.9e" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0464" published="2001-07-02" name="CVE-2001-0464" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in websync.exe in Cyberscheduler allows remote attackers to execute arbitrary commands via a long tzs (timezone) parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2628" source="BID" patch="1" adv="1">2628</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98761402029302&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010417 Cyberscheduler remote root compromise</ref>
    </refs>
    <vuln_soft>
      <prod vendor="crosswind" name="cyberscheduler">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0465" published="2001-06-18" name="CVE-2001-0465" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">TurboTax saves passwords in a temporary file when a user imports investment tax information from a financial institution, which could allow local users to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98653594732053&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010405 </ref>
      <ref url="http://www.turbotax.com/atr/update/" source="CONFIRM">http://www.turbotax.com/atr/update/</ref>
      <ref url="http://xforce.iss.net/static/6622.php" source="XF">turbotax-save-passwords(6622)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intuit" name="turbo_tax">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0466" published="2001-06-18" name="CVE-2001-0466" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in ustorekeeper 1.61 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98633176230748&amp;w=2" source="BUGTRAQ" adv="1">20010403 new advisory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microburst" name="ustorekeeper_online_shopping_system">
        <vers num="1.61" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0467" published="2001-06-27" name="CVE-2001-0467" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in RobTex Viking Web server before 1.07-381 allows remote attackers to read arbitrary files via a \... (modified dot dot) in an HTTP URL request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2643" source="BID" patch="1" adv="1">2643</ref>
      <ref url="http://www.securityfocus.com/archive/1/178935" source="BUGTRAQ" patch="1" adv="1">20010423 Vulnerability in Viking Web Server</ref>
      <ref url="http://www.robtex.com/files/viking/beta/chglog.txt" source="CONFIRM">http://www.robtex.com/files/viking/beta/chglog.txt</ref>
      <ref url="http://xforce.iss.net/static/6450.php" source="XF">viking-dot-directory-traversal(6450)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="robtex" name="viking_server">
        <vers prev="1" num="1.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0468" published="2001-06-27" name="CVE-2001-0468" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in FTPFS allows local users to gain root privileges via a long user name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6234.php" source="XF" adv="1">ftpfs-bo</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0163.html" source="BUGTRAQ" adv="1">20010313 Buffer oveflow in FTPFS (linux kernel module)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ftpfs" name="ftpfs">
        <vers num="0.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0469" published="2001-06-27" name="CVE-2001-0469" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">rwho daemon rwhod in FreeBSD 4.2 and earlier, and possibly other operating systems, allows remote attackers to cause a denial of service via malformed packets with a short length.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6229.php" source="XF" patch="1" adv="1">rwhod-remote-dos(6229)</ref>
      <ref url="http://www.securityfocus.com/bid/2473" source="BID" patch="1" adv="1">2473</ref>
      <ref url="http://archives.neohapsis.com/archives/freebsd/2001-03/0163.html" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-01:29</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers prev="1" num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0470" published="2001-06-27" name="CVE-2001-0470" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in SNMP proxy agent snmpd in Solaris 8 may allow local users to gain root privileges by calling snmpd with a long program name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6239.php" source="XF" adv="1">snmpd-argv-bo</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0181.html" source="BUGTRAQ" adv="1">20010315 Re: Solaris 5.8 snmpd Vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0160.html" source="BUGTRAQ" adv="1">20010313 Solaris 5.8 snmpd Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="5.8" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0471" published="2001-06-27" name="CVE-2001-0471" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SSH daemon version 1 (aka SSHD-1 or SSH-1) 1.2.30 and earlier does not log repeated login attempts, which could allow remote attackers to compromise accounts without detection via a brute force attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2345" source="BID" patch="1" adv="1">2345</ref>
      <ref url="http://www.securityfocus.com/archive/1/160648" source="BUGTRAQ" patch="1" adv="1">20010205 SSHD-1 Logging Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ssh" name="ssh">
        <vers prev="1" num="1.2.30" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0472" published="2001-06-27" name="CVE-2001-0472" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Hursley Software Laboratories Consumer Transaction Framework (HSLCTF) HTTP object allows remote attackers to cause a denial of service (crash) via an extremely long HTTP request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6250.php" source="XF" patch="1" adv="1">hslctf-http-dos</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0243.html" source="BUGTRAQ" patch="1" adv="1">20010320 def-2001-12: Hursley Software Laboratories Consumer Transaction Framework DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="high_availability_cluster_multiprocessing">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0473" published="2001-06-27" name="CVE-2001-0473" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in Mutt before 1.2.5 allows a remote malicious IMAP server to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6235.php" source="XF" patch="1" adv="1">mutt-imap-format-string(6235)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-029.html" source="REDHAT" patch="1" adv="1">RHSA-2001:029</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-031.php3" source="MANDRAKE" patch="1" adv="1">MDKSA-2001-031</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98473109630421&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010315 Immunix OS Security update for mutt</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0246.html" source="BUGTRAQ" patch="1" adv="1">20010320 Trustix Security Advisory - mutt</ref>
      <ref url="http://www.osvdb.org/5615" source="OSVDB">5615</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000385" source="CONECTIVA">CLA-2001:385</ref>
    </refs>
    <vuln_soft>
      <prod vendor="immunix" name="immunix">
        <vers num="6.2" />
        <vers num="7.0" />
        <vers num="7.0_beta" />
      </prod>
      <prod vendor="mutt" name="mutt">
        <vers prev="1" num="1.2.5" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="5.2" />
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0474" published="2001-06-27" name="CVE-2001-0474" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Utah-glx in Mesa before 3.3-14 on Mandrake Linux 7.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/glxmemory file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6231.php" source="XF" patch="1" adv="1">mesa-utahglx-symlink(6231)</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-029.php3" source="MANDRAKE" patch="1" adv="1">MDKSA-2001:029</ref>
    </refs>
    <vuln_soft>
      <prod vendor="brian_paul" name="mesa">
        <vers prev="1" num="3.3-14" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0475" published="2001-06-27" name="CVE-2001-0475" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">index.php in Jelsoft vBulletin does not properly initialize a PHP variable that is used to store template information, which allows remote attackers to execute arbitrary PHP code via special characters in the templatecache parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6237.php" source="XF" patch="1" adv="1">vbulletin-php-elevate-privileges(6237)</ref>
      <ref url="http://www.vbulletin.com/forum/showthread.php?s=b20af207b5b908ecf7a4ecf56fbe3cd3&amp;threadid=10839" source="CONFIRM" patch="1" adv="1">http://www.vbulletin.com/forum/showthread.php?s=b20af207b5b908ecf7a4ecf56fbe3cd3&amp;threadid=10839</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0180.html" source="BUGTRAQ" patch="1" adv="1">20010315 vBulletin allows arbitrary code execution</ref>
      <ref url="http://www.securityfocus.com/bid/2474" source="BID" adv="1">2474</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jelsoft" name="vbulletin">
        <vers prev="1" num="1.1.5" />
        <vers prev="1" num="2.0_beta_2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0476" published="2001-06-27" name="CVE-2001-0476" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in s.cgi program in Aspseek search engine 1.03 and earlier allow remote attackers to execute arbitrary commands via (1) a long HTTP query string, or (2) a long tmpl parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6248.php" source="XF" patch="1" adv="1">aspseek-scgi-bo</ref>
      <ref url="http://www.aspseek.org/changes.html" source="CONFIRM" patch="1">http://www.aspseek.org/changes.html</ref>
      <ref url="http://www.securityfocus.com/bid/2492" source="BID" adv="1">2492</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0233.html" source="BUGTRAQ" adv="1">20010318 Aspseek Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="swsoft" name="aspseek">
        <vers num="1.0" />
        <vers prev="1" num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0477" published="2001-06-27" name="CVE-2001-0477" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Vulnerability in WebCalendar 0.9.26 allows remote command execution.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0392.html" source="BUGTRAQ" patch="1" adv="1">20010423 (SRPRE00004) WebCalendar 0.9.26</ref>
      <ref url="http://www.securityfocus.com/bid/2639" source="BID" adv="1">2639</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webcalendar" name="webcalendar">
        <vers num="0.9.11" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.19" />
        <vers num="0.9.20" />
        <vers num="0.9.21" />
        <vers num="0.9.22" />
        <vers num="0.9.23" />
        <vers num="0.9.24" />
        <vers num="0.9.25" />
        <vers num="0.9.26" />
        <vers num="0.9.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0478" published="2001-06-27" name="CVE-2001-0478" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in phpMyAdmin 2.2.0 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2642" source="BID" patch="1" adv="1">2642</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0396.html" source="BUGTRAQ" patch="1" adv="1">20010423 (SRPRE00001) phpMyAdmin 2.1.0 and phpPgAdmin 2.2.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyadmin" name="phpmyadmin">
        <vers prev="1" num="2.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0479" published="2001-06-27" name="CVE-2001-0479" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in phpPgAdmin 2.2.1 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2640" source="BID" patch="1" adv="1">2640</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0396.html" source="BUGTRAQ" patch="1" adv="1">20010423 (SRPRE00001) phpMyAdmin 2.1.0 and phpPgAdmin 2.2.1</ref>
      <ref url="http://www.greatbridge.org/project/phppgadmin/cvs/checkout.php/phpPgAdmin/ChangeLog?r=1.13" source="CONFIRM">http://www.greatbridge.org/project/phppgadmin/cvs/checkout.php/phpPgAdmin/ChangeLog?r=1.13</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phppgadmin" name="phppgadmin">
        <vers num="2.2" />
        <vers num="2.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0480" published="2001-06-27" name="CVE-2001-0480" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Alex's FTP Server 0.7 allows remote attackers to read arbitrary files via a ... (modified dot dot) in the (1) GET or (2) CD commands.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0523.html" source="BUGTRAQ" patch="1" adv="1">20010428 Vulnerabilities in Alex's FTP Server </ref>
      <ref url="http://www.securityfocus.com/bid/2668" source="BID" adv="1">2668</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alex_linde" name="alexs_ftp_server">
        <vers num="0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0481" published="2001-06-27" name="CVE-2001-0481" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Vulnerability in rpmdrake in Mandrake Linux 8.0 related to insecure temporary file handling.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-043.php3" source="MANDRAKE" patch="1" adv="1">MDKSA-2001:043</ref>
      <ref url="http://xforce.iss.net/static/6494.php" source="XF">linux-rpmdrake-temp-file(6494)</ref>
      <ref url="http://www.osvdb.org/5612" source="OSVDB">5612</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0482" published="2001-06-18" name="CVE-2001-0482" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Configuration error in Argus PitBull LX allows root users to bypass specified access control restrictions and cause a denial of service or execute arbitrary commands by modifying kernel variables such as MaxFiles, MaxInodes, and ModProbePath in /proc/sys via calls to sysctl.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0475.html" source="BUGTRAQ" patch="1" adv="1">20010330 Serious Pitbull LX Vulnerability </ref>
      <ref url="http://xforce.iss.net/static/6623.php" source="XF">pitbull-lx-modify-kernel(6623)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="argus_systems" name="pitbull_lx">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0483" published="2001-06-18" name="CVE-2001-0483" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Configuration error in Axent Raptor Firewall 6.5 allows remote attackers to use the firewall as a proxy to access internal web resources when the http.noproxy Rule is not set.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2517" source="BID" patch="1" adv="1">2517</ref>
      <ref url="http://www.securityfocus.com/archive/1/171953" source="BUGTRAQ" patch="1" adv="1">20010327 RE: Raptor 6.5 http vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0359.html" source="BUGTRAQ" patch="1" adv="1">20010324 Raptor 6.5 http vulnerability </ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="raptor_firewall">
        <vers num="6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0484" published="2001-06-27" name="CVE-2001-0484" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Tektronix PhaserLink 850 does not require authentication for access to configuration pages such as _ncl_subjects.shtml and _ncl_items.shtml, which allows remote attackers to modify configuration information and cause a denial of service by accessing the pages.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6482.php" source="XF">tektronix-phaserlink-webserver-backdoor(6482)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0482.html" source="BUGTRAQ" adv="1">20010425 Tektronix (Xerox) PhaserLink 850 Webserver Vulnerability (NEW)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tek" name="phaserlink">
        <vers num="850" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0485" published="2001-06-27" name="CVE-2001-0485" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unknown vulnerability in netprint in IRIX 6.2, and possibly other versions, allows local users with lp privileges attacker to execute arbitrary commands via the -n option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2656" source="BID" patch="1" adv="1">2656</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6473" source="XF" adv="1">irix-netprint-shared-library(6473)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0475.html" source="BUGTRAQ" adv="1">20010426 IRIX /usr/lib/print/netprint local root symbols exploit.</ref>
      <ref url="http://www.osvdb.org/8571" source="OSVDB">8571</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0502.html" source="BUGTRAQ">20010427 Re: IRIX /usr/lib/print/netprint local root symbols exploit.</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20010701-01-P" source="SGI">20010701-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sgi" name="irix">
        <vers num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0486" published="2001-07-02" name="CVE-2001-0486" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Remote attackers can cause a denial of service in Novell BorderManager 3.6 and earlier by sending TCP SYN flood to port 353.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2623" source="BID" patch="1" adv="1">2623</ref>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2959062.htm" source="CONFIRM" patch="1" adv="1">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2959062.htm</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98779821207867&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010420 Novell BorderManager 3.5 VPN Denial of Service</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0000.html" source="BUGTRAQ" patch="1">20010501 Re: Proof of concept DoS against novell border manager enterprise edition 3.5 </ref>
      <ref url="http://archives.neohapsis.com/archives/vuln-dev/2001-q2/0020.html" source="VULN-DEV" adv="1">20010402 (no subject)</ref>
      <ref url="http://xforce.iss.net/static/6429.php" source="XF">bordermanager-vpn-syn-dos(6429)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98865027328391&amp;w=2" source="BUGTRAQ">20010429 Proof of concept DoS against novell border manager enterprise</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="bordermanager">
        <vers prev="1" num="3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0487" published="2001-06-27" name="CVE-2001-0487" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">AIX SNMP server snmpd allows remote attackers to cause a denial of service via a RST during the TCP connection.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/5611" source="OSVDB">5611</ref>
      <ref url="http://www.iss.net/security_center/static/6996.php" source="XF">aix-snmpd-rst-dos(6996)</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY17630&amp;apar=only" source="AIXAPAR">IY17630</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix_snmp">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0488" published="2001-06-27" name="CVE-2001-0488" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">pcltotiff in HP-UX 10.x has unnecessary set group id permissions, which allows local users to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2646" source="BID" patch="1" adv="1">2646</ref>
      <ref url="http://xforce.iss.net/static/6447.php" source="XF">hp-pcltotiff-insecure-permissions(6447)</ref>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0104-149" source="HP">HPSBUX0104-149</ref>
      <ref url="http://www.osvdb.org/2188" source="OSVDB">2188</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.01" />
        <vers num="10.10" />
        <vers num="10.20" />
        <vers num="10.26" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0489" published="2001-06-27" name="CVE-2001-0489" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in gftp prior to 2.0.8 allows remote malicious FTP servers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/linux/redhat/2001-q2/0043.html" source="REDHAT" patch="1" adv="1">RHSA-2001:053</ref>
      <ref url="http://xforce.iss.net/static/6478.php" source="XF">gftp-format-string(6478)</ref>
      <ref url="http://www.securityfocus.com/bid/2657" source="BID">2657</ref>
      <ref url="http://www.osvdb.org/1805" source="OSVDB">1805</ref>
      <ref url="http://www.debian.org/security/2001/dsa-057" source="DEBIAN">DSA-057</ref>
      <ref url="http://archives.neohapsis.com/archives/vuln-dev/2001-q2/0231.html" source="VULN-DEV">20010417 gftp exploitable?</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gftp" name="gftp">
        <vers prev="1" num="2.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0490" published="2001-06-27" name="CVE-2001-0490" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in WINAMP 2.6x and 2.7x allows attackers to execute arbitrary code via a long string in an AIP file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0518.html" source="BUGTRAQ" patch="1" adv="1">20010429 Winamp 2.6x / 2.7x buffer overflow </ref>
    </refs>
    <vuln_soft>
      <prod vendor="nullsoft" name="winamp">
        <vers num="2.6x" />
        <vers num="2.7x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0491" published="2001-06-27" name="CVE-2001-0491" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in RaidenFTPD Server 2.1 before build 952 allows attackers to access files outside the ftp root via dot dot attacks, such as (1) .... in CWD, (2) .. in NLST, or (3) ... in NLST.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0465.html" source="BUGTRAQ" patch="1" adv="1">20010425 Vulnerabilities in RaidenFTPD Server </ref>
      <ref url="http://xforce.iss.net/static/6455.php" source="XF">raidenftpd-dot-directory-traversal(6455)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="team_johnlong" name="raidenftpd">
        <vers num="2.1_build_947" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0492" published="2001-06-27" name="CVE-2001-0492" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Netcruiser Web server version 0.1.2.8 and earlier allows remote attackers to determine the physical path of the server via a URL containing (1) con, (2) com2, or (3) com3.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6468.php" source="XF">netcruiser-server-path-disclosure(6468)</ref>
      <ref url="http://www.securityfocus.com/bid/2650" source="BID" adv="1">2650</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0427.html" source="BUGTRAQ" adv="1">20010424 Advisory for Netcruiser</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netcruiser_software" name="netcruiser_web_server">
        <vers prev="1" num="0.1.2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0493" published="2001-06-27" name="CVE-2001-0493" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Small HTTP server 2.03 allows remote attackers to cause a denial of service via a URL that contains an MS-DOS device name such as aux.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2649" source="BID" adv="1">2649</ref>
      <ref url="http://home.lanck.net/mf/srv/index.htm" source="CONFIRM">http://home.lanck.net/mf/srv/index.htm</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0428.html" source="BUGTRAQ" adv="1">20010424 Advisory for Small HTTP Server </ref>
      <ref url="http://xforce.iss.net/static/6446.php" source="XF">small-http-aux-dos(6446)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="max_feoktistov" name="small_http_server">
        <vers num="2.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0494" published="2001-06-27" name="CVE-2001-0494" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in IPSwitch IMail SMTP server 6.06 and possibly prior versions allows remote attackers to execute arbitrary code via a long From: header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0433.html" source="BUGTRAQ" patch="1" adv="1">20010424 IPSwitch IMail 6.06 SMTP Remote System Access Vulnerability </ref>
      <ref url="http://ipswitch.com/Support/IMail/news.html" source="CONFIRM">http://ipswitch.com/Support/IMail/news.html</ref>
      <ref url="http://xforce.iss.net/static/6445.php" source="XF">ipswitch-imail-smtp-bo(6445)</ref>
      <ref url="http://www.osvdb.org/5610" source="OSVDB">5610</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="imail">
        <vers prev="1" num="6.06" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0495" published="2001-06-27" name="CVE-2001-0495" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal in DataWizard WebXQ server 1.204 allows remote attackers to view files outside of the web root via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2660" source="BID" patch="1" adv="1">2660</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0490.html" source="BUGTRAQ" patch="1" adv="1">20010426 Vulnerability in WebXQ Server </ref>
      <ref url="http://xforce.iss.net/static/6466.php" source="XF">webxq-dot-directory-traversal(6466)</ref>
      <ref url="http://www.osvdb.org/1799" source="OSVDB">1799</ref>
    </refs>
    <vuln_soft>
      <prod vendor="datawizard" name="webxq">
        <vers num="2.1.204" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0496" published="2001-06-27" name="CVE-2001-0496" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">kdesu in kdelibs package creates world readable temporary files containing authentication info, which can allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-059.html" source="REDHAT" patch="1" adv="1">RHSA-2001:059</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-046.php3" source="MANDRAKE" patch="1" adv="1">MDKSA-2001:046</ref>
      <ref url="http://xforce.iss.net/static/6856.php" source="XF">kdelibs-kdesu-insecure-tmpfile(6856)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="2007" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="7.1" edition="" />
        <vers num="7.1" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0497" published="2001-07-21" name="CVE-2001-0497" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">dnskeygen in BIND 8.2.4 and earlier, and dnssec-keygen in BIND 9.1.2 and earlier, set insecure permissions for a HMAC-MD5 shared secret key file used for DNS Transactional Signatures (TSIG), which allows attackers to obtain the keys and perform dynamic DNS updates.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/alerts/advise78.php" source="ISS" patch="1" adv="1">20010611 BIND Inadvertent Local Exposure of HMAC-MD5 (TSIG) Keys</ref>
      <ref url="http://xforce.iss.net/static/6694.php" source="XF">bind-local-key-exposure(6694)</ref>
      <ref url="http://www.osvdb.org/5609" source="OSVDB">5609</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="bind">
        <vers prev="1" num="8.2.4" />
        <vers prev="1" num="9.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0498" published="2001-07-21" name="CVE-2001-0498" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Transparent Network Substrate (TNS) over Net8 (SQLNet) in Oracle 8i 8.1.7 and earlier allows remote attackers to cause a denial of service via a malformed SQLNet connection request with a large offset in the header extension.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.nai.com/research/covert/advisories/049.asp" source="NAI">20010627 Oracle 8i SQLNet Header Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="oracle8i">
        <vers prev="1" num="8.1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0499" published="2001-07-21" name="CVE-2001-0499" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Transparent Network Substrate (TNS) Listener in Oracle 8i 8.1.7 and earlier allows remote attackers to gain privileges via a long argument to the commands (1) STATUS, (2) PING, (3) SERVICES, (4) TRC_FILE, (5) SAVE_CONFIG, or (6) RELOAD.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/620495" source="CERT-VN">VU#620495</ref>
      <ref url="http://www.cert.org/advisories/CA-2001-16.html" source="CERT">CA-2001-16</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6758" source="XF">oracle-tns-listener-bo(6758)</ref>
      <ref url="http://www.securityfocus.com/bid/2941" source="BID">2941</ref>
      <ref url="http://www.nai.com/research/covert/advisories/050.asp" source="NAI">20010627 Vulnerability in Oracle 8i TNS Listener</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="oracle8i">
        <vers prev="1" num="8.1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0500" published="2001-07-21" name="CVE-2001-0500" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier allows remote attackers to execute arbitrary commands via a long argument to Internet Data Administration (.ida) and Internet Data Query (.idq) files such as default.ida, as commonly exploited by Code Red.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2001-13.html" source="CERT" patch="1" adv="1">CA-2001-13</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-033.asp" source="MS" patch="1" adv="1">MS01-033</ref>
      <ref url="http://www.securityfocus.com/bid/2880" source="BID">2880</ref>
      <ref url="http://www.securityfocus.com/archive/1/191873" source="BUGTRAQ">20010618 All versions of Microsoft Internet Information Services, Remote buffer overflow (SYSTEM Level Access)</ref>
      <ref url="http://www.iss.net/security_center/static/6705.php" source="XF">iis-isapi-idq-bo(6705)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/l-098.shtml" source="CIAC">L-098</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:197" source="OVAL" sig="1">oval:org.mitre.oval:def:197</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="index_server">
        <vers num="2.0" />
      </prod>
      <prod vendor="microsoft" name="indexing_service">
        <vers num="" edition=":windows_2000" />
      </prod>
      <prod vendor="microsoft" name="internet_information_server">
        <vers prev="1" num="6.0" edition="beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0501" published="2001-07-21" name="CVE-2001-0501" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Microsoft Word 2002 and earlier allows attackers to automatically execute macros without warning the user by embedding the macros in a manner that escapes detection by the security scanner.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2876" source="BID" patch="1" adv="1">2876</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-034.asp" source="MS" patch="1" adv="1">MS01-034</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=99325144322224&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010622 Fwd: Microsoft Word macro vulnerability advisory MS01-034</ref>
      <ref url="http://xforce.iss.net/static/6732.php" source="XF">msword-macro-bypass-security(6732)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="word">
        <vers num="2000" edition="sr1" />
        <vers num="2000" edition="sr1a" />
        <vers num="2000" edition="sr2" />
        <vers num="2001" edition="" />
        <vers num="2001" edition=":mac" />
        <vers prev="1" num="2002" />
        <vers num="97" edition="sr1" />
        <vers num="97" edition="sr2" />
        <vers num="98" edition="" />
        <vers num="98" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0502" published="2001-07-21" name="CVE-2001-0502" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Running Windows 2000 LDAP Server over SSL, a function does not properly check the permissions of a user request when the directory principal is a domain user and the data attribute is the domain password, which allows local users to modify the login password of other users.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-036.asp" source="MS" patch="1" adv="1">MS01-036</ref>
      <ref url="http://xforce.iss.net/static/6745.php" source="XF">win2k-ldap-change-passwords(6745)</ref>
      <ref url="http://www.securityfocus.com/bid/2929" source="BID">2929</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/l-101.shtml" source="CIAC">L-101</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0503" published="2001-07-21" name="CVE-2001-0503" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft NetMeeting 3.01 with Remote Desktop Sharing enabled allows remote attackers to cause a denial of service via a malformed string to the NetMeeting service port, aka a variant of the "NetMeeting Desktop Sharing" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms00-077.asp" source="MS" patch="1" adv="1">MS00-077</ref>
      <ref url="http://www.osvdb.org/5608" source="OSVDB">5608</ref>
      <ref url="http://www.iss.net/security_center/static/5368.php" source="XF">netmeeting-desktop-sharing-dos(5368)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="netmeeting">
        <vers num="3.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0504" published="2001-08-14" name="CVE-2001-0504" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Vulnerability in authentication process for SMTP service in Microsoft Windows 2000 allows remote attackers to use incorrect credentials to gain privileges and conduct activites such as mail relaying.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/435963" source="CERT-VN">VU#435963</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms01-037.asp" source="MS" patch="1" adv="1">MS01-037</ref>
      <ref url="http://xforce.iss.net/static/6803.php" source="XF">win2k-smtp-mail-relay(6803)</ref>
      <ref url="http://www.securityfocus.com/bid/2988" source="BID">2988</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/l-107.shtml" source="CIAC">L-107</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0505" published="2001-10-30" name="CVE-2001-0505" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple memory leaks in Microsoft Services for Unix 2.0 allow remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed requests to (1) the Telnet service, or (2) the NFS service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/994851" source="CERT-VN">VU#994851</ref>
      <ref url="http://www.kb.cert.org/vuls/id/581603" source="CERT-VN">VU#581603</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms01-039.asp" source="MS" patch="1" adv="1">MS01-039</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6883" source="XF">sfu-telnet-dos(6883)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6882" source="XF">sfu-nfs-dos(6882)</ref>
      <ref url="http://www.securityfocus.com/bid/3089" source="BID">3089</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="services">
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":unix" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0506" published="2001-09-20" name="CVE-2001-0506" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes (SSI) directive for a long filename, which triggers the overflow when the directory name is added, aka the "SSI privilege elevation" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/3190" source="BID" patch="1" adv="1">3190</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms01-044.asp" source="MS" patch="1" adv="1">MS01-044</ref>
      <ref url="http://xforce.iss.net/static/6984.php" source="XF">iis-ssi-directive-bo(6984)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/l-132.shtml" source="CIAC">L-132</ref>
      <ref url="http://online.securityfocus.com/archive/1/242541" source="BUGTRAQ">20011127 IIS Server Side Include Buffer overflow exploit code</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=99802093532233&amp;w=2" source="BUGTRAQ">20010817 NSFOCUS SA2001-06 : Microsoft IIS ssinc.dll Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0507" published="2001-09-20" name="CVE-2001-0507" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System file listing privilege elevation" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms01-044.asp" source="MS" patch="1" adv="1">MS01-044</ref>
      <ref url="http://xforce.iss.net/static/6985.php" source="XF">iis-relative-path-privilege-elevation(6985)</ref>
      <ref url="http://www.osvdb.org/5607" source="OSVDB">5607</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/l-132.shtml" source="CIAC">L-132</ref>
      <ref url="http://online.securityfocus.com/archive/1/205069" source="BUGTRAQ">20010816 ENTERCEPT SECURITY ALERT: Privilege Escalation Vulnerability in Microsoft IIS</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:912" source="OVAL" sig="1">oval:org.mitre.oval:def:912</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:909" source="OVAL" sig="1">oval:org.mitre.oval:def:909</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0508" published="2001-09-20" name="CVE-2001-0508" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Vulnerability in IIS 5.0 allows remote attackers to cause a denial of service (restart) via a long, invalid WebDAV request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms01-044.asp" source="MS" patch="1" adv="1">MS01-044</ref>
      <ref url="http://www.securityfocus.com/bid/2690" source="BID">2690</ref>
      <ref url="http://www.osvdb.org/5633" source="OSVDB">5633</ref>
      <ref url="http://www.osvdb.org/5606" source="OSVDB">5606</ref>
      <ref url="http://www.iss.net/security_center/static/6982.php" source="XF">iis-webdav-long-request-dos(6982)</ref>
      <ref url="http://online.securityfocus.com/archive/1/182579" source="BUGTRAQ">20010506 IIS 5.0 PROPFIND DOS #2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0509" published="2001-09-20" name="CVE-2001-0509" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service via malformed inputs.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-041.asp" source="MS" patch="1" adv="1">MS01-041</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:82" source="OVAL" sig="1">oval:org.mitre.oval:def:82</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers prev="1" num="2000" />
        <vers num="5.5" />
      </prod>
      <prod vendor="microsoft" name="sql_server">
        <vers prev="1" num="2000" />
        <vers num="7.0" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0513" published="2001-07-21" name="CVE-2001-0513" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Oracle listener process on Windows NT redirects connection requests to another port and creates a separate thread to process the request, which allows remote attackers to cause a denial of service by repeatedly connecting to the Oracle listener but not connecting to the redirected port.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/105259" source="CERT-VN">VU#105259</ref>
      <ref url="http://xforce.iss.net/alerts/advise81.php" source="ISS" patch="1" adv="1">20010619 Oracle Redirect Denial of Service</ref>
      <ref url="http://xforce.iss.net/static/6717.php" source="XF">oracle-listener-redirect-dos(6717)</ref>
      <ref url="http://www.osvdb.org/5600" source="OSVDB">5600</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="oracle9i">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0514" published="2001-07-21" name="CVE-2001-0514" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SNMP service in Atmel 802.11b VNET-B Access Point 1.3 and earlier, as used in Netgear ME102 and Linksys WAP11, accepts arbitrary community strings with requested MIB modifications, which allows remote attackers to obtain sensitive information such as WEP keys, cause a denial of service, or gain access to the network.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/alerts/advise83.php" source="ISS" patch="1" adv="1">20010620 Multiple Vendor 802.11b Access Point SNMP authentication flaw</ref>
      <ref url="http://xforce.iss.net/static/6576.php" source="XF">atmel-vnetb-ap-snmp-security(6576)</ref>
      <ref url="http://www.securityfocus.com/bid/2896" source="BID">2896</ref>
    </refs>
    <vuln_soft>
      <prod vendor="atmel" name="802.11b_vnet-b_access_point">
        <vers prev="1" num="1.3" />
      </prod>
      <prod vendor="linksys" name="wap11">
        <vers num="" />
      </prod>
      <prod vendor="netgear" name="me102">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0515" published="2001-07-21" name="CVE-2001-0515" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Oracle Listener in Oracle 7.3 and 8i allows remote attackers to cause a denial of service via a malformed connection packet with a large offset_to_data value.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/alerts/advise82.php" source="ISS" patch="1" adv="1">20010515 Multiple Oracle Listener Denial of Service Vulnerabilities</ref>
      <ref url="http://otn.oracle.com/deploy/security/pdf/net8_dos_alert.pdf" source="CONFIRM">http://otn.oracle.com/deploy/security/pdf/net8_dos_alert.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="7.3" />
      </prod>
      <prod vendor="oracle" name="oracle8i">
        <vers num="8.1.6" />
        <vers prev="1" num="8.1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0516" published="2001-07-21" name="CVE-2001-0516" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Oracle listener between Oracle 9i and Oracle 8.0 allows remote attackers to cause a denial of service via a malformed connection packet that contains an incorrect requester_version value that does not match an expected offset to the data.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/alerts/advise82.php" source="ISS" patch="1" adv="1">20010515 Multiple Oracle Listener Denial of Service Vulnerabilities</ref>
      <ref url="http://otn.oracle.com/deploy/security/pdf/net8_dos_alert.pdf" source="CONFIRM">http://otn.oracle.com/deploy/security/pdf/net8_dos_alert.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="oracle8i">
        <vers num="" />
      </prod>
      <prod vendor="oracle" name="oracle9i">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0517" published="2001-07-21" name="CVE-2001-0517" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Oracle listener in Oracle 8i on Solaris allows remote attackers to cause a denial of service via a malformed connection packet with a maximum transport data size that is set to 0.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6715.php" source="XF" patch="1" adv="1">oracle-listener-data-transport-dos(6715)</ref>
      <ref url="http://xforce.iss.net/alerts/advise82.php" source="ISS" patch="1" adv="1">20010515 Multiple Oracle Listener Denial of Service Vulnerabilities</ref>
      <ref url="http://otn.oracle.com/deploy/security/pdf/net8_dos_alert.pdf" source="CONFIRM">http://otn.oracle.com/deploy/security/pdf/net8_dos_alert.pdf</ref>
      <ref url="http://www.osvdb.org/5590" source="OSVDB">5590</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="oracle8i">
        <vers num="8.1.6" />
        <vers num="8.1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0518" published="2001-07-21" name="CVE-2001-0518" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Oracle listener before Oracle 9i allows attackers to cause a denial of service by repeatedly sending the first portion of a fragmented Oracle command without sending the remainder of the command, which causes the listener to hang.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6716.php" source="XF" patch="1" adv="1">oracle-listener-fragmentation-dos(6716)</ref>
      <ref url="http://xforce.iss.net/alerts/advise82.php" source="ISS" patch="1" adv="1">20010515 Multiple Oracle Listener Denial of Service Vulnerabilities</ref>
      <ref url="http://otn.oracle.com/deploy/security/alerts.htm" source="CONFIRM">http://otn.oracle.com/deploy/security/alerts.htm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="oracle9i">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0519" published="2001-08-14" name="CVE-2001-0519" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Aladdin eSafe Gateway versions 2.x allows a remote attacker to circumvent HTML SCRIPT filtering via a special arrangement of HTML tags which includes SCRIPT tags embedded within other SCRIPT tags.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0282.html" source="BUGTRAQ" patch="1" adv="1">20010529 Aladdin eSafe Gateway Filter Bypass - Updated Advisory </ref>
      <ref url="http://xforce.iss.net/static/6580.php" source="XF" adv="1">esafe-gateway-bypass-filtering(6580)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aladdin_knowledge_systems" name="esafe_gateway">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0520" published="2001-08-14" name="CVE-2001-0520" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Aladdin eSafe Gateway versions 3.0 and earlier allows a remote attacker to circumvent filtering of SCRIPT tags by embedding the scripts within certain HTML tags including (1) onload in the BODY tag, (2) href in the A tag, (3) the BUTTON tag, (4) the INPUT tag, or (5) any other tag in which scripts can be defined.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6580.php" source="XF" adv="1">esafe-gateway-bypass-filtering(6580)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0284.html" source="BUGTRAQ" adv="1">20010529 Aladdin eSafe Gateway Script-filtering Bypass through HTML tags</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aladdin_knowledge_systems" name="esafe_gateway">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0521" published="2001-08-14" name="CVE-2001-0521" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Aladdin eSafe Gateway versions 3.0 and earlier allows a remote attacker to circumvent HTML SCRIPT filtering via the UNICODE encoding of SCRIPT tags within the HTML document.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6580.php" source="XF" adv="1">esafe-gateway-bypass-filtering(6580)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0285.html" source="BUGTRAQ" adv="1">20010529 Aladdin eSafe Gateway Script-filtering Bypass through Unicode Vulnerability </ref>
    </refs>
    <vuln_soft>
      <prod vendor="aladdin_knowledge_systems" name="esafe_gateway">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0522" published="2001-08-14" name="CVE-2001-0522" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in Gnu Privacy Guard (aka GnuPG or gpg) 1.05 and earlier can allow an attacker to gain privileges via format strings in the original filename that is stored in an encrypted file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/403051" source="CERT-VN">VU#403051</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-053.php3" source="MANDRAKE" patch="1" adv="1">MDKSA-2001:053</ref>
      <ref url="http://www.gnupg.org/whatsnew.html#rn20010529" source="CONFIRM">http://www.gnupg.org/whatsnew.html#rn20010529</ref>
      <ref url="http://xforce.iss.net/static/6642.php" source="XF">gnupg-tty-format-string(6642)</ref>
      <ref url="http://www.turbolinux.com/pipermail/tl-security-announce/2001-June/000439.html" source="TURBO">TLSA2001028</ref>
      <ref url="http://www.securityfocus.com/bid/2797" source="BID">2797</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-073.html" source="REDHAT">RHSA-2001:073</ref>
      <ref url="http://www.osvdb.org/1845" source="OSVDB">1845</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2001_020_gpg_txt.html" source="SUSE">SuSE-SA:2001:020</ref>
      <ref url="http://www.debian.org/security/2001/dsa-061" source="DEBIAN">DSA-061</ref>
      <ref url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-020.0.txt" source="CALDERA">CSSA-2001-020.0</ref>
      <ref url="http://online.securityfocus.com/archive/1/188218" source="BUGTRAQ">20010601 The GnuPG format string bug (was: TSLSA-2001-0009 - GnuPG)</ref>
      <ref url="http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-023-01" source="IMMUNIX">IMNX-2001-70-023-01</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000399" source="CONECTIVA">CLA-2001:399</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="privacy_guard">
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0523" published="2001-08-14" name="CVE-2001-0523" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">eEye SecureIIS versions 1.0.3 and earlier allows a remote attacker to bypass filtering of requests made to SecureIIS by escaping HTML characters within the request, which could allow a remote attacker to use restricted variables and perform directory traversal attacks on vulnerable programs that would otherwise be protected.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6564.php" source="XF" patch="1" adv="1">eeye-secureiis-directory-traversal(6564)</ref>
      <ref url="http://xforce.iss.net/static/6563.php" source="XF" patch="1" adv="1">eeye-secureiis-bypass-detection(6563)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0197.html" source="BUGTRAQ" adv="1">20010519 RE: ASLabs-2001-01: Multiple Security Problems in eEye SecureIIS</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0185.html" source="BUGTRAQ" adv="1">20010518 ASLabs-2001-01: Multiple Security Problems in eEye SecureIIS </ref>
    </refs>
    <vuln_soft>
      <prod vendor="eeye_digital_security" name="secureiis">
        <vers num="1.0.2" />
      </prod>
      <prod vendor="eeye_digital_security" name="securells">
        <vers prev="1" num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0524" published="2001-08-14" name="CVE-2001-0524" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">eEye SecureIIS versions 1.0.3 and earlier does not perform length checking on individual HTTP headers, which allows a remote attacker to send arbitrary length strings to IIS, contrary to an advertised feature of SecureIIS versions 1.0.3 and earlier.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6574.php" source="XF" patch="1" adv="1">eeye-secureiis-http-header-bo(6574)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0197.html" source="BUGTRAQ" adv="1">20010519 RE: ASLabs-2001-01: Multiple Security Problems in eEye SecureIIS</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0185.html" source="BUGTRAQ" adv="1">20010518 ASLabs-2001-01: Multiple Security Problems in eEye SecureIIS </ref>
    </refs>
    <vuln_soft>
      <prod vendor="eeye_digital_security" name="securells">
        <vers prev="1" num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0525" published="2001-08-14" name="CVE-2001-0525" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in dsh in dqs 3.2.7 in SuSE Linux 7.0 and earlier, and possibly other operating systems, allows local users to gain privileges via a long first command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6577.php" source="XF" patch="1" adv="1">dqs-dsh-bo(6577)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0195.html" source="BUGTRAQ" patch="1" adv="1">20010519 Re: dqs 3.2.7 local root exploit.</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0193.html" source="BUGTRAQ" patch="1" adv="1">20010519 dqs 3.2.7 local root exploit.</ref>
      <ref url="http://www.securityfocus.com/bid/2749" source="BID">2749</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="suse_linux">
        <vers num="6.3" />
        <vers num="6.4" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0526" published="2001-08-14" name="CVE-2001-0526" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in the Xview library as used by mailtool in Solaris 8 and earlier allows a local attacker to gain privileges via the OPENWINHOME environment variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6626.php" source="XF" patch="1" adv="1">solaris-mailtool-openwinhome-bo(6626)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0258.html" source="BUGTRAQ" patch="1" adv="1">20010528 [synnergy] - Solaris mailtool(1) buffer overflow vulnerability </ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":sparc" />
        <vers num="8.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0527" published="2001-08-14" name="CVE-2001-0527" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">DCScripts DCForum versions 2000 and earlier allow a remote attacker to gain additional privileges by inserting pipe symbols (|) and newlines into the last name in the registration form, which will create an extra entry in the registration database.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6538.php" source="XF" patch="1" adv="1">dcforum-cgi-admin-access(6538)</ref>
      <ref url="http://www.dcscripts.com/dcforum/dcfNews/167.html" source="CONFIRM" patch="1">http://www.dcscripts.com/dcforum/dcfNews/167.html</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0122.html" source="BUGTRAQ" adv="1">20010515 DCForum Password File Manipukation Vulnerability (qDefense Advisory Number QDAV-5-2000-2) </ref>
      <ref url="http://www.securityfocus.com/bid/2728" source="BID">2728</ref>
      <ref url="http://www.osvdb.org/480" source="OSVDB">480</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dcscripts" name="dcforum">
        <vers num="6.0" />
      </prod>
      <prod vendor="dcscripts" name="dcforum_2000">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0528" published="2001-08-14" name="CVE-2001-0528" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Oracle E-Business Suite Release 11i Applications Desktop Integrator (ADI) version 7.x includes a debug version of FNDPUB11I.DLL, which logs the APPS schema password in cleartext in a debug file, which allows local users to obtain the password and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6501.php" source="XF" patch="1" adv="1">oracle-adi-plaintext-passwords(6501)</ref>
      <ref url="http://www.securityfocus.com/bid/2694" source="BID" patch="1" adv="1">2694</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0223.html" source="BUGTRAQ" patch="1" adv="1">20010522 Vulnerability in Oracle E-Business Suite Release 11i Applications Desktop Integrator</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0044.html" source="BUGTRAQ" adv="1">20010507 Oracle's ADI 7.1.1.10.1 Major security hole</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11i" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0529" published="2001-08-14" name="CVE-2001-0529" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">OpenSSH version 2.9 and earlier, with X forwarding enabled, allows a local attacker to delete any file named 'cookies' via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/655259" source="CERT-VN">VU#655259</ref>
      <ref url="http://www.securityfocus.com/bid/2825" source="BID" patch="1" adv="1">2825</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2001-010.txt.asc" source="NETBSD" patch="1" adv="1">NetBSD-SA2001-010</ref>
      <ref url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-023.0.txt" source="CALDERA" adv="1">CSSA-2001-023.0</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-06/0007.html" source="BUGTRAQ" adv="1">20010604 Re: SSH allows deletion of other users files... </ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0322.html" source="BUGTRAQ" adv="1">20010604 SSH allows deletion of other users files... </ref>
      <ref url="http://xforce.iss.net/static/6676.php" source="XF">openssh-symlink-file-deletion(6676)</ref>
      <ref url="http://www.osvdb.org/1853" source="OSVDB">1853</ref>
      <ref url="http://www.openbsd.org/errata29.html" source="OPENBSD">20010612</ref>
      <ref url="http://online.securityfocus.com/archive/1/188737" source="BUGTRAQ">20010605 OpenSSH_2.5.2p2 RH7.0 &lt;- version info</ref>
      <ref url="http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-034-01" source="IMMUNIX">IMNX-2001-70-034-01</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000431" source="CONECTIVA">CLA-2001:431</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openssh">
        <vers prev="1" num="2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0530" published="2001-08-14" name="CVE-2001-0530" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Spearhead NetGAP 200 and 300 before build 78 allow a remote attacker to bypass file blocking and content inspection via specially encoded URLs which include '%' characters.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6625.php" source="XF" patch="1" adv="1">netgap-unicode-bypass-filter(6625)</ref>
      <ref url="http://www.securityfocus.com/bid/2798" source="BID" patch="1" adv="1">2798</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-06/0047.html" source="BUGTRAQ" patch="1" adv="1">20010607 SpearHead Security NetGAP </ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0256.html" source="BUGTRAQ" adv="1">20010528 Vulnerability discovered in SpearHead NetGap </ref>
    </refs>
    <vuln_soft>
      <prod vendor="spearhead" name="netgap_200">
        <vers prev="1" num="78" />
      </prod>
      <prod vendor="spearhead" name="netgap_300">
        <vers prev="1" num="78" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0533" published="2001-08-14" name="CVE-2001-0533" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in libi18n library in IBM AIX 5.1 and 4.3.x allows local users to gain root privileges via a long LANG environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www-1.ibm.com/services/continuity/recover1.nsf/advisories/85256A3400529A8685256A8D00804A37/$file/oar271.txt" source="IBM" patch="1" adv="1">MSS-OAR-E01-2001:271.1</ref>
      <ref url="http://xforce.iss.net/static/6863.php" source="XF">aix-libi18n-lang-bo(6863)</ref>
      <ref url="http://www.osvdb.org/5585" source="OSVDB">5585</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/l-123.shtml" source="CIAC">L-123</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.3" />
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0534" published="2001-07-21" name="CVE-2001-0534" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in RADIUS daemon radiusd in (1) Merit 3.6b and (2) Lucent 2.1-2 RADIUS allow remote attackers to cause a denial of service or execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/898931" source="CERT-VN">VU#898931</ref>
      <ref url="http://xforce.iss.net/alerts/alerts.php" source="ISS">20010705 Remote Buffer Overflow in Multiple RADIUS Implementations</ref>
      <ref url="http://www.securityfocus.com/bid/2989" source="BID">2989</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lucent" name="radius">
        <vers num="2.1.2" />
      </prod>
      <prod vendor="merit" name="radius">
        <vers num="3.6b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0535" published="2001-10-30" name="CVE-2001-0535" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Example applications (Exampleapps) in ColdFusion Server 4.x do not properly restrict prevent access from outside the local host's domain, which allows remote attackers to conduct upload, read, or execute files by spoofing the "HTTP Host" (CGI.Host) variable in (1) the "Web Publish" example script, and (2) the "Email" example script.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/alerts/advise92.php" source="ISS" adv="1">20010807 Remote Vulnerabilities in Macromedia ColdFusion Example Applications</ref>
      <ref url="http://www.allaire.com/Handlers/index.cfm?ID=21700" source="ALLAIRE" adv="1">MPSB01-08</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macromedia" name="coldfusion_server">
        <vers num="4.x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0537" published="2001-07-21" name="CVE-2001-0537" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when local authorization is being used, by specifying a high access level in the URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2001-14.html" source="CERT" patch="1" adv="1">CA-2001-14</ref>
      <ref url="http://www.securityfocus.com/bid/2936" source="BID" patch="1" adv="1">2936</ref>
      <ref url="http://www.cisco.com/warp/public/707/IOS-httplevel-pub.html" source="CISCO" patch="1" adv="1">20010627 IOS HTTP authorization vulnerability</ref>
      <ref url="http://xforce.iss.net/static/6749.php" source="XF">cisco-ios-admin-access(6749)</ref>
      <ref url="http://www.securityfocus.com/archive/1/Pine.LNX.3.96.1010702134611.22995B-100000@Lib-Vai.lib.asu.edu" source="BUGTRAQ">20010702 Cisco device HTTP exploit...</ref>
      <ref url="http://www.securityfocus.com/archive/1/4.3.2.7.2.20010629095801.0c3e6a70@brussels.cisco.com" source="BUGTRAQ">20010629 Re: Cisco Security Advisory: IOS HTTP authorization vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/20010703011650.60515.qmail@web14910.mail.yahoo.com" source="BUGTRAQ">20010702 ios-http-auth.sh</ref>
      <ref url="http://www.securityfocus.com/archive/1/1601227034.20010702112207@olympos.org" source="BUGTRAQ">20010702 Cisco IOS HTTP Configuration Exploit</ref>
      <ref url="http://www.osvdb.org/578" source="OSVDB">578</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/l-106.shtml" source="CIAC">L-106</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="11.3" />
        <vers num="11.3aa" />
        <vers num="11.3da" />
        <vers num="11.3db" />
        <vers num="11.3ha" />
        <vers num="11.3ma" />
        <vers num="11.3na" />
        <vers num="11.3t" />
        <vers num="11.3xa" />
        <vers num="12.0" />
        <vers num="12.0(10)w5(18g)" />
        <vers num="12.0(14)w5(20)" />
        <vers num="12.0(5)xk" />
        <vers num="12.0(7)xk" />
        <vers num="12.0da" />
        <vers num="12.0db" />
        <vers num="12.0dc" />
        <vers num="12.0s" />
        <vers num="12.0sc" />
        <vers num="12.0sl" />
        <vers num="12.0st" />
        <vers num="12.0t" />
        <vers num="12.0wc" />
        <vers num="12.0wt" />
        <vers num="12.0xa" />
        <vers num="12.0xb" />
        <vers num="12.0xc" />
        <vers num="12.0xd" />
        <vers num="12.0xe" />
        <vers num="12.0xf" />
        <vers num="12.0xg" />
        <vers num="12.0xh" />
        <vers num="12.0xi" />
        <vers num="12.0xj" />
        <vers num="12.0xl" />
        <vers num="12.0xm" />
        <vers num="12.0xn" />
        <vers num="12.0xp" />
        <vers num="12.0xq" />
        <vers num="12.0xr" />
        <vers num="12.0xs" />
        <vers num="12.0xu" />
        <vers num="12.0xv" />
        <vers num="12.1" />
        <vers num="12.1aa" />
        <vers num="12.1cx" />
        <vers num="12.1da" />
        <vers num="12.1db" />
        <vers num="12.1dc" />
        <vers num="12.1e" />
        <vers num="12.1ec" />
        <vers num="12.1ex" />
        <vers num="12.1ey" />
        <vers num="12.1ez" />
        <vers num="12.1t" />
        <vers num="12.1xa" />
        <vers num="12.1xb" />
        <vers num="12.1xc" />
        <vers num="12.1xd" />
        <vers num="12.1xe" />
        <vers num="12.1xf" />
        <vers num="12.1xg" />
        <vers num="12.1xh" />
        <vers num="12.1xi" />
        <vers num="12.1xj" />
        <vers num="12.1xk" />
        <vers num="12.1xl" />
        <vers num="12.1xm" />
        <vers num="12.1xp" />
        <vers num="12.1xq" />
        <vers num="12.1xr" />
        <vers num="12.1xs" />
        <vers num="12.1xt" />
        <vers num="12.1xu" />
        <vers num="12.1xv" />
        <vers num="12.1xw" />
        <vers num="12.1xx" />
        <vers num="12.1xy" />
        <vers num="12.1xz" />
        <vers num="12.1ya" />
        <vers num="12.1yb" />
        <vers num="12.1yc" />
        <vers num="12.1yd" />
        <vers num="12.1yf" />
        <vers num="12.2" />
        <vers num="12.2t" />
        <vers num="12.2xa" />
        <vers num="12.2xd" />
        <vers num="12.2xe" />
        <vers num="12.2xh" />
        <vers num="12.2xq" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0538" published="2001-08-14" name="CVE-2001-0538" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary commands via a malicious HTML e-mail message or web page.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/131569" source="CERT-VN">VU#131569</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-038.asp" source="MS" patch="1" adv="1">MS01-038</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=99496431214078&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010712 MS Office XP - the more money I give to Microsoft, the more vulnerable my Windows computers are</ref>
      <ref url="http://xforce.iss.net/static/6831.php" source="XF">outlook-activex-view-control(6831)</ref>
      <ref url="http://www.securityfocus.com/bid/3025" source="BID">3025</ref>
      <ref url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0107&amp;L=ntbugtraq&amp;F=P&amp;S=&amp;P=862" source="NTBUGTRAQ">20010712 Vulnerability in IE/Outlook ActiveX control</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/l-113.shtml" source="CIAC">L-113</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="outlook">
        <vers prev="1" num="2002" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0540" published="2001-10-30" name="CVE-2001-0540" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Memory leak in Terminal servers in Windows NT and Windows 2000 allows remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed Remote Desktop Protocol (RDP) requests to port 3389.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms01-040.asp" source="MS" patch="1" adv="1">MS01-040</ref>
      <ref url="http://xforce.iss.net/static/6912.php" source="XF">win-terminal-rdp-dos(6912)</ref>
      <ref url="http://www.securityfocus.com/bid/3099" source="BID">3099</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="terminal_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0541" published="2001-09-20" name="CVE-2001-0541" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Windows Media Player 7.1 and earlier allows remote attackers to execute arbitrary commands via a malformed Windows Media Station (.NSC) file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-042.asp" source="MS" patch="1" adv="1">MS01-042</ref>
      <ref url="http://www.securityfocus.com/archive/1/187001" source="BUGTRAQ" adv="1">20010527 Microsoft Windows Media Player Buffer Overflow Vulnerability</ref>
      <ref url="http://xforce.iss.net/static/6907.php" source="XF">mediaplayer-nsc-bo(6907)</ref>
      <ref url="http://www.securityfocus.com/bid/3105" source="BID">3105</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_media_player">
        <vers num="6.4" />
        <vers num="7" />
        <vers prev="1" num="7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0542" published="2001-12-20" name="CVE-2001-0542" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflows in Microsoft SQL Server 7.0 and 2000 allow attackers with access to SQL Server to execute arbitrary code through the functions (1) raiserror, (2) formatmessage, or (3) xp_sprintf.  NOTE: the C runtime format string vulnerability reported in MS01-060 is identified by CVE-2001-0879.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/700575" source="CERT-VN">VU#700575</ref>
      <ref url="http://xforce.iss.net/static/7724.php" source="XF" patch="1" adv="1">mssql-text-message-bo(7724)</ref>
      <ref url="http://www.securityfocus.com/bid/3733" source="BID" patch="1" adv="1">3733</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-060.asp" source="MS" patch="1" adv="1">MS01-060</ref>
      <ref url="http://www.atstake.com/research/advisories/2001/a122001-1.txt" source="ATSTAKE" patch="1" adv="1">A122001-1</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=100891252317406&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20011221 @stake advisory: Multiple overflow and format string vulnerabilities in in Microsoft SQL Server</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:83" source="OVAL" sig="1">oval:org.mitre.oval:def:83</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="sql_server">
        <vers num="2000" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0543" published="2001-09-20" name="CVE-2001-0543" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Memory leak in NNTP service in Windows NT 4.0 and Windows 2000 allows remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed posts.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-043.asp" source="MS" patch="1" adv="1">MS01-043</ref>
      <ref url="http://xforce.iss.net/static/6977.php" source="XF">win-nntp-dos(6977)</ref>
      <ref url="http://www.securityfocus.com/bid/3183" source="BID">3183</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:334" source="OVAL" sig="1">oval:org.mitre.oval:def:334</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="2000" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0544" published="2001-10-30" name="CVE-2001-0544" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">IIS 5.0 allows local users to cause a denial of service (hang) via by installing content that produces a certain invalid MIME Content-Type header, which corrupts the File Type table.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms01-044.asp" source="MS" patch="1" adv="1">MS01-044</ref>
      <ref url="http://xforce.iss.net/static/6983.php" source="XF">iis-invalid-mime-header-dos(6983)</ref>
      <ref url="http://www.securityfocus.com/bid/3195" source="BID">3195</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/l-132.shtml" source="CIAC">L-132</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0545" published="2001-10-30" name="CVE-2001-0545" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IIS 4.0 with URL redirection enabled allows remote attackers to cause a denial of service (crash) via a malformed request that specifies a length that is different than the actual length.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms01-044.asp" source="MS" patch="1" adv="1">MS01-044</ref>
      <ref url="http://xforce.iss.net/static/6981.php" source="XF">iis-url-redirection-dos(6981)</ref>
      <ref url="http://www.osvdb.org/5736" source="OSVDB">5736</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/l-132.shtml" source="CIAC">L-132</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0546" published="2001-09-20" name="CVE-2001-0546" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Memory leak in H.323 Gatekeeper Service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (resource exhaustion) via a large amount of malformed H.323 data.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-045.asp" source="MS" patch="1" adv="1">MS01-045</ref>
      <ref url="http://xforce.iss.net/static/6989.php" source="XF">isa-h323-gatekeeper-dos(6989)</ref>
      <ref url="http://www.securityfocus.com/bid/3196" source="BID">3196</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="isa_server">
        <vers num="2000" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0547" published="2001-09-20" name="CVE-2001-0547" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Memory leak in the proxy service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows local attackers to cause a denial of service (resource exhaustion).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-045.asp" source="MS" patch="1" adv="1">MS01-045</ref>
      <ref url="http://xforce.iss.net/static/6990.php" source="XF">isa-proxy-memory-leak-dos(6990)</ref>
      <ref url="http://www.securityfocus.com/bid/3197" source="BID">3197</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="isa_server">
        <vers num="2000" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0548" published="2001-08-14" name="CVE-2001-0548" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in dtmail in Solaris 2.6 and 7 allows local users to gain privileges via the MAIL environment variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=99598918914068&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010724 NSFOCUS SA2001-04 : Solaris dtmail Buffer Overflow Vulnerability</ref>
      <ref url="http://xforce.iss.net/static/6879.php" source="XF">solaris-dtmail-bo(6879)</ref>
      <ref url="http://www.securityfocus.com/bid/3081" source="BID">3081</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.6" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0549" published="2001-08-14" name="CVE-2001-0549" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Symantec LiveUpdate 1.5 stores proxy passwords in cleartext in a registry key, which could allow local users to obtain the passwords.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/814187" source="CERT-VN" patch="1" adv="1">VU#814187</ref>
      <ref url="http://www.sarc.com/avcenter/security/Content/2001_07_20.html" source="CONFIRM" adv="1">http://www.sarc.com/avcenter/security/Content/2001_07_20.html</ref>
      <ref url="http://xforce.iss.net/static/7013.php" source="XF">liveupdate-obtain-proxy-password(7013)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="liveupdate">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0550" published="2001-11-30" name="CVE-2001-0550" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">wu-ftpd 2.6.1 allows remote attackers to execute arbitrary commands via a "~{" argument to commands such as CWD, which is not properly handled by the glob function (ftpglob).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/886083" source="CERT-VN" patch="1" adv="1">VU#886083</ref>
      <ref url="http://www.cert.org/advisories/CA-2001-33.html" source="CERT" patch="1" adv="1">CA-2001-33</ref>
      <ref url="http://www.securityfocus.com/bid/3581" source="BID" patch="1" adv="1">3581</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-157.html" source="REDHAT" patch="1" adv="1">RHSA-2001:157</ref>
      <ref url="http://www.caldera.com/support/security/advisories/CSSA-2001-041.0.txt" source="CALDERA" patch="1" adv="1">CSSA-2001-041.0</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/7611" source="XF">wuftp-glob-heap-corruption(7611)</ref>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0107-162" source="HP">HPSBUX0107-162</ref>
      <ref url="http://www.securityfocus.com/archive/82/180823" source="VULN-DEV">20010430 some ftpd implementations mishandle CWD ~{</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2001_043_wuftpd_txt.html" source="SUSE">SuSE-SA:2001:043</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-090.php3" source="MANDRAKE">MDKSA-2001:090</ref>
      <ref url="http://www.debian.org/security/2001/dsa-087" source="DEBIAN">DSA-087</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=100700363414799&amp;w=2" source="BUGTRAQ">20011128 CORE-20011001: Wu-FTP glob heap corruption vulnerability</ref>
      <ref url="http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-036-01" source="IMMUNIX">IMNX-2001-70-036-01</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000442" source="CONECTIVA">CLA-2001:442</ref>
    </refs>
    <vuln_soft>
      <prod vendor="david_madore" name="ftpd-bsd">
        <vers num="0.3.2" />
        <vers num="0.3.3" />
      </prod>
      <prod vendor="washington_university" name="wu-ftpd">
        <vers num="2.5.0" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0551" published="2001-05-22" name="CVE-2001-0551" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in CDE Print Viewer (dtprintinfo) allows local users to execute arbitrary code by copying text from the clipboard into the Help window.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/860296" source="CERT-VN" patch="1" adv="1">VU#860296</ref>
      <ref url="http://archives.neohapsis.com/archives/hp/2001-q2/0044.html" source="HP" patch="1" adv="1">HPSBUX0105-151</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5958" source="OVAL">oval:org.mitre.oval:def:5958</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.10" />
        <vers num="10.20" />
        <vers num="10.24" />
        <vers num="11.00" />
        <vers num="11.04" />
        <vers num="11.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0552" published="2001-09-20" name="CVE-2001-0552" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">ovactiond in HP OpenView Network Node Manager (NNM) 6.1 and Tivoli Netview 5.x and 6.x allows remote attackers to execute arbitrary commands via shell metacharacters in a certain SNMP trap message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/952171" source="CERT-VN" patch="1" adv="1">VU#952171</ref>
      <ref url="http://www.cert.org/advisories/CA-2001-24.html" source="CERT" patch="1" adv="1">CA-2001-24</ref>
      <ref url="http://www.securityfocus.com/bid/2845" source="BID" patch="1" adv="1">2845</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=99201278704545&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010608 HP Openview NNM6.1 ovactiond bin exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="5.01" />
        <vers num="6.1" />
      </prod>
      <prod vendor="ibm" name="tivoli_netview">
        <vers num="5.0" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0553" published="2001-08-14" name="CVE-2001-0553" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">SSH Secure Shell 3.0.0 on Unix systems does not properly perform password authentication to the sshd2 daemon, which allows local users to gain access to accounts with short password fields, such as locked accounts that use "NP" in the password field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/737451" source="CERT-VN">VU#737451</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-07/0486.html" source="BUGTRAQ" patch="1" adv="1">20010720 URGENT SECURITY ADVISORY FOR SSH SECURE SHELL 3.0.0</ref>
      <ref url="http://www.ssh.com/products/ssh/exploit.cfm" source="CONFIRM">http://www.ssh.com/products/ssh/exploit.cfm</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6868" source="XF">ssh-password-length-unauth-access(6868)</ref>
      <ref url="http://www.securityfocus.com/bid/3078" source="BID">3078</ref>
      <ref url="http://www.osvdb.org/586" source="OSVDB">586</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/l-121.shtml" source="CIAC">L-121</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ssh" name="secure_shell">
        <vers num="3.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0554" published="2001-08-14" name="CVE-2001-0554" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2001-21.html" source="CERT" patch="1" adv="1">CA-2001-21</ref>
      <ref url="http://www.securityfocus.com/bid/3064" source="BID" patch="1" adv="1">3064</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:49.telnetd.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-01:49</ref>
      <ref url="http://xforce.iss.net/static/6875.php" source="XF">telnetd-option-telrcv-bo(6875)</ref>
      <ref url="http://www.securityfocus.com/archive/1/197804" source="BUGTRAQ" adv="1">20010718 multiple vendor telnet daemon vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-100.html" source="REDHAT">RHSA-2001:100</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-099.html" source="REDHAT">RHSA-2001:099</ref>
      <ref url="http://www.osvdb.org/809" source="OSVDB">809</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2001_029_nkitb_txt.html" source="SUSE">SuSE-SA:2001:029</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-068.php3" source="MANDRAKE">MDKSA-2001:068</ref>
      <ref url="http://www.debian.org/security/2001/dsa-075" source="DEBIAN">DSA-075</ref>
      <ref url="http://www.debian.org/security/2001/dsa-070" source="DEBIAN">DSA-070</ref>
      <ref url="http://www.cisco.com/warp/public/707/catos-telrcv-vuln-pub.shtml" source="CISCO">20020129 Cisco CatOS Telnet Buffer Vulnerability</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/l-131.shtml" source="CIAC">L-131</ref>
      <ref url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-030.0.txt" source="CALDERA">CSSA-2001-030.0</ref>
      <ref url="http://online.securityfocus.com/archive/1/203000" source="BUGTRAQ">20010810 ADV/EXP: netkit &lt;=0.17 in.telnetd remote buffer overflow</ref>
      <ref url="http://online.securityfocus.com/archive/1/199541" source="BUGTRAQ">20010725 SCO - Telnetd AYT overflow ?</ref>
      <ref url="http://online.securityfocus.com/archive/1/199496" source="BUGTRAQ">20010725 Telnetd AYT overflow scanner</ref>
      <ref url="http://online.securityfocus.com/advisories/3476" source="IBM">MSS-OAR-E01-2001:298</ref>
      <ref url="http://ftp.support.compaq.com/patches/.new/html/SSRT0745U.shtml" source="COMPAQ">SSRT0745U</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000413" source="CONECTIVA">CLA-2001:413</ref>
      <ref url="http://archives.neohapsis.com/archives/hp/2001-q4/0014.html" source="HP">HPSBUX0110-172</ref>
      <ref url="ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.10/CSSA-2001-SCO.10.txt" source="CALDERA">CSSA-2001-SCO.10</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20010801-01-P" source="SGI">20010801-01-P</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2001-012.txt.asc" source="NETBSD">NetBSD-SA2001-012</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="1.0" />
        <vers num="5-1.2" />
        <vers num="5-1.2.1" />
        <vers num="5-1.2.2" />
        <vers num="5_1.1" />
        <vers num="5_1.1.1" />
      </prod>
      <prod vendor="netkit" name="linux_netkit">
        <vers num="0.10" />
        <vers num="0.11" />
        <vers num="0.12" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="3.5.1" />
        <vers num="4.1.1" />
        <vers num="4.2" />
        <vers num="4.3" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="5.1" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.5" />
        <vers num="1.5.1" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.6" />
        <vers num="2.7" />
        <vers num="2.8" />
      </prod>
      <prod vendor="sgi" name="irix">
        <vers num="6.5" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.5.1" />
        <vers num="2.6" />
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0555" published="2001-08-14" name="CVE-2001-0555" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">ScreamingMedia SITEWare versions 2.5 through 3.1 allows a remote attacker to read world-readable files via a ..  (dot dot) attack through (1) the SITEWare Editor's Desktop or (2) the template parameter in SWEditServlet.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/795707" source="CERT-VN">VU#795707</ref>
      <ref url="http://www01.screamingmedia.com/en/security/sms1001.php" source="CONFIRM" patch="1" adv="1">http://www01.screamingmedia.com/en/security/sms1001.php</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/6689" source="XF">siteware-dot-file-retrieval(6689)</ref>
      <ref url="http://www.securityfocus.com/bid/2869" source="BID">2869</ref>
      <ref url="http://www.osvdb.org/13887" source="OSVDB">13887</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-06/0166.html" source="BUGTRAQ" adv="1">20010613 ScreamingMedia SITEWare source code disclosure vulnerability </ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-06/0165.html" source="BUGTRAQ" adv="1">20010613 ScreamingMedia SITEWare arbitrary file retrieval vulnerability </ref>
    </refs>
    <vuln_soft>
      <prod vendor="screaming_media" name="siteware">
        <vers prev="1" num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0556" published="2001-08-22" name="CVE-2001-0556" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The Nirvana Editor (NEdit) 5.1.1 and earlier allows a local attacker to overwrite other users' files via a symlink attack on (1) backup files or (2) temporary files used when nedit prints a file or portions of a file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2667" source="BID" patch="1" adv="1">2667</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-061.html" source="REDHAT" patch="1" adv="1">RHSA-2001:061</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-042.php3" source="MANDRAKE" patch="1" adv="1">MDKSA-2001:042</ref>
      <ref url="http://www.debian.org/security/2001/dsa-053" source="DEBIAN" patch="1" adv="1">DSA-053</ref>
      <ref url="http://www.securityfocus.com/archive/1/180237" source="BUGTRAQ">20010428 More nedit problems ? (was Re: PROGENY-SA-2001-10...)</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2001_014_nedit.html" source="SUSE">SuSE-SA:2001:14</ref>
      <ref url="http://www.nedit.org/archives/develop/2001-Feb/0391.html" source="CONFIRM">http://www.nedit.org/archives/develop/2001-Feb/0391.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nedit" name="nedit">
        <vers prev="1" num="5.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0557" published="2001-08-14" name="CVE-2001-0557" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">T. Hauck Jana Webserver 1.46 and earlier allows a remote attacker to view arbitrary files via a '..' (dot dot) attack which is URL encoded (%2e%2e).</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/132099" source="CERT-VN">VU#132099</ref>
      <ref url="http://xforce.iss.net/static/6513.php" source="XF" patch="1" adv="1">jana-server-directory-traversal(6513)</ref>
      <ref url="http://www.securityfocus.com/bid/2703" source="BID" patch="1" adv="1">2703</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0086.html" source="BUGTRAQ" patch="1" adv="1">20010507 Advisory for Jana server </ref>
    </refs>
    <vuln_soft>
      <prod vendor="t._hauck" name="jana_web_server">
        <vers num="1.0j" />
        <vers num="1.45" />
        <vers prev="1" num="1.46" />
        <vers num="2.0_beta_1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0558" published="2001-08-14" name="CVE-2001-0558" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">T. Hauck Jana Webserver 2.01 beta 1 and earlier allows a remote attacker to create a denial of service via a URL request which includes a MS-DOS device name (i.e. GET /aux HTTP/1.0).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6521.php" source="XF" patch="1" adv="1">jana-server-device-dos(6521)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0086.html" source="BUGTRAQ" patch="1" adv="1">20010507 Advisory for Jana server </ref>
      <ref url="http://www.securityfocus.com/bid/2704" source="BID">2704</ref>
      <ref url="http://www.osvdb.org/1817" source="OSVDB">1817</ref>
    </refs>
    <vuln_soft>
      <prod vendor="t._hauck" name="jana_web_server">
        <vers num="1.45" />
        <vers num="1.46" />
        <vers num="2.0b2" />
        <vers num="2.0beta1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0559" published="2001-08-14" name="CVE-2001-0559" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">crontab in Vixie cron 3.0.1 and earlier does not properly drop privileges after the failed parsing of a modification operation, which could allow a local attacker to gain additional privileges when an editor is called to correct the error.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2687" source="BID" patch="1" adv="1">2687</ref>
      <ref url="http://www.securityfocus.com/archive/1/183029" source="BUGTRAQ" patch="1" adv="1">20010507 Vixie cron vulnerability</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-050.php3" source="MANDRAKE" patch="1" adv="1">MDKSA-2001:050</ref>
      <ref url="http://www.debian.org/security/2001/dsa-054" source="DEBIAN" adv="1">DSA-054</ref>
      <ref url="http://xforce.iss.net/static/6508.php" source="XF">vixie-cron-gain-privileges(6508)</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2001_017_cron_txt.html" source="SUSE">SuSE-SA:2001:17</ref>
    </refs>
    <vuln_soft>
      <prod vendor="paul_vixie" name="vixie_cron">
        <vers prev="1" num="3.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0560" published="2001-08-22" name="CVE-2001-0560" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in Vixie cron 3.0.1-56 and earlier could allow a local attacker to gain additional privileges via a long username (> 20 characters).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6098.php" source="XF" patch="1" adv="1">vixie-crontab-bo(6098)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-014.html" source="REDHAT" patch="1" adv="1">RHSA-2001:014</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-022.php3" source="MANDRAKE" patch="1" adv="1">MDKSA-2001:022</ref>
      <ref url="http://archives.neohapsis.com/archives/linux/immunix/2001-q1/0066.html" source="BUGTRAQ" patch="1" adv="1">20010220 Immunix OS Security update for vixie-cron</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0197.html" source="BUGTRAQ" patch="1" adv="1">20010210 vixie cron possible local root compromise </ref>
      <ref url="http://www.osvdb.org/5583" source="OSVDB">5583</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY17261&amp;apar=only" source="AIXAPAR">IY17261</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY17048&amp;apar=only" source="AIXAPAR">IY17048</ref>
    </refs>
    <vuln_soft>
      <prod vendor="paul_vixie" name="vixie_cron">
        <vers prev="1" num="3.0.1.56" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0561" published="2001-08-14" name="CVE-2001-0561" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to read arbitrary files via a '..' (dot dot) attack in (1) a1disp2.cgi, (2) a1disp3.cgi, or (3) a1disp4.cgi.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/471691" source="CERT-VN">VU#471691</ref>
      <ref url="http://xforce.iss.net/static/6503.php" source="XF" patch="1" adv="1">a1stats-dot-directory-traversal(6503)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0047.html" source="BUGTRAQ" patch="1" adv="1">20010507 Advisory for A1Stats</ref>
      <ref url="http://www.securityfocus.com/bid/2705" source="BID" adv="1">2705</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drummond_miles" name="a1stats">
        <vers num="1.0" />
        <vers prev="1" num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0562" published="2001-08-14" name="CVE-2001-0562" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">a1disp.cgi program in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to execute commands via a specially crafted URL which includes shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6505.php" source="XF" patch="1" adv="1">a1stats-a1admin-dos(6505)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0047.html" source="BUGTRAQ" patch="1" adv="1">20010507 Advisory for A1Stats</ref>
      <ref url="http://www.securityfocus.com/bid/2705" source="BID" adv="1">2705</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drummond_miles" name="a1stats">
        <vers prev="1" num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0563" published="2001-08-14" name="CVE-2001-0563" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ElectroSystems Engineering Inc. ElectroComm 2.0 and earlier allows a remote attacker to create a denial of service via large (> 160000 character) strings sent to port 23.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6514.php" source="XF" adv="1">electrocomm-telnet-dos(6514)</ref>
      <ref url="http://www.securityfocus.com/bid/2706" source="BID" adv="1">2706</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0049.html" source="BUGTRAQ" adv="1">20010507 Advisory for Electrocomm 2.0 </ref>
    </refs>
    <vuln_soft>
      <prod vendor="electrosoft" name="electrocomm">
        <vers num="1.0" />
        <vers prev="1" num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0564" published="2001-08-22" name="CVE-2001-0564" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">APC Web/SNMP Management Card prior to Firmware 310 only supports one telnet connection, which allows a remote attacker to create a denial of service via repeated failed logon attempts which temporarily locks the card.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0436.html" source="BUGTRAQ" adv="1">20010225 APC web/snmp/telnet management card dos </ref>
      <ref url="http://xforce.iss.net/static/6199.php" source="XF">apc-telnet-dos(6199)</ref>
      <ref url="http://www.securityfocus.com/bid/2430" source="BID">2430</ref>
      <ref url="ftp://ftp.apcftp.com/hardware/webcard/firmware/sy/v310/install.txt" source="MISC">ftp://ftp.apcftp.com/hardware/webcard/firmware/sy/v310/install.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apc" name="ap9606">
        <vers prev="1" num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0565" published="2001-08-14" name="CVE-2001-0565" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in mailx in Solaris 8 and earlier allows a local attacker to gain additional privileges via a long '-F' command line option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/446864" source="CERT-VN">VU#446864</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0016.html" source="BUGTRAQ" patch="1" adv="1">20010502 Solaris mailx Vulnerability </ref>
      <ref url="http://xforce.iss.net/static/8246.php" source="XF">solaris-mailx-f-bo(8246)</ref>
      <ref url="http://www.securityfocus.com/bid/2610" source="BID">2610</ref>
      <ref url="http://online.securityfocus.com/archive/1/184210" source="BUGTRAQ">20010511 Solaris /usr/bin/mailx exploit (SPARC)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":x86" />
        <vers num="2.5" edition=":sparc" />
        <vers num="2.5.1" edition="" />
        <vers num="2.5.1" edition=":sparc" />
        <vers num="2.5.1" edition=":x86" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":sparc" />
        <vers num="2.6" edition=":x86" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="7.0" edition=":sparc" />
        <vers prev="1" num="8.0" edition="" />
        <vers prev="1" num="8.0" edition=":sparc" />
        <vers prev="1" num="8.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0566" published="2001-08-14" name="CVE-2001-0566" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco Catalyst 2900XL switch allows a remote attacker to create a denial of service via an empty UDP packet sent to port 161 (SNMP) when SNMP is disabled.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6515.php" source="XF" patch="1" adv="1">cisco-catalyst-udp-dos(6515)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0040.html" source="BUGTRAQ" patch="1" adv="1">20010503 Cisco Catalyst 2900XL crashes with empty UDP packet when SNMP is disabled. </ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="catalyst_2900">
        <vers num="xl" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0567" published="2001-08-14" name="CVE-2001-0567" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Digital Creations Zope 2.3.2 and earlier allows a local attacker to gain additional privileges via the changing of ZClass permission mappings for objects and methods in the ZClass.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-065.html" source="REDHAT" patch="1" adv="1">RHSA-2001:065</ref>
      <ref url="http://www.zope.org/Products/Zope/Hotfix_2001-05-01/security_alert" source="CONFIRM">http://www.zope.org/Products/Zope/Hotfix_2001-05-01/security_alert</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-049.php3" source="MANDRAKE" adv="1">MDKSA-2001:049</ref>
      <ref url="http://www.debian.org/security/2001/dsa-055" source="DEBIAN" adv="1">DSA-055</ref>
      <ref url="http://xforce.iss.net/static/6958.php" source="XF">zope-zclass-gain-privileges(6958)</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000407" source="CONECTIVA">CLA-2001:407</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zope" name="zope">
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0568" published="2001-08-22" name="CVE-2001-0568" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Digital Creations Zope 2.3.1 b1 and earlier allows a local attacker (Zope user) with through-the-web scripting capabilities to alter ZClasses class attributes.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.zope.org/Products/Zope/Products/Zope/Products/Zope/Hotfix_2001-02-23" source="CONFIRM" patch="1" adv="1">http://www.zope.org/Products/Zope/Products/Zope/Products/Zope/Hotfix_2001-02-23</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-021.html" source="REDHAT" patch="1" adv="1">RHSA-2001:021</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-025.php3" source="MANDRAKE" patch="1">MDKSA-2001:025 </ref>
      <ref url="http://www.debian.org/security/2001/dsa-043" source="DEBIAN" patch="1" adv="1">DSA-043</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000382" source="CONECTIVA">CLA-2001:382</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zope" name="zope">
        <vers prev="1" num="2.3.1_b1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0569" published="2001-08-22" name="CVE-2001-0569" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Digital Creations Zope 2.3.1 b1 and earlier contains a problem in the method return values related to the classes (1) ObjectManager, (2) PropertyManager, and (3) PropertySheet.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.zope.org/Products/Zope/Products/Zope/Products/Zope/Hotfix_2001-02-23" source="CONFIRM" patch="1" adv="1">http://www.zope.org/Products/Zope/Products/Zope/Products/Zope/Hotfix_2001-02-23</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-021.html" source="REDHAT" patch="1" adv="1">RHSA-2001:021</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-025.php3" source="MANDRAKE" patch="1">MDKSA-2001:025 </ref>
      <ref url="http://www.debian.org/security/2001/dsa-043" source="DEBIAN" patch="1" adv="1">DSA-043</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000382" source="CONECTIVA">CLA-2001:382</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zope" name="zope">
        <vers prev="1" num="2.3.1_b1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0570" published="2001-08-14" name="CVE-2001-0570" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">minicom 1.83.1 and earlier allows a local attacker to gain additional privileges via numerous format string attacks.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6498.php" source="XF" patch="1" adv="1">minicom-xmodem-format-string(6498)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-067.html" source="REDHAT" patch="1" adv="1">RHSA-2001:067</ref>
      <ref url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-016.0.txt" source="CALDERA" patch="1" adv="1">CSSA-2001-016.0</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=99014300904714&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010517 Immunix OS Security update for minicom</ref>
      <ref url="http://www.securityfocus.com/archive/1/181922" source="BUGTRAQ">20010503 minicom exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="minicom" name="minicom">
        <vers prev="1" num="1.83.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0571" published="2001-08-22" name="CVE-2001-0571" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the web server for (1) Elron Internet Manager (IM) Message Inspector and (2) Anti-Virus before 3.0.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the requested URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2520" source="BID" patch="1" adv="1">2520</ref>
      <ref url="http://www.securityfocus.com/bid/2519" source="BID" patch="1" adv="1">2519</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98567864203963&amp;w=2" source="BUGTRAQ" adv="1">20010326 http://archives.neohapsis.com/archives/bugtraq/2001-03/0345.html</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98538867727489&amp;w=2" source="BUGTRAQ" adv="1">20010323 Elron IM Products Vulnerability </ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0382.html" source="BUGTRAQ">20010406 http://archives.neohapsis.com/archives/bugtraq/2001-03/0345.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="elron" name="im_anti_virus">
        <vers num="3.0.3" />
      </prod>
      <prod vendor="elron" name="im_message_inspector">
        <vers num="3.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0572" published="2001-08-22" name="CVE-2001-0572" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The SSH protocols 1 and 2 (aka SSH-2) as implemented in OpenSSH and other packages have various weaknesses which can allow a remote attacker to obtain the following information via sniffing: (1) password lengths or ranges of lengths, which simplifies brute force password guessing, (2) whether RSA or DSA authentication is being used, (3) the number of authorized_keys in RSA authentication, or (4) the lengths of shell commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/596827" source="CERT-VN">VU#596827</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-033.html" source="REDHAT" patch="1" adv="1">RHSA-2001:033</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-033.php3" source="MANDRAKE" patch="1" adv="1">MDKSA-2001:033</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0225.html" source="BUGTRAQ" patch="1" adv="1">20010318 Passive Analysis of SSH (Secure Shell) Traffic </ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000391" source="CONECTIVA" adv="1">CLA-2001:391</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openssh">
        <vers num="4.5" />
      </prod>
      <prod vendor="ssh" name="ssh">
        <vers num="1.2.24" />
        <vers num="1.2.25" />
        <vers num="1.2.26" />
        <vers num="1.2.27" />
        <vers num="1.2.28" />
        <vers num="1.2.29" />
        <vers num="1.2.30" />
        <vers num="1.2.31" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0573" published="2001-08-02" name="CVE-2001-0573" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">lsfs in AIX 4.x allows a local user to gain additional privileges by creating Trojan horse programs named (1) grep or (2) lslv in a certain directory that is under the user's control, which cause lsfs to access the programs in that directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/123651" source="CERT-VN">VU#123651</ref>
      <ref url="http://archives.neohapsis.com/archives/aix/2001-q2/0000.html" source="AIXAPAR" patch="1" adv="1">IY16909</ref>
      <ref url="http://xforce.iss.net/static/7007.php" source="XF">aix-lsfs-path(7007)</ref>
      <ref url="http://www.osvdb.org/5582" source="OSVDB">5582</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0574" published="2001-08-14" name="CVE-2001-0574" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in MP3Mystic prior to 1.04b3 allows a remote attacker to download arbitrary files via a '..' (dot dot) in the URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6504.php" source="XF" patch="1" adv="1">mp3mystic-dot-directory-traversal(6504)</ref>
      <ref url="http://www.securityfocus.com/bid/2699" source="BID" patch="1" adv="1">2699</ref>
      <ref url="http://mp3mystic.com/mp3mystic/news.phtml" source="CONFIRM" patch="1" adv="1">http://mp3mystic.com/mp3mystic/news.phtml</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0046.html" source="BUGTRAQ" patch="1" adv="1">20010507 Advisory for MP3Mystic</ref>
      <ref url="http://www.osvdb.org/1815" source="OSVDB">1815</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jason_rahaim" name="mp3mystic">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0575" published="2001-08-22" name="CVE-2001-0575" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in lpshut in SCO OpenServer 5.0.6 can allow a local attacker to gain additional privileges via a long first argument to lpshut.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6290.php" source="XF" patch="1" adv="1">sco-openserver-lpshut-bo(6290)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0404.html" source="BUGTRAQ" patch="1" adv="1">20010327 SCO 5.0.6 issues (lpshut) </ref>
      <ref url="http://security-archive.merton.ox.ac.uk/bugtraq-200104/0221.html" source="BUGTRAQ">20010412 SSE072B: SCO OpenServer revision of buffer overflow fixes</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="openserver">
        <vers num="5.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0576" published="2001-08-22" name="CVE-2001-0576" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">lpusers as included with SCO OpenServer 5.0 through 5.0.6 allows a local attacker to gain additional privileges via a buffer overflow attack in the '-u' command line parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6292.php" source="XF" patch="1" adv="1">sco-openserver-lpusers-bo(6292)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0407.html" source="BUGTRAQ" patch="1" adv="1">20010327 SCO 5.0.6 issues (lpusers) </ref>
      <ref url="http://security-archive.merton.ox.ac.uk/bugtraq-200104/0221.html" source="BUGTRAQ">20010412 SSE072B: SCO OpenServer revision of buffer overflow fixes</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="openserver">
        <vers prev="1" num="5.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0577" published="2001-08-22" name="CVE-2001-0577" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">recon in SCO OpenServer 5.0 through 5.0.6 can allow a local attacker to gain additional privileges via a buffer overflow attack in the first command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6289.php" source="XF" patch="1" adv="1">sco-openserver-recon-bo(6289)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0410.html" source="BUGTRAQ" patch="1" adv="1">20010327 SCO 5.0.6 issues (recon) </ref>
      <ref url="http://security-archive.merton.ox.ac.uk/bugtraq-200104/0221.html" source="BUGTRAQ">20010412 SSE072B: SCO OpenServer revision of buffer overflow fixes</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="openserver">
        <vers prev="1" num="5.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0578" published="2001-08-22" name="CVE-2001-0578" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in lpforms in SCO OpenServer 5.0-5.0.6 can allow a local attacker to gain additional privileges via a long first argument to the lpforms command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6293.php" source="XF" patch="1" adv="1">sco-openserver-lpforms-bo(6293)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0416.html" source="BUGTRAQ" patch="1" adv="1">20010327 SCO 5.0.6 issues (lpforms) </ref>
      <ref url="http://security-archive.merton.ox.ac.uk/bugtraq-200104/0221.html" source="BUGTRAQ">20010412 SSE072B: SCO OpenServer revision of buffer overflow fixes</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="openserver">
        <vers prev="1" num="5.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0579" published="2001-08-22" name="CVE-2001-0579" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">lpadmin in SCO OpenServer 5.0.6 can allow a local attacker to gain additional privileges via a buffer overflow attack in the first argument to the command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6291.php" source="XF" patch="1" adv="1">sco-openserver-lpadmin-bo(6291)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0421.html" source="BUGTRAQ" patch="1" adv="1">20010327 SCO 5.0.6 issues (lpadmin) </ref>
      <ref url="http://security-archive.merton.ox.ac.uk/bugtraq-200104/0221.html" source="BUGTRAQ">20010412 SSE072B: SCO OpenServer revision of buffer overflow fixes</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="openserver">
        <vers prev="1" num="5.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0580" published="2001-08-22" name="CVE-2001-0580" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Hughes Technologies Virtual DNS (VDNS) Server 1.0 allows a remote attacker to create a denial of service by connecting to port 6070, sending some data, and closing the connection.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0050.html" source="BUGTRAQ" patch="1" adv="1">200105007 Advisory for Vdns </ref>
    </refs>
    <vuln_soft>
      <prod vendor="hughes_technologies" name="dsl_vdns">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0581" published="2001-08-22" name="CVE-2001-0581" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Spytech Spynet Chat Server 6.5 allows a remote attacker to create a denial of service (crash) via a large number of connections to port 6387.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2701" source="BID" patch="1" adv="1">2701</ref>
      <ref url="http://xforce.iss.net/static/6509.php" source="XF" adv="1">spynet-connection-dos(6509)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0051.html" source="BUGTRAQ" adv="1">20010507 Advisory for Spynet Chat</ref>
    </refs>
    <vuln_soft>
      <prod vendor="spytech" name="spynet_chat">
        <vers prev="1" num="6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0582" published="2001-08-22" name="CVE-2001-0582" modified="2009-04-03" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Ben Spink CrushFTP FTP Server 2.1.6 and earlier allows a local attacker to access arbitrary files via a '..' (dot dot) attack, or variations, in (1) GET, (2) CD, (3) NLST, (4) SIZE, (5) RETR.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/110803" source="CERT-VN">VU#110803</ref>
      <ref url="http://xforce.iss.net/static/6495.php" source="XF" patch="1" adv="1">crushftp-directory-traversal(6495)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0036.html" source="BUGTRAQ" patch="1" adv="1">20010503 Vulnerabilities in CrushFTP Server </ref>
    </refs>
    <vuln_soft>
      <prod vendor="ben_spink" name="crushftp_ftp_server">
        <vers num="2.1.4" />
        <vers prev="1" num="2.1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0583" published="2001-08-22" name="CVE-2001-0583" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Alt-N Technologies MDaemon 3.5.4 allows a remote attacker to create a denial of service via the URL request of a MS-DOS device (such as GET /aux) to (1) the Worldclient service at port 3000, or (2) the Webconfig service at port 3001.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6240.php" source="XF" patch="1" adv="1">mdaemon-webservices-dos(6240)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0188.html" source="BUGTRAQ" patch="1" adv="1">20010315 def-2001-11: MDaemon 3.5.4 Dos-Device DoS</ref>
      <ref url="http://ftp1.deerfield.com/pub/mdaemon/Archive/3.5.6/" source="CONFIRM">http://ftp1.deerfield.com/pub/mdaemon/Archive/3.5.6/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alt-n" name="mdaemon">
        <vers num="3.5.4" edition="" />
        <vers num="3.5.4" edition=":standard" />
        <vers num="3.5.4" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0584" published="2001-08-22" name="CVE-2001-0584" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">IMAP server in Alt-N Technologies MDaemon 3.5.6 allows a local user to cause a denial of service (hang) via long (1) SELECT or (2) EXAMINE commands.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0365.html" source="BUGTRAQ" patch="1" adv="1">20010325 MDaemon IMAP Denial Of Service </ref>
      <ref url="http://xforce.iss.net/static/6279.php" source="XF" adv="1">mdaemon-imap-command-dos(6279)</ref>
      <ref url="http://www.securityfocus.com/bid/2508" source="BID" adv="1">2508</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alt-n" name="mdaemon">
        <vers num="3.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0585" published="2001-08-22" name="CVE-2001-0585" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Gordano NTMail 6.0.3c allows a remote attacker to create a denial of service via a long (>= 255 characters) URL request to port 8000 or port 9000.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6249.php" source="XF" patch="1" adv="1">ntmail-long-url-dos(6249)</ref>
      <ref url="http://www.securityfocus.com/bid/2494" source="BID" patch="1" adv="1">2494</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0248.html" source="BUGTRAQ" patch="1" adv="1">20010320 def-2001-13: NTMail Web Services DoS </ref>
    </refs>
    <vuln_soft>
      <prod vendor="gordano" name="ntmail">
        <vers num="6.0.3c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0586" published="2001-08-22" name="CVE-2001-0586" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">TrendMicro ScanMail for Exchange 3.5 Evaluation allows a local attacker to recover the administrative credentials for ScanMail via a combination of unprotected registry keys and weakly encrypted passwords.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/ntbugtraq/2001-q1/0049.html" source="BUGTRAQ" patch="1" adv="1">20010330 STAT Security Advisory: Trend Micro's ScanMail for Exchange store s passwords in registry unprotected </ref>
      <ref url="http://xforce.iss.net/static/6311.php" source="XF">scanmail-reveals-credentials(6311)</ref>
      <ref url="http://www.osvdb.org/5581" source="OSVDB">5581</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="scanmail_exchange">
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0587" published="2001-08-22" name="CVE-2001-0587" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">deliver program in MMDF 2.43.3b in SCO OpenServer 5.0.6 can allow a local attacker to gain additional privileges via a buffer overflow in the first argument to the command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6302.php" source="XF" patch="1" adv="1">sco-openserver-deliver-bo(6302)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0418.html" source="BUGTRAQ" patch="1" adv="1">20010327 SCO 5.0.6 MMDF issues (deliver) </ref>
      <ref url="http://www.securityfocus.com/bid/2583" source="BID">2583</ref>
      <ref url="http://security-archive.merton.ox.ac.uk/bugtraq-200104/0221.html" source="BUGTRAQ">20010412 SSE072B: SCO OpenServer revision of buffer overflow fixes</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="openserver">
        <vers num="5.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0588" published="2001-08-22" name="CVE-2001-0588" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">sendmail 8.9.3, as included with the MMDF 2.43.3b package in SCO OpenServer 5.0.6, can allow a local attacker to gain additional privileges via a buffer overflow in the first argument to the command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0417.html" source="BUGTRAQ" patch="1" adv="1">20010327 SCO 5.0.6 MMDF issues (sendmail 8.9.3) </ref>
      <ref url="http://security-archive.merton.ox.ac.uk/bugtraq-200104/0221.html" source="BUGTRAQ">20010412 SSE072B: SCO OpenServer revision of buffer overflow fixes</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="openserver">
        <vers num="5.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0589" published="2001-08-22" name="CVE-2001-0589" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">NetScreen ScreenOS prior to 2.5r6 on the NetScreen-10 and Netscreen-100 can allow a local attacker to bypass the DMZ 'denial' policy via specific traffic patterns.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2523" source="BID" patch="1" adv="1">2523</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0375.html" source="BUGTRAQ" patch="1" adv="1">20010326 Netscreen: DMZ Network Receives Some "Denied" Traffic </ref>
      <ref url="http://xforce.iss.net/static/6317.php" source="XF">netscreen-screenos-bypass-firewall(6317)</ref>
      <ref url="http://www.osvdb.org/1780" source="OSVDB">1780</ref>
    </refs>
    <vuln_soft>
      <prod vendor="juniper" name="netscreen_screenos">
        <vers num="1.64" />
        <vers num="1.66" />
        <vers num="2.1" />
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0590" published="2001-08-02" name="CVE-2001-0590" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end with an HTTP protocol specification (i.e. HTTP/1.0).</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0031.html" source="BUGTRAQ" adv="1">20010403 Re: Tomcat may reveal script source code by URL trickery </ref>
      <ref url="http://xforce.iss.net/static/6971.php" source="XF">jakarta-tomcat-jsp-source(6971)</ref>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBTL0112-004" source="HP">HPSBTL0112-004</ref>
      <ref url="http://www.osvdb.org/5580" source="OSVDB">5580</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="tomcat">
        <vers prev="1" num="3.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0591" published="2001-08-22" name="CVE-2001-0591" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Oracle JSP 1.0.x through 1.1.1 and Oracle 8.1.7 iAS Release 1.0.2 can allow a remote attacker to read or execute arbitrary .jsp files via a '..' (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2286" source="BID" patch="1" adv="1">2286</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0239.html" source="BUGTRAQ" patch="1" adv="1">20010212 Patch for Potential Vulnerability in the execution of JSPs outside doc_root </ref>
      <ref url="http://xforce.iss.net/static/5986.php" source="XF">oracle-handlers-directory-traversal(5986)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="1.0.2" />
      </prod>
      <prod vendor="oracle" name="jsp">
        <vers prev="1" num="1.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0592" published="2001-08-02" name="CVE-2001-0592" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Watchguard Firebox II prior to 4.6 allows a remote attacker to create a denial of service in the kernel via a large stream (>10,000) of malformed ICMP or TCP packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6327.php" source="XF" patch="1" adv="1">firebox-kernel-dos(6327)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0054.html" source="BUGTRAQ" patch="1" adv="1">20010405 def-2001-18: Watchguard Firebox II Kernel DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="watchguard" name="firebox_ii">
        <vers prev="1" num="4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0593" published="2001-08-22" name="CVE-2001-0593" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Ananconda Partners Clipper 3.3 and earlier allows a remote attacker to read arbitrary files via a '..' (dot dot) attack in the template parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0395.html" source="BUGTRAQ" patch="1" adv="1">20010327 advisory </ref>
      <ref url="http://xforce.iss.net/static/6286.php" source="XF" adv="1">anaconda-clipper-directory-traversal(6286)</ref>
      <ref url="http://www.securityfocus.com/bid/2512" source="BID" adv="1">2512</ref>
      <ref url="http://anacondapartners.com/cgi-local/apexec.pl?template=ap_releasenotestemplate.html&amp;f1=ap_af_updates_menu&amp;f2=ap_af_releasenotes_clip" source="MISC">http://anacondapartners.com/cgi-local/apexec.pl?template=ap_releasenotestemplate.html&amp;f1=ap_af_updates_menu&amp;f2=ap_af_releasenotes_clip</ref>
    </refs>
    <vuln_soft>
      <prod vendor="anaconda_partners" name="clipper">
        <vers prev="1" num="3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0594" published="2001-08-02" name="CVE-2001-0594" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6359.php" source="XF" patch="1" adv="1">solaris-kcms-command-bo(6359)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0140.html" source="BUGTRAQ" patch="1" adv="1">20010409 Solaris kcms_configure vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/2558" source="BID" adv="1">2558</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7" source="OVAL" sig="1">oval:org.mitre.oval:def:7</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:65" source="OVAL" sig="1">oval:org.mitre.oval:def:65</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0595" published="2001-08-02" name="CVE-2001-0595" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in the kcsSUNWIOsolf.so library in Solaris 7 and 8 allows local attackers to execute arbitrary commands via the KCMS_PROFILES environment variable, e.g. as demonstrated using the kcms_configure program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6365.php" source="XF" patch="1" adv="1">solaris-kcssunwiosolf-bo(6365)</ref>
      <ref url="http://www.securityfocus.com/bid/2605" source="BID">2605</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0203.html" source="BUGTRAQ" adv="1">20010411 [LSD] Solaris kcsSUNWIOsolf.so and dtsession vulnerabilities </ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="7.0" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0596" published="2001-08-02" name="CVE-2001-0596" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Netscape Communicator before 4.77 allows remote attackers to execute arbitrary Javascript via a GIF image whose comment contains the Javascript.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6344.php" source="XF" patch="1" adv="1">netscape-javascript-access-data(6344)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-046.html" source="REDHAT" patch="1" adv="1">RHSA-2001:046</ref>
      <ref url="http://www.debian.org/security/2001/dsa-051" source="DEBIAN" patch="1" adv="1">DSA-051</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98685237415117&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010409 Netscape 4.76 gif comment flaw</ref>
      <ref url="http://www.securityfocus.com/bid/2637" source="BID">2637</ref>
      <ref url="http://www.osvdb.org/5579" source="OSVDB">5579</ref>
      <ref url="http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-014-01" source="IMMUNIX">IMNX-2001-70-014-01</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000393" source="CONECTIVA">CLA-2001:393</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="communicator">
        <vers prev="1" num="4.77" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0597" published="2001-08-02" name="CVE-2001-0597" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Zetetic Secure Tool for Recalling Important Passwords (STRIP) 0.5 and earlier for the PalmOS allows a local attacker to recover passwords via a brute force attack.  This attack is made feasible by STRIP's use of SysRandom, which is seeded by TimeGetTicks, and an implementation flaw which vastly reduces the password 'search space'.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6362.php" source="XF" patch="1" adv="1">strip-weak-passwords(6362)</ref>
      <ref url="http://www.securityfocus.com/bid/2567" source="BID" patch="1" adv="1">2567</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0169.html" source="BUGTRAQ" patch="1" adv="1">20010410 Catastrophic failure of Strip password generation. </ref>
    </refs>
    <vuln_soft>
      <prod vendor="zetetic_enterprises" name="strip">
        <vers num="0.3" />
        <vers num="0.4" />
        <vers prev="1" num="0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0598" published="2001-08-02" name="CVE-2001-0598" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Symantec Ghost 6.5 and earlier allows a remote attacker to create a denial of service by sending large (> 45Kb) amounts of data to the Ghost Configuration Server on port 1347, which triggers an error that is not properly handled.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6357.php" source="XF" patch="1" adv="1">ghost-configuration-server-dos(6357)</ref>
      <ref url="http://www.securityfocus.com/bid/2570" source="BID" patch="1" adv="1">2570</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0175.html" source="BUGTRAQ" patch="1" adv="1">20010411 def-2001-21: Ghost Multiple DoS </ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="norton_ghost">
        <vers prev="1" num="6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0599" published="2001-08-02" name="CVE-2001-0599" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sybase Adaptive Server Anywhere Database Engine 6.0.3.2747 and earlier as included with Symantec Ghost 6.5 allows a remote attacker to create a denial of service by sending large (> 45Kb) amounts of data to port 2638.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6356.php" source="XF" patch="1" adv="1">ghost-database-engine-dos(6356)</ref>
      <ref url="http://www.securityfocus.com/bid/2572" source="BID" patch="1" adv="1">2572</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0175.html" source="BUGTRAQ" patch="1" adv="1">20010411 def-2001-21: Ghost Multiple DoS </ref>
    </refs>
    <vuln_soft>
      <prod vendor="sybase" name="adaptive_server_anywhere">
        <vers prev="1" num="6.0.3.2747" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0600" published="2001-08-02" name="CVE-2001-0600" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Lotus Domino R5 prior to 5.0.7 allows a remote attacker to create a denial of service via repeated URL requests with the same HTTP headers, such as (1) Accept, (2) Accept-Charset, (3) Accept-Encoding, (4) Accept-Language, and (5) Content-Type.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6347.php" source="XF" patch="1" adv="1">lotus-domino-header-dos(6347)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0174.html" source="BUGTRAQ" patch="1" adv="1">20010411 def-2001-20: Lotus Domino Multiple DoS </ref>
    </refs>
    <vuln_soft>
      <prod vendor="lotus" name="domino_r5_server">
        <vers prev="1" num="5.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0601" published="2001-08-02" name="CVE-2001-0601" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Lotus Domino R5 prior to 5.0.7 allows a remote attacker to create a denial of service via HTTP requests containing certain combinations of UNICODE characters.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6349.php" source="XF" patch="1" adv="1">lotus-domino-unicode-dos(6349)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0174.html" source="BUGTRAQ" adv="1">20010411 def-2001-20: Lotus Domino Multiple DoS </ref>
    </refs>
    <vuln_soft>
      <prod vendor="lotus" name="domino_r5_server">
        <vers prev="1" num="5.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0602" published="2001-08-02" name="CVE-2001-0602" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Lotus Domino R5 prior to 5.0.7 allows a remote attacker to create a denial of service via repeated (>400) URL requests for DOS devices.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6348.php" source="XF" patch="1" adv="1">lotus-domino-device-dos(6348)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0174.html" source="BUGTRAQ" patch="1" adv="1">20010411 def-2001-20: Lotus Domino Multiple DoS </ref>
    </refs>
    <vuln_soft>
      <prod vendor="lotus" name="domino_r5_server">
        <vers prev="1" num="5.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0603" published="2001-08-02" name="CVE-2001-0603" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Lotus Domino R5 prior to 5.0.7 allows a remote attacker to create a denial of service via repeatedly sending large (> 10Kb) amounts of data to the DIIOP - CORBA service on TCP port 63148.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6350.php" source="XF" patch="1" adv="1">lotus-domino-corba-dos(6350)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0174.html" source="BUGTRAQ" patch="1" adv="1">20010411 def-2001-20: Lotus Domino Multiple DoS </ref>
    </refs>
    <vuln_soft>
      <prod vendor="lotus" name="domino_r5_server">
        <vers prev="1" num="5.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0604" published="2001-08-02" name="CVE-2001-0604" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Lotus Domino R5 prior to 5.0.7 allows a remote attacker to create a denial of service via URL requests (>8Kb) containing a large number of '/' characters.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6351.php" source="XF" patch="1" adv="1">lotus-domino-url-dos(6351)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0174.html" source="BUGTRAQ" patch="1" adv="1">20010411 def-2001-20: Lotus Domino Multiple DoS </ref>
    </refs>
    <vuln_soft>
      <prod vendor="lotus" name="domino_r5_server">
        <vers prev="1" num="5.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0605" published="2001-08-22" name="CVE-2001-0605" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Headlight Software MyGetright prior to 1.0b allows a remote attacker to upload and/or overwrite arbitrary files via a malicious .dld (skins-data) file which contains long strings of random data.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98321819112158&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010226 My Getright Unsupervised File Download Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="headlight_software" name="mygetright">
        <vers prev="1" num="1.0b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0606" published="2001-08-22" name="CVE-2001-0606" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Vulnerability in iPlanet Web Server 4.X in HP-UX 11.04 (VVOS) with VirtualVault A.04.00 allows a remote attacker to create a denial of service via the HTTPS service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6110.php" source="XF" patch="1">hp-virtualvault-iws-dos(6110)</ref>
      <ref url="http://archives.neohapsis.com/archives/hp/2001-q1/0041.html" source="HP" patch="1" adv="1">HPSBUX0102-139</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="virtualvault">
        <vers num="4.0" />
      </prod>
      <prod vendor="sun" name="iplanet_web_server">
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0607" published="2001-08-22" name="CVE-2001-0607" modified="2009-03-04" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">asecure as included with HP-UX 10.01 through 11.00 can allow a local attacker to create a denial of service and gain additional privileges via unsafe permissions on the asecure program, a different vulnerability than CVE-2000-0083.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/hp/2001-q1/0080.html" source="HP" patch="1" adv="1">HPSBUX0103-145 </ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5621" source="OVAL">oval:org.mitre.oval:def:5621</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers prev="1" num="11.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0608" published="2001-08-22" name="CVE-2001-0608" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">HP architected interface facility (AIF) as includes with MPE/iX 5.5 through 6.5 running on a HP3000 allows an attacker to gain additional privileges and gain access to databases via the AIF - AIFCHANGELOGON program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/895496" source="CERT-VN">VU#895496</ref>
      <ref url="http://archives.neohapsis.com/archives/hp/2001-q1/0087.html" source="HP" patch="1" adv="1">HPSBMP0103-011</ref>
      <ref url="http://xforce.iss.net/static/6951.php" source="XF">hp-aif-gain-privileges(6951)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="mpe">
        <vers prev="1" num="6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0609" published="2001-08-02" name="CVE-2001-0609" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in Infodrom cfingerd 1.4.3 and earlier allows a remote attacker to gain additional privileges via a malformed ident reply that is passed to the syslog function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6364.php" source="XF" patch="1" adv="1">cfingerd-remote-format-string(6364)</ref>
      <ref url="http://www.securityfocus.com/bid/2576" source="BID" patch="1" adv="1">2576</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0202.html" source="BUGTRAQ" patch="1" adv="1">20010411 CFINGERD remote vulnerability </ref>
    </refs>
    <vuln_soft>
      <prod vendor="infodrom" name="cfingerd">
        <vers num="1.4.0" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers prev="1" num="1.4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0610" published="2001-08-02" name="CVE-2001-0610" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">kfm as included with KDE 1.x can allow a local attacker to gain additional privileges via a symlink attack in the kfm cache directory in /tmp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6428.php" source="XF" patch="1" adv="1">kfm-tmpfile-symlink(6428)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0336.html" source="BUGTRAQ">20010418 Insecure directory handling in KFM file manager </ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="kde">
        <vers num="1.x" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":ppc" />
        <vers num="7.0" edition=":sparc" />
        <vers num="7.0" edition="alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0611" published="2001-08-14" name="CVE-2001-0611" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Becky! 2.00.05 and earlier can allow a remote attacker to gain additional privileges via a buffer overflow attack on long messages without newline characters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6531.php" source="XF" patch="1" adv="1">becky-mail-message-bo(6531)</ref>
      <ref url="http://www.securityfocus.com/bid/2723" source="BID" patch="1" adv="1">2723</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0089.html" source="BUGTRAQ" patch="1" adv="1">20010514 Becky! 2.00.05 Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rimarts_inc." name="becky_internet_mail">
        <vers num="1.26.3" />
        <vers num="1.26.4" />
        <vers num="1.26.5" />
        <vers num="2.0.3" />
        <vers num="2.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0612" published="2001-08-22" name="CVE-2001-0612" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">McAfee Remote Desktop 3.0 and earlier allows remote attackers to cause a denial of service (crash) via a large number of packets to port 5045.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2726" source="BID" patch="1" adv="1">2726</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0158.html" source="BUGTRAQ" patch="1" adv="1">20010516 Remote Desktop DoS </ref>
      <ref url="http://xforce.iss.net/static/6547.php" source="XF" adv="1">remote-desktop-dos(6547)</ref>
      <ref url="http://www.osvdb.org/6288" source="OSVDB">6288</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcafee" name="remote_desktop_32">
        <vers num="2.1.2" />
        <vers prev="1" num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0613" published="2001-08-22" name="CVE-2001-0613" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Omnicron Technologies OmniHTTPD Professional 2.08 and earlier allows a remote attacker to create a denial of service via a long POST URL request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6540.php" source="XF" adv="1">omnihttpd-post-dos(6540)</ref>
      <ref url="http://www.securityfocus.com/bid/2730" source="BID" adv="1">2730</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0131.html" source="BUGTRAQ" adv="1">20010515 OmniHTTPd Pro Denial of Service Vulnerability </ref>
    </refs>
    <vuln_soft>
      <prod vendor="omnicron" name="omnihttpd">
        <vers prev="1" num="2.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0614" published="2001-08-22" name="CVE-2001-0614" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Carello E-Commerce 1.2.1 and earlier allows a remote attacker to gain additional privileges and execute arbitrary commands via a specially constructed URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6532.php" source="XF" patch="1" adv="1">carello-url-code-execution(6532)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98991352402073&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010514 def-2001-25: Carello E-Commerce Arbitrary Command Execution </ref>
    </refs>
    <vuln_soft>
      <prod vendor="carello" name="e-commerce">
        <vers prev="1" num="1.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0615" published="2001-08-14" name="CVE-2001-0615" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Faust Informatics Freestyle Chat server prior to 4.1 SR3 allows a remote attacker to read arbitrary files via a specially crafted URL which includes variations of a '..' (dot dot) attack such as '...' or '....'.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6601.php" source="XF" patch="1" adv="1">freestyle-chat-directory-traversal(6601)</ref>
      <ref url="http://www.securityfocus.com/bid/2776" source="BID" patch="1" adv="1">2776</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0241.html" source="BUGTRAQ" patch="1" adv="1">20010525 Advisory for Freestyle Chat server</ref>
      <ref url="http://www.osvdb.org/1841" source="OSVDB">1841</ref>
    </refs>
    <vuln_soft>
      <prod vendor="faust_informatics" name="freestyle_chat">
        <vers prev="1" num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0616" published="2001-08-14" name="CVE-2001-0616" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Faust Informatics Freestyle Chat server prior to 4.1 SR3 allows a remote attacker to create a denial of service via a URL request which includes a MS-DOS device name (e.g., GET /aux HTTP/1.0).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6602.php" source="XF" patch="1" adv="1">freestyle-chat-device-dos(6602)</ref>
      <ref url="http://www.securityfocus.com/bid/2777" source="BID" patch="1" adv="1">2777</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0241.html" source="BUGTRAQ" patch="1" adv="1">20010525 Advisory for Freestyle Chat server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="faust_informatics" name="freestyle_chat">
        <vers prev="1" num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0617" published="2001-08-22" name="CVE-2001-0617" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Allied Telesyn AT-AR220e cable/DSL router firmware 1.08a RC14 with the portmapper and the 'Virtual Server' enabled can allow a remote attacker to gain access to mapped services even though the single portmappings may be disabled.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6560.php" source="XF" patch="1" adv="1">telesyn-portmapper-access-services(6560)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0125.html" source="BUGTRAQ" patch="1" adv="1">20010514 Cable-Router AR220e Portmapper Security-Flaw </ref>
    </refs>
    <vuln_soft>
      <prod vendor="alliedtelesyn" name="at-ar220e">
        <vers num="1.08a" edition="rc14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0618" published="2001-08-02" name="CVE-2001-0618" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Orinoco RG-1000 wireless Residential Gateway uses the last 5 digits of the 'Network Name' or SSID as the default Wired Equivalent Privacy (WEP) encryption key.  Since the SSID occurs in the clear during communications, a remote attacker could determine the WEP key and decrypt RG-1000 traffic.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6328.php" source="XF" patch="1" adv="1">orinoco-rg1000-wep-key(6328)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0020.html" source="BUGTRAQ" adv="1">20010402 RG-1000 802.11 Residential Gateway default WEP key disclosure flaw </ref>
    </refs>
    <vuln_soft>
      <prod vendor="lucent" name="orinoco_rg-1000">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0619" published="2001-08-02" name="CVE-2001-0619" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Lucent Closed Network protocol can allow remote attackers to join Closed Network networks which they do not have access to.  The 'Network Name' or SSID, which is used as a shared secret to join the network, is transmitted in the clear.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0015.html" source="BUGTRAQ" adv="1">20010402 Design Flaw in Lucent/Orinoco 802.11 proprietary access control- closed network</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lucent" name="orinoco">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0620" published="2001-08-02" name="CVE-2001-0620" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">iPlanet Calendar Server 5.0p2 and earlier allows a local attacker to gain access to the Netscape Admin Server (NAS) LDAP database and read arbitrary files by obtaining the cleartext administrator username and password from the configuration file, which has insecure permissions.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6402.php" source="XF" adv="1">iplanet-calendar-plaintext-password(6402)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0320.html" source="BUGTRAQ">20010418 iplanet calendar server 5.0p2 exposes Netscape Admin Server master password </ref>
    </refs>
    <vuln_soft>
      <prod vendor="iplanet" name="calendar_server">
        <vers prev="1" num="5.0p2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0621" published="2001-08-14" name="CVE-2001-0621" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The FTP server on Cisco Content Service 11000 series switches (CSS) before WebNS 4.01B23s and WebNS 4.10B13s allows an attacker who is an FTP user to read and write arbitrary files via GET or PUT commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6557.php" source="XF" patch="1" adv="1">cisco-css-ftp-commands(6557)</ref>
      <ref url="http://www.cisco.com/warp/public/707/arrowpoint-ftp-pub.shtml" source="CISCO" patch="1" adv="1">20010517 Cisco Content Service Switch 11000 Series FTP Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/2745" source="BID">2745</ref>
      <ref url="http://www.osvdb.org/1834" source="OSVDB">1834</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/l-085.shtml" source="CIAC">L-085</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="content_services_switch_11000">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0622" published="2001-08-14" name="CVE-2001-0622" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The web management service on Cisco Content Service series 11000 switches (CSS) before WebNS 4.01B29s or WebNS 4.10B17s allows a remote attacker to gain additional privileges by directly requesting the web management URL instead of navigating through the interface.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/arrowpoint-webmgmt-vuln-pub.shtml" source="CISCO" patch="1" adv="1">20010531 Cisco Content Service Switch 11000 Series Web Management Vulnerability</ref>
      <ref url="http://xforce.iss.net/static/6631.php" source="XF">cisco-css-web-management(6631)</ref>
      <ref url="http://www.securityfocus.com/bid/2806" source="BID">2806</ref>
      <ref url="http://www.osvdb.org/1848" source="OSVDB">1848</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="content_services_switch_11000">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0623" published="2001-08-02" name="CVE-2001-0623" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">sendfiled, as included with Simple Asynchronous File Transfer (SAFT), on various Linux systems does not properly drop privileges when sending notification emails, which allows local attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6430.php" source="XF" patch="1" adv="1">saft-sendfiled-execute-code(6430)</ref>
      <ref url="http://www.debian.org/security/2001/dsa-052" source="DEBIAN" patch="1" adv="1">DSA-052</ref>
      <ref url="http://www.debian.org/security/2001/dsa-050" source="DEBIAN">DSA-050</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sendfile" name="sendfile">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0624" published="2001-08-02" name="CVE-2001-0624" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">QNX 2.4 allows a local user to read arbitrary files by directly accessing the mount point for the FAT disk partition, e.g. /fs-dos.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6437.php" source="XF" adv="1">qnx-fat-file-read</ref>
      <ref url="http://archives.neohapsis.com/archives/vuln-dev/2001-q2/0266.html" source="VULN-DEV" adv="1">20010421 QNX FIle Read Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qnx" name="qnx">
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0625" published="2001-08-22" name="CVE-2001-0625" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">ftpdownload in Computer Associates InoculateIT 6.0 allows a local attacker to overwrite arbitrary files via a symlink attack on /tmp/ftpdownload.log .</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6607.php" source="XF" adv="1">inoculateit-ftpdownload-symlink(6607)</ref>
      <ref url="http://www.securityfocus.com/bid/2778" source="BID">2778</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0245.html" source="BUGTRAQ" adv="1">20010525 Security Bug in InoculateIT for Linux (fwd) </ref>
      <ref url="http://www.osvdb.org/1843" source="OSVDB">1843</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="inoculateit">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0626" published="2001-08-22" name="CVE-2001-0626" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">O'Reilly Website Professional 2.5.4 and earlier allows remote attackers to determine the physical path to the root directory via a URL request containing a ":" character.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2488" source="BID" adv="1">2488</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0236.html" source="BUGTRAQ" adv="1">20010316 WebServer Pro All Version Vulnerability</ref>
      <ref url="http://xforce.iss.net/static/3839.php" source="XF">website-pro-dir-path(3839)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oreilly" name="website_professional">
        <vers prev="1" num="2.5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0627" published="2001-08-22" name="CVE-2001-0627" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">vi as included with SCO OpenServer 5.0 - 5.0.6 allows a local attacker to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/747736" source="CERT-VN">VU#747736</ref>
      <ref url="http://www.securityfocus.com/bid/2752" source="BID" adv="1">2752</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0220.html" source="BUGTRAQ" adv="1">20010522 [SRT2001-09] - vi and crontab -e /tmp issues </ref>
      <ref url="http://xforce.iss.net/static/6588.php" source="XF">sco-openserver-vi-symlink(6588)</ref>
      <ref url="ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.17/CSSA-2001-SCO.17.txt" source="CALDERA">CSSA-2001-SCO.17</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="openserver">
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0628" published="2001-08-14" name="CVE-2001-0628" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Microsoft Word 2000 does not check AutoRecovery (.asd) files for macros, which allows a local attacker to execute arbitrary macros with the user ID of the Word user.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6614.php" source="XF" patch="1" adv="1">word-asd-macro-execution(6614)</ref>
      <ref url="http://www.securityfocus.com/bid/2760" source="BID" patch="1" adv="1">2760</ref>
      <ref url="http://support.microsoft.com/support/kb/articles/Q274/2/28.asp" source="MSKB" patch="1" adv="1">Q274228</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="word">
        <vers num="2000" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0629" published="2001-08-14" name="CVE-2001-0629" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">HP Event Correlation Service (ecsd) as included with OpenView Network Node Manager 6.1 allows a remote attacker to gain addition privileges via a buffer overflow attack in the '-restore_config' command line parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6582.php" source="XF" patch="1" adv="1">openview-nnm-ecsd-bo(6582)</ref>
      <ref url="http://www.securityfocus.com/bid/2761" source="BID" patch="1" adv="1">2761</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0226.html" source="BUGTRAQ" patch="1" adv="1">20010523 HP OpenView NNM v6.1 buffer overflow </ref>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0107-158" source="HP">HPSBUX0107-158</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0630" published="2001-08-22" name="CVE-2001-0630" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in MIMAnet viewsrc.cgi 2.0 allows a remote attacker to read arbitrary files via a '..' (dot dot) attack in the 'loc' variable.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2762" source="BID" patch="1" adv="1">2762</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0231.html" source="BUGTRAQ" patch="1" adv="1">20010523 Vulnerability in viewsrc.cgi </ref>
      <ref url="http://xforce.iss.net/static/6583.php" source="XF">viewsrc-cgi-view-files(6583)</ref>
      <ref url="http://www.osvdb.org/5565" source="OSVDB">5565</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mimanet" name="source_viewer">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0631" published="2001-08-22" name="CVE-2001-0631" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Centrinity First Class Internet Services 5.50 allows for the circumventing of the default 'spam' filters via the presence of '&lt;@>' in the 'From:' field, which allows remote attackers to send spoofed email with the identity of local users.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0440.html" source="BUGTRAQ" adv="1">20010226 Re: [Fwd: FirstClass Internetgateway "stupidity"] </ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0376.html" source="BUGTRAQ" adv="1">20010221 FirstClass Internetgateway "stupidity" </ref>
      <ref url="http://xforce.iss.net/static/6192.php" source="XF">centrinity-firstclass-email-spoofing(6192)</ref>
      <ref url="http://www.securityfocus.com/bid/2423" source="BID">2423</ref>
    </refs>
    <vuln_soft>
      <prod vendor="centrinity" name="centrinity_firstclass">
        <vers num="5.50" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0632" published="2001-08-22" name="CVE-2001-0632" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Sun Chili!Soft 3.5.2 on Linux and 3.6 on AIX creates a default admin username and password in the default installation, which can allow a remote attacker to gain additional privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0443.html" source="BUGTRAQ" patch="1" adv="1">20010224 Re: Advisory: Chili!Soft ASP Multiple Vulnerabilities </ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0378.html" source="BUGTRAQ" adv="1">20010220 Advisory: Chili!Soft ASP Multiple Vulnerabilities </ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="chilisoft">
        <vers num="3.5.2" />
        <vers num="3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0633" published="2001-08-22" name="CVE-2001-0633" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Sun Chili!Soft ASP on multiple Unixes allows a remote attacker to read arbitrary files above the web root via a '..' (dot dot) attack in the sample script 'codebrws.asp'.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0443.html" source="BUGTRAQ" patch="1" adv="1">20010224 Re: Advisory: Chili!Soft ASP Multiple Vulnerabilities </ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0378.html" source="BUGTRAQ" adv="1">20010220 Advisory: Chili!Soft ASP Multiple Vulnerabilities </ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="chilisoft">
        <vers prev="1" num="3.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0634" published="2001-08-22" name="CVE-2001-0634" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Sun Chili!Soft ASP has weak permissions on various configuration files, which allows a local attacker to gain additional privileges and create a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0443.html" source="BUGTRAQ" patch="1" adv="1">20010226 Re: Advisory: Chili!Soft ASP Multiple Vulnerabilities </ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0378.html" source="BUGTRAQ" patch="1" adv="1">20010220 Advisory: Chili!Soft ASP Multiple Vulnerabilities </ref>
      <ref url="http://xforce.iss.net/static/6176.php" source="XF">chilisoft-asp-license-dos(6176)</ref>
      <ref url="http://www.securityfocus.com/bid/2409" source="BID">2409</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="chilisoft">
        <vers prev="1" num="3.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0635" published="2001-08-14" name="CVE-2001-0635" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Red Hat Linux 7.1 sets insecure permissions on swap files created during installation, which can allow a local attacker to gain additional privileges by reading sensitive information from the swap file, such as passwords.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-058.html" source="REDHAT" patch="1" adv="1">RHSA-2001:058</ref>
      <ref url="http://xforce.iss.net/static/6493.php" source="XF">mount-swap-world-readable(6493)</ref>
      <ref url="http://www.osvdb.org/5564" source="OSVDB">5564</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="linux">
        <vers num="7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0636" published="2001-09-20" name="CVE-2001-0636" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflows in Raytheon SilentRunner allow remote attackers to (1) cause a denial of service in the collector (cle.exe) component of SilentRunner 2.0 via traffic containing long passwords, or (2) execute arbitrary commands via long HTTP queries in the Knowledge Browser component in SilentRunner 2.0 and 2.0.1.  NOTE: It is highly likely that this candidate will be split into multiple candidates.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/alerts/advise91.php" source="ISS" adv="1">20010806 Multiple Buffer Overflow Vulnerabilities in Raytheon SilentRunner</ref>
    </refs>
    <vuln_soft>
      <prod vendor="raytheon" name="silentrunner">
        <vers num="2.0" />
        <vers num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0641" published="2001-09-20" name="CVE-2001-0641" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in man program in various distributions of Linux allows local user to execute arbitrary code as group man via a long -S option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6530.php" source="XF" patch="1" adv="1">man-s-bo(6530)</ref>
      <ref url="http://www.securityfocus.com/bid/2711" source="BID" patch="1" adv="1">2711</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-069.html" source="REDHAT" patch="1" adv="1">RHSA-2001:069</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0087.html" source="BUGTRAQ" adv="1">20010513 RH 7.0:/usr/bin/man exploit: gid man + more</ref>
      <ref url="http://www.securityfocus.com/archive/1/190136" source="BUGTRAQ">20010612 man 1.5h10 + man 1.5i-4 exploits</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2001_019_man_txt.html" source="SUSE">SuSE-SA:2001:019</ref>
    </refs>
    <vuln_soft>
      <prod vendor="immunix" name="immunix">
        <vers num="6.2" />
        <vers num="7.0" />
        <vers num="7.0_beta" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="5.2" />
        <vers num="6.2" />
        <vers num="7.0" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
        <vers num="7.0" />
        <vers num="7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0642" published="2001-09-20" name="CVE-2001-0642" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Directory traversal vulnerability in IncrediMail version 1400185 and earlier allows local users to overwrite files on the local hard drive by appending .. (dot dot) sequences to filenames listed in the content.ini file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6529.php" source="XF" adv="1">incredimail-dot-overwrite-files(6529)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0078.html" source="BUGTRAQ" adv="1">20010511 [eyeonsecurity.net] Incredimail allows automatic over writing offiles on your hard disk</ref>
    </refs>
    <vuln_soft>
      <prod vendor="incredimail" name="incredimail">
        <vers prev="1" num="1400185" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0643" published="2001-09-20" name="CVE-2001-0643" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Internet Explorer 5.5 does not display the Class ID (CLSID) when it is at the end of the file name, which could allow attackers to trick the user into executing dangerous programs by making it appear that the document is of a safe file type.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6426.php" source="XF" patch="1" adv="1">ie-clsid-execute-files(6426)</ref>
      <ref url="http://www.securityfocus.com/archive/1/176909" source="BUGTRAQ" patch="1" adv="1">20010416 Double clicking on innocent looking files may be dangerous</ref>
      <ref url="http://www.sarc.com/avcenter/venc/data/vbs.postcard@mm.html" source="MISC" patch="1" adv="1">http://www.sarc.com/avcenter/venc/data/vbs.postcard@mm.html</ref>
      <ref url="http://vil.nai.com/vil/virusSummary.asp?virus_k=99048" source="MISC" patch="1" adv="1">http://vil.nai.com/vil/virusSummary.asp?virus_k=99048</ref>
      <ref url="http://www.securityfocus.com/bid/2612" source="BID">2612</ref>
      <ref url="http://www.osvdb.org/7858" source="OSVDB">7858</ref>
      <ref url="http://www.guninski.com/clsidext.html" source="MISC">http://www.guninski.com/clsidext.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0644" published="2001-09-20" name="CVE-2001-0644" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Maxum Rumpus FTP Server 1.3.3 and 2.0.3 dev 3 stores passwords in plaintext in the "Rumpus User Database" file in the prefs folder, which could allow attackers to gain privileges on the server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/184751" source="BUGTRAQ" patch="1" adv="1">20010515 Rumpus FTP DoS</ref>
      <ref url="http://xforce.iss.net/static/6543.php" source="XF" adv="1">rumpus-plaintext-passwords(6543)</ref>
      <ref url="http://www.securityfocus.com/bid/2718" source="BID" adv="1">2718</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maxum_development_corporation" name="rumpus_ftp_server">
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers prev="1" num="2.0.3_dev_3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0645" published="2001-09-20" name="CVE-2001-0645" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Symantec/AXENT NetProwler 3.5.x contains several default passwords, which could allow remote attackers to (1) access to the management tier via the "admin" password, or (2) connect to a MySQL ODBC from the management tier using a blank password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/508387" source="CERT-VN">VU#508387</ref>
      <ref url="http://xforce.iss.net/static/6539.php" source="XF" patch="1" adv="1">netprowler-default-odbc-password(6539)</ref>
      <ref url="http://xforce.iss.net/static/6537.php" source="XF" patch="1" adv="1">netprowler-default-management-password(6537)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0097.html" source="BUGTRAQ" patch="1" adv="1">20010510 Corsaire Limited Security Advisory - Symantec/Axent NetProwler 3. 5.x password restrictions </ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0098.html" source="BUGTRAQ" adv="1">20010510 Corsaire Limited Security Advisory - Symantec/Axent NetProwler 3. 5.x database configuration</ref>
    </refs>
    <vuln_soft>
      <prod vendor="axent" name="netprowler">
        <vers num="3.5" />
        <vers num="3.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0646" published="2001-09-20" name="CVE-2001-0646" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Maxum Rumpus FTP Server 1.3.3 and 2.0.3 dev 3 allows a remote attacker to perform a denial of service (hang) by creating a directory name of a specific length.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6542.php" source="XF" patch="1" adv="1">rumpus-long-directory-dos(6542)</ref>
      <ref url="http://www.securityfocus.com/bid/2716" source="BID" patch="1" adv="1">2716</ref>
      <ref url="http://www.securityfocus.com/archive/1/184751" source="BUGTRAQ" patch="1" adv="1">20010515 Rumpus FTP DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maxum_development_corporation" name="rumpus_ftp_server">
        <vers num="1.3.2" />
        <vers num="1.3.4" />
        <vers num="2.0.3dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0647" published="2001-08-06" name="CVE-2001-0647" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Orange Web Server 2.1, based on GoAhead, allows a remote attacker to perform a denial of service via an HTTP GET request that does not include the HTTP version.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2432" source="BID" adv="1">2432</ref>
      <ref url="http://www.securityfocus.com/archive/1/165658" source="BUGTRAQ">20010227 Orange Web Server v2.1 DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="orange_software" name="orange_web_server">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0648" published="2001-09-20" name="CVE-2001-0648" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in PHProjekt 2.1 and earlier allows a remote attacker to conduct unauthorized activities via a dot dot (..) attack on the file module.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6522.php" source="XF" patch="1" adv="1">phprojekt-dot-directory-traversal(6522)</ref>
      <ref url="http://www.securityfocus.com/bid/2702" source="BID" patch="1" adv="1">2702</ref>
      <ref url="http://www.securityfocus.com/archive/1/184215" source="BUGTRAQ" patch="1" adv="1">20010508 security hole in os groupware suite PHProjekt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phprojekt" name="phprojekt">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0649" published="2001-09-20" name="CVE-2001-0649" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Personal Web Sharing 1.5.5 allows a remote attacker to cause a denial of service via a long HTTP request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6536.php" source="XF" adv="1">macos-web-sharing-dos(6536)</ref>
      <ref url="http://www.securityfocus.com/archive/1/184548" source="BUGTRAQ" adv="1">20010510 Personal Web Sharing remote stop</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="personal_web_sharing">
        <vers num="1.5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0650" published="2001-09-20" name="CVE-2001-0650" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco devices IOS 12.0 and earlier allow a remote attacker to cause a crash, or bad route updates, via malformed BGP updates with unrecognized transitive attribute.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/106392" source="CERT-VN" patch="1" adv="1">VU#106392</ref>
      <ref url="http://xforce.iss.net/static/6566.php" source="XF" patch="1" adv="1">cisco-ios-bgp-dos(6566)</ref>
      <ref url="http://www.cisco.com/warp/public/707/ios-bgp-attr-corruption-pub.shtml" source="CISCO" patch="1" adv="1">20010510 Cisco IOS BGP Attribute Corruption Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/2733" source="BID">2733</ref>
      <ref url="http://www.osvdb.org/1830" source="OSVDB">1830</ref>
      <ref url="http://ciac.llnl.gov/ciac/bulletins/l-082.shtml" source="CIAC">L-082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="11.2" />
        <vers num="11.3" />
        <vers prev="1" num="12.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0652" published="2001-10-30" name="CVE-2001-0652" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Heap overflow in xlock in Solaris 2.6 through 8 allows local users to gain root privileges via a long (1) XFILESEARCHPATH or (2) XUSERFILESEARCHPATH environmental variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=99745571104126&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010810 NSFOCUS SA2001-05 : Solaris Xlock Heap Overflow Vulnerability</ref>
      <ref url="http://xforce.iss.net/static/6967.php" source="XF">solaris-xlock-bo(6967)</ref>
      <ref url="http://www.securityfocus.com/bid/3160" source="BID">3160</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:131" source="OVAL" sig="1">oval:org.mitre.oval:def:131</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10" source="OVAL" sig="1">oval:org.mitre.oval:def:10</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers prev="1" num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0653" published="2001-09-20" name="CVE-2001-0653" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Sendmail 8.10.0 through 8.11.5, and 8.12.0 beta, allows local users to modify process memory and possibly gain privileges via a large value in the 'category' part of debugger (-d) command line arguments, which is interpreted as a negative number.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/3163" source="BID" patch="1" adv="1">3163</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=99841063100516&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010821 *ALERT* UPDATED BID 3163 (URGENCY 6.58): Sendmail Debugger Arbitrary Code Execution Vulnerability (fwd)</ref>
      <ref url="http://www.sendmail.org/8.11.html" source="CONFIRM">http://www.sendmail.org/8.11.html</ref>
      <ref url="http://xforce.iss.net/static/7016.php" source="XF">sendmail-debug-signed-int-overflow(7016)</ref>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBTL0112-007" source="HP">HPSBTL0112-007</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2001_028_sendmail_txt.html" source="SUSE">SuSE-SA:2001:028</ref>
      <ref url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-075.php3" source="MANDRAKE">MDKSA-2001:075</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/l-133.shtml" source="CIAC">L-133</ref>
      <ref url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-032.0.txt" source="CALDERA">CSSA-2001-032.0</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2001-106.html" source="REDHAT">RHSA-2001:106</ref>
      <ref url="http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-032-01" source="IMMUNIX">IMNX-2001-70-032-01</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000412" source="CONECTIVA">CLA-2001:412</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2001-017.txt.asc" source="NETBSD">NetBSD-SA2001-017</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sendmail" name="sendmail">
        <vers num="8.11.0" />
        <vers num="8.11.1" />
        <vers num="8.11.2" />
        <vers num="8.11.3" />
        <vers num="8.11.4" />
        <vers num="8.11.5" />
        <vers num="8.12" edition="beta10" />
        <vers num="8.12" edition="beta12" />
        <vers num="8.12" edition="beta16" />
        <vers num="8.12" edition="beta5" />
        <vers num="8.12" edition="beta7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0658" published="2001-09-20" name="CVE-2001-0658" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cross-site scripting (CSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause other clients to execute certain script or read cookies via malicious script in an invalid URL that is not properly quoted in an error message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-045.asp" source="MS" patch="1" adv="1">MS01-045</ref>
      <ref url="http://xforce.iss.net/static/6991.php" source="XF">isa-cross-site-scripting(6991)</ref>
      <ref url="http://www.securityfocus.com/bid/3198" source="BID">3198</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="isa_server">
        <vers num="2000" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0659" published="2001-09-20" name="CVE-2001-0659" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in IrDA driver providing infrared data exchange on Windows 2000 allows attackers who are physically close to the machine to cause a denial of service (reboot) via a malformed IrDA packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-046.asp" source="MS" patch="1" adv="1">MS01-046</ref>
      <ref url="http://xforce.iss.net/static/7008.php" source="XF">win2k-irda-dos(7008)</ref>
      <ref url="http://www.securityfocus.com/bid/3215" source="BID">3215</ref>
      <ref url="http://online.securityfocus.com/archive/1/209385" source="BUGTRAQ">20010821 IrDA semiremote vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0660" published="2001-10-30" name="CVE-2001-0660" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Outlook Web Access (OWA) in Microsoft Exchange 5.5, SP4 and earlier, allows remote attackers to identify valid user email addresses by directly accessing a back-end function that processes the global address list (GAL).</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms01-047.asp" source="MS" patch="1" adv="1">MS01-047</ref>
      <ref url="http://support.microsoft.com/support/kb/articles/Q307/1/95.ASP" source="MSKB" patch="1" adv="1">Q307195</ref>
      <ref url="http://xforce.iss.net/static/7089.php" source="XF">exchange-owa-obtain-addresses(7089)</ref>
      <ref url="http://www.securityfocus.com/bid/3301" source="BID">3301</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers prev="1" num="5.5" edition="sp4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0662" published="2001-10-30" name="CVE-2001-0662" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">RPC endpoint mapper in Windows NT 4.0 allows remote attackers to cause a denial of service (loss of RPC services) via a malformed request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-048.asp" source="MS">MS01-048</ref>
      <ref url="http://xforce.iss.net/static/7105.php" source="XF">winnt-rpc-endpoint-dos(7105)</ref>
      <ref url="http://www.securityfocus.com/bid/3313" source="BID">3313</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/l-142.shtml" source="CIAC">L-142</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0663" published="2001-12-06" name="CVE-2001-0663" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Terminal Server in Windows NT and Windows 2000 allows remote attackers to cause a denial of service via a sequence of invalid Remote Desktop Protocol (RDP) packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms01-052.asp" source="MS" patch="1" adv="1">MS01-052</ref>
      <ref url="http://xforce.iss.net/static/7302.php" source="XF">win-rdp-packet-dos(7302)</ref>
      <ref url="http://www.securityfocus.com/bid/3445" source="BID">3445</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0664" published="2001-10-30" name="CVE-2001-0664" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Internet Explorer 5.5 and 5.01 allows remote attackers to bypass security restrictions via malformed URLs that contain dotless IP addresses, which causes Internet Explorer to process the page in the Intranet Zone, which may have fewer security restrictions, aka the "Zone Spoofing vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-051.asp" source="MS" patch="1" adv="1">MS01-051</ref>
      <ref url="http://xforce.iss.net/static/7258.php" source="XF">ie-incorrect-security-zone(7258)</ref>
      <ref url="http://www.securityfocus.com/bid/3420" source="BID">3420</ref>
      <ref url="http://www.osvdb.org/1971" source="OSVDB">1971</ref>
      <ref url="http://morph3us.org/blog/?p=31" source="MISC">http://morph3us.org/blog/?p=31</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=100281551611595&amp;w=2" source="BUGTRAQ">20011011 Serious security Flaw in Microsoft Internet Explorer - Zone Spoofing</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" />
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0665" published="2001-10-30" name="CVE-2001-0665" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Internet Explorer 6 and earlier allows remote attackers to cause certain HTTP requests to be automatically executed and appear to come from the user, which could allow attackers to gain privileges or execute operations within web-based services, aka the "HTTP Request Encoding vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-051.asp" source="MS" patch="1" adv="1">MS01-051</ref>
      <ref url="http://xforce.iss.net/static/7259.php" source="XF">ie-url-http-requests(7259)</ref>
      <ref url="http://www.securityfocus.com/bid/3421" source="BID">3421</ref>
      <ref url="http://www.osvdb.org/1972" source="OSVDB">1972</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers prev="1" num="6" edition="windows_server_2003_sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0666" published="2001-10-30" name="CVE-2001-0666" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Outlook Web Access (OWA) in Microsoft Exchange 2000 allows an authenticated user to cause a denial of service (CPU consumption) via a malformed OWA request for a deeply nested folder within the user's mailbox.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-049.asp" source="MS" patch="1" adv="1">MS01-049</ref>
      <ref url="http://xforce.iss.net/static/7168.php" source="XF">exchange-owa-folder-request-dos(7168)</ref>
      <ref url="http://www.securityfocus.com/bid/3368" source="BID">3368</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="2000" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0667" published="2001-10-30" name="CVE-2001-0667" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Internet Explorer 6 and earlier, when used with the Telnet client in Services for Unix (SFU) 2.0, allows remote attackers to execute commands by spawning Telnet with a log file option on the command line and writing arbitrary code into an executable file which is later executed, aka a new variant of the Telnet Invocation vulnerability as described in CVE-2001-0150.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/952611" source="CERT-VN">VU#952611</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-051.asp" source="MS" patch="1" adv="1">MS01-051</ref>
      <ref url="http://xforce.iss.net/static/7260.php" source="XF">ie-telnet-command-execution-variant(7260)</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/m-024.shtml" source="CIAC">M-024</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers prev="1" num="6" edition="windows_server_2003_sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0668" published="2001-09-20" name="CVE-2001-0668" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in line printer daemon (rlpdaemon) in HP-UX 10.01 through 11.11 allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/966075" source="CERT-VN">VU#966075</ref>
      <ref url="http://www.cert.org/advisories/CA-2001-30.html" source="CERT">CA-2001-30</ref>
      <ref url="http://xforce.iss.net/alerts/advise93.php" source="ISS" patch="1" adv="1">20010827 Remote Buffer Overflow Vulnerability in HP-UX Line Printer Daemon</ref>
      <ref url="http://xforce.iss.net/static/6811.php" source="XF">hpux-rlpd-bo(6811)</ref>
      <ref url="http://www.securityfocus.com/bid/3240" source="BID">3240</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/l-134.shtml" source="CIAC">L-134</ref>
      <ref url="http://archives.neohapsis.com/archives/hp/2001-q3/0047.html" source="HP">HPSBUX0108-163</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="10.01" />
        <vers num="10.10" />
        <vers num="10.20" />
        <vers num="11.00" />
        <vers num="11.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0669" published="2001-10-30" name="CVE-2001-0669" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Various Intrusion Detection Systems (IDS) including (1) Cisco Secure Intrusion Detection System, (2) Cisco Catalyst 6000 Intrusion Detection System Module, (3) Dragon Sensor 4.x, (4) Snort before 1.8.1, (5) ISS RealSecure Network Sensor 5.x and 6.x before XPU 3.2, and (6) ISS RealSecure Server Sensor 5.5 and 6.0 for Windows, allow remote attackers to evade detection of HTTP attacks via non-standard "%u" Unicode encoding of ASCII characters in the requested URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/548515" source="CERT-VN">VU#548515</ref>
      <ref url="http://xforce.iss.net/alerts/advise95.php" source="ISS" patch="1" adv="1">20010905 Multiple Vendor IDS Unicode Bypass Vulnerability</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-intrusion-detection-obfuscation-vuln-pub.shtml" source="CISCO" patch="1" adv="1">20010905 Cisco Secure Intrusion Detection System Signature Obfuscation Vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=99972950200602&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010905 %u encoding IDS bypass vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/3292" source="BID">3292</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="catalyst_6000_intrusion_detection_system_module">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="secure_intrusion_detection_system">
        <vers num="" />
      </prod>
      <prod vendor="iss" name="realsecure_network_sensor">
        <vers num="5.x" />
        <vers num="6.x" />
      </prod>
      <prod vendor="iss" name="realsecure_server_sensor">
        <vers num="5.5" />
        <vers num="6.0" />
      </prod>
      <prod vendor="snort" name="snort">
        <vers num="1.8.1" />
      </prod>
      <prod vendor="enterasys" name="dragon">
        <vers num="4.x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0670" published="2001-10-03" name="CVE-2001-0670" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in BSD line printer daemon (in.lpd or lpd) in various BSD-based operating systems allows remote attackers to execute arbitrary code via an incomplete print job followed by a request to display the printer queue.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/274043" source="CERT-VN">VU#274043</ref>
      <ref url="http://www.cert.org/advisories/CA-2001-30.html" source="CERT">CA-2001-30</ref>
      <ref url="http://xforce.iss.net/alerts/advise94.php" source="ISS" patch="1" adv="1">20010829 Remote Buffer Overflow Vulnerability in BSD Line Printer Daemon</ref>
      <ref url="http://www.openbsd.com/errata28.html" source="OPENBSD" patch="1">20010829</ref>
      <ref url="ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.20/CSSA-2001-SCO.20.txt" source="CALDERA" patch="1">CSSA-2001-SCO.20</ref>
      <ref url="http://xforce.iss.net/static/7046.php" source="XF">bsd-lpd-bo(7046)</ref>
      <ref url="http://www.securityfocus.com/bid/3252" source="BID">3252</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-147.html" source="REDHAT">RHSA-2001:147</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2001-018.txt.asc" source="NETBSD">NetBSD-SA2001-018</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bsd" name="bsd">
        <vers prev="1" num="4.1" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers prev="1" num="4.3" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers prev="1" num="1.5.1" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0671" published="2001-12-06" name="CVE-2001-0671" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflows in (1) send_status, (2) kill_print, and (3) chk_fhost in lpd in AIX 4.3 and 5.1 allow remote attackers to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/722143" source="CERT-VN" patch="1" adv="1">VU#722143</ref>
      <ref url="http://www.kb.cert.org/vuls/id/466239" source="CERT-VN" patch="1" adv="1">VU#466239</ref>
      <ref url="http://www.kb.cert.org/vuls/id/388183" source="CERT-VN" patch="1" adv="1">VU#388183</ref>
      <ref url="http://www.cert.org/advisories/CA-2001-30.html" source="CERT" patch="1" adv="1">CA-2001-30</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="4.3" />
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0674" published="2001-09-20" name="CVE-2001-0674" modified="2009-12-19" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in RobTex Viking Web server before 1.07-381 allows remote attackers to read arbitrary files via a hexadecimal encoded dot-dot attack (eg. http://www.server.com/%2e%2e/%2e%2e) in an HTTP URL request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6394.php" source="XF" patch="1" adv="1">viking-hex-directory-traversal(6394)</ref>
      <ref url="http://www.securityfocus.com/archive/1/177231" source="BUGTRAQ" patch="1" adv="1">20010417 Advisory for Viking</ref>
      <ref url="http://www.robtex.com/viking/bugs.htm" source="CONFIRM" patch="1" adv="1">http://www.robtex.com/viking/bugs.htm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="robtex" name="viking_server">
        <vers num="1.0.4" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers prev="1" num="1.0.7_build381" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0675" published="2001-09-20" name="CVE-2001-0675" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Rit Research Labs The Bat! 1.51 for Windows allows a remote attacker to cause a denial of service by sending an email to a user's account containing a carrage return &lt;CR> that is not followed by a line feed &lt;LF>.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6423.php" source="XF" patch="1" adv="1">thebat-pop3-dos(6423)</ref>
      <ref url="http://www.securityfocus.com/bid/2636" source="BID">2636</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0410.html" source="BUGTRAQ" adv="1">20010423 Re: SECURITY.NNOV: The Bat! &lt;cr> bug </ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0381.html" source="BUGTRAQ" adv="1">20010421 Re: SECURITY.NNOV: The Bat! &lt;cr> bug</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0345.html" source="BUGTRAQ" adv="1">20010418 SECURITY.NNOV: The Bat! &lt;cr> bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ritlabs" name="the_bat">
        <vers num="1.51" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0676" published="2001-09-20" name="CVE-2001-0676" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Rit Research Labs The Bat! 1.48f and earlier allows a remote attacker to create arbitrary files via a "dot dot" attack in the filename for an attachment.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5871.php" source="XF" patch="1" adv="1">thebat-attachment-directory-traversal(5871)</ref>
      <ref url="http://www.securityfocus.com/archive/1/154359" source="BUGTRAQ" patch="1" adv="1">20010104 SECURITY.NNOV advisory - The Bat! directory traversal (public release)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ritlabs" name="the_bat">
        <vers prev="1" num="1.48f" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0677" published="2001-09-20" name="CVE-2001-0677" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Eudora 5.0.2 allows a remote attacker to read arbitrary files via an email with the path of the target file in the "Attachment Converted" MIME header, which sends the file when the email is forwarded to the attacker by the user.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6431.php" source="XF" adv="1">eudora-plain-text-attachment(6431)</ref>
      <ref url="http://www.securityfocus.com/archive/1/177369" source="BUGTRAQ" adv="1">20010418 Eudora file leakage problem (still)</ref>
      <ref url="http://www.securityfocus.com/bid/2616" source="BID">2616</ref>
      <ref url="http://www.osvdb.org/3085" source="OSVDB">3085</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qualcomm" name="eudora">
        <vers num="5.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0678" published="2001-09-20" name="CVE-2001-0678" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">A buffer overflow in reggo.dll file used by Trend Micro InterScan VirusWall prior to 3.51 build 1349 for Windows NT 3.5 and InterScan WebManager 1.2 allows a local attacker to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6575.php" source="XF" patch="1" adv="1">interscan-reggo-bo(6575)</ref>
      <ref url="http://www.securityfocus.com/archive/1/185383" source="BUGTRAQ" adv="1">20010519 TrendMicro Interscan VirusWall RegGo.dll BOf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="interscan_viruswall">
        <vers num="3.51" />
      </prod>
      <prod vendor="trend_micro" name="interscan_webmanager">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0679" published="1999-11-08" name="CVE-2001-0679" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">A buffer overflow in InterScan VirusWall 3.23 and 3.3 allows a remote attacker to execute arbitrary code by sending a long HELO command to the server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/3465.php" source="XF" patch="1" adv="1">viruswall-helo-bo(3465)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94216491202063&amp;w=2" source="NTBUGTRAQ" patch="1">19991109 InterScan VirusWall 3.23/3.3 Buffer Overflow</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94208143007829&amp;w=2" source="NTBUGTRAQ" patch="1" adv="1">19991108 Patch for VirusWall 3.23.</ref>
      <ref url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind9911&amp;L=NTBUGTRAQ&amp;P=R2331" source="NTBUGTRAQ" adv="1">19991108 Interscan VirusWall NT 3.23/3.3 buffer overflow.</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94204166130782&amp;w=2" source="BUGTRAQ">19991108 Patch for VirusWall 3.23.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="interscan_viruswall">
        <vers num="3.23" />
        <vers num="3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0680" published="2001-09-20" name="CVE-2001-0680" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in ftpd in QPC QVT/Net 4.0 and AVT/Term 5.0 allows a remote attacker to traverse directories on the web server via a "dot dot" attack in a LIST (ls) command.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6375.php" source="XF" adv="1">qpc-ftpd-directory-traversal(6375)</ref>
      <ref url="http://www.securityfocus.com/archive/1/176712" source="BUGTRAQ" adv="1">20010413 QPC FTPd Directory Traversal and BoF Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/bid/2618" source="BID">2618</ref>
      <ref url="http://www.osvdb.org/4050" source="OSVDB">4050</ref>
      <ref url="http://www.osvdb.org/1794" source="OSVDB">1794</ref>
      <ref url="http://online.securityfocus.com/archive/1/216555" source="BUGTRAQ">20010925 Vulnerabilities in QVT/Term</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qpc_software" name="avt_term">
        <vers num="5.0" />
      </prod>
      <prod vendor="qpc_software" name="qvt_net">
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0681" published="2001-09-20" name="CVE-2001-0681" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in ftpd in QPC QVT/Net 5.0 and QVT/Term 5.0 allows a remote attacker to cause a denial of service via a long (1) username or (2) password.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6376.php" source="XF" adv="1">qpc-ftpd-bo(6376)</ref>
      <ref url="http://www.securityfocus.com/archive/1/176712" source="BUGTRAQ" adv="1">20010413 QPC FTPd Directory Traversal and BoF Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qpc_software" name="qvt_net">
        <vers num="5.0" />
      </prod>
      <prod vendor="qpc_software" name="qvt_term">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0682" published="2001-08-29" name="CVE-2001-0682" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">ZoneAlarm and ZoneAlarm Pro allows a local attacker to cause a denial of service by running a trojan to initialize a ZoneAlarm mutex object which prevents ZoneAlarm from starting.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/5821.php" source="XF" patch="1" adv="1">zonealarm-mutex-dos(5821)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=97818917222992&amp;w=2" source="NTBUGTRAQ" adv="1">20001230 [DiamondCS Advisory] ZoneAlarm and ZoneAlarm Pro can be blocked from loading by setting a Mutex in memory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zonelabs" name="zonealarm">
        <vers num="7.0.302.000" edition="" />
        <vers num="7.0.302.000" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0683" published="2001-09-20" name="CVE-2001-0683" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Memory leak in Netscape Collabra Server 3.5.4 and earlier allows a remote attacker to cause a denial of service (memory exhaustion) by repeatedly sending approximately 5K of data to TCP port 5238.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6158.php" source="XF" patch="1" adv="1">netscape-collabra-kernel-dos(6158)</ref>
      <ref url="http://www.securityfocus.com/archive/1/165516" source="BUGTRAQ" patch="1" adv="1">20010226 def-2001-08: Netscape Collabra DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="collabra_server">
        <vers prev="1" num="3.5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0684" published="2001-09-20" name="CVE-2001-0684" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Netscape Collabra Server 3.5.4 and earlier allows a remote attacker to cause a denial of service by sending seven or more characters to TCP port 5239.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/165516" source="BUGTRAQ" patch="1" adv="1">20010226 def-2001-08: Netscape Collabra DoS</ref>
      <ref url="http://xforce.iss.net/static/6159.php" source="XF">netscape-collabra-cpu-dos(6159)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netscape" name="collabra_server">
        <vers prev="1" num="3.5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0685" published="2001-09-20" name="CVE-2001-0685" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:P)" CVSS_score="2.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="1.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Thibault Godouet FCron prior to 1.1.1 allows a local user to corrupt another user's crontab file via a symlink attack on the fcrontab temporary file.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2835" source="BID" patch="1" adv="1">2835</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98339581702282&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010228 fcron 0.9.5 is vulnerable to a symlink attack</ref>
      <ref url="http://fcron.free.fr/CHANGES.html" source="CONFIRM">http://fcron.free.fr/CHANGES.html</ref>
      <ref url="http://xforce.iss.net/static/7127.php" source="XF">fcron-tmpfile-symlink(7127)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thibault_godouet" name="fcron">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0686" published="2001-09-20" name="CVE-2001-0686" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in mail included with SunOS 5.8 for x86 allows a local user to gain privileges via a long HOME environment variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-06/0000.html" source="BUGTRAQ" patch="1" adv="1">20010604 $HOME buffer overflow in SunOS 5.8 x86</ref>
      <ref url="http://www.securityfocus.com/bid/2819" source="BID" adv="1">2819</ref>
      <ref url="http://xforce.iss.net/static/6638.php" source="XF">solaris-mail-home-bo(6638)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="5.8" edition="" />
        <vers num="5.8" edition=":x86" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0687" published="2001-09-20" name="CVE-2001-0687" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Broker FTP server 5.9.5 for Windows NT and 9x allows a remote attacker to retrieve privileged web server system information by (1) issuing a CD command (CD C:) followed by the LS command, (2) specifying arbitrary paths in the UNC format (\\computername\sharename).</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6674.php" source="XF" adv="1">broker-ftp-cd-directory-traversal(6674)</ref>
      <ref url="http://www.securityfocus.com/bid/2853" source="BID" adv="1">2853</ref>
      <ref url="http://www.securityfocus.com/archive/1/190032" source="BUGTRAQ" adv="1">20010610 Broker FTP Server 5.9.5.0 Buffer Overflow / DoS / Directory Traversal</ref>
    </refs>
    <vuln_soft>
      <prod vendor="transsoft" name="broker_ftp_server">
        <vers num="4.0" />
        <vers num="4.7.5.0" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers prev="1" num="5.9.5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0688" published="2001-09-20" name="CVE-2001-0688" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Broker FTP Server 5.9.5.0 allows a remote attacker to cause a denial of service by repeatedly issuing an invalid CD or CWD ("CD . .") command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2851" source="BID" adv="1">2851</ref>
      <ref url="http://www.securityfocus.com/archive/1/190032" source="BUGTRAQ" adv="1">20010610 Broker FTP Server 5.9.5.0 Buffer Overflow / DoS / Directory Traversal</ref>
    </refs>
    <vuln_soft>
      <prod vendor="transsoft" name="broker_ftp_server">
        <vers num="3.0_build_1" />
        <vers num="4.0" />
        <vers num="4.7.5.0" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.7" />
        <vers num="5.9.5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0689" published="2001-09-20" name="CVE-2001-0689" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Vulnerability in TrendMicro Virus Control System 1.8 allows a remote attacker to view configuration files and change the configuration via a certain CGI program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-06/0065.html" source="BUGTRAQ" adv="1">20010607 [SNS Advisory No.29] Trend Micro Virus Control System(VCS)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="virus_control_system">
        <vers num="1.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0690" published="2001-09-20" name="CVE-2001-0690" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in exim (3.22-10 in Red Hat, 3.12 in Debian and 3.16 in Conectiva) in batched SMTP mode allows a remote attacker to execute arbitrary code via format strings in SMTP mail headers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-078.html" source="REDHAT" patch="1" adv="1">RHSA-2001:078</ref>
      <ref url="http://www.debian.org/security/2001/dsa-058" source="DEBIAN" patch="1" adv="1">DSA-058</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2001-06/0041.html" source="BUGTRAQ" adv="1">20010606 lil' exim format bug</ref>
      <ref url="http://xforce.iss.net/static/6671.php" source="XF">exim-syntax-format-string(6671)</ref>
      <ref url="http://www.securityfocus.com/bid/2828" source="BID">2828</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000402" source="CONECTIVA">CLA-2001:402</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_cambridge" name="exim">
        <vers prev="1" num="3.22" />
      </prod>
      <prod vendor="conectiva" name="linux">
        <vers num="" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="4.0" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0691" published="2001-09-20" name="CVE-2001-0691" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflows in Washington University imapd 2000a through 2000c could allow local users without shell access to execute code as themselves in certain configurations.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2856" source="BID" patch="1" adv="1">2856</ref>
      <ref url="http://www.securityfocus.com/advisories/3352" source="MANDRAKE" patch="1" adv="1">MDKSA-2001:054</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-094.html" source="REDHAT">RHSA-2001:094</ref>
      <ref url="http://www.iss.net/security_center/static/6269.php" source="XF">imap-ipop2d-ipop3d-bo(6269)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="university_of_washington" name="imapd">
        <vers num="2000" />
        <vers num="2000c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0692" published="2001-09-20" name="CVE-2001-0692" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SMTP proxy in WatchGuard Firebox (2500 and 4500) 4.5 and 4.6 allows a remote attacker to bypass firewall filtering via a base64 MIME encoded email attachment whose boundary name ends in two dashes.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2855" source="BID" patch="1" adv="1">2855</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=99379787421319&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20010628 RE: WatchGuard SMTP Proxy issue</ref>
      <ref url="http://xforce.iss.net/static/6682.php" source="XF" adv="1">firebox-smtp-bypass-filter(6682)</ref>
      <ref url="http://www.securityfocus.com/archive/1/189783" source="BUGTRAQ" adv="1">20010608 WatchGuard SMTP Proxy issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="watchguard" name="firebox_2500">
        <vers num="4.5" />
        <vers num="4.6" />
      </prod>
      <prod vendor="watchguard" name="firebox_4500">
        <vers num="4.5" />
        <vers num="4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0693" published="2001-09-20" name="CVE-2001-0693" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WebTrends HTTP Server 3.1c and 3.5 allows a remote attacker to view script source code via a filename followed by an encoded space (%20).</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6639.php" source="XF" adv="1">webtrends-unicode-reveal-source(6639)</ref>
      <ref url="http://www.securityfocus.com/bid/2812" source="BID" adv="1">2812</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=99166905208903&amp;w=2" source="BUGTRAQ" adv="1">20010603 Webtrends HTTP Server %20 bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webtrends" name="webtrends_enterprise_reporting_server">
        <vers num="3.1c" />
      </prod>
      <prod vendor="webtrends" name="webtrends_enterprise_reporting_server_nt">
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0694" published="2001-09-20" name="CVE-2001-0694" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in WFTPD 3.00 R5 allows a remote attacker to view arbitrary files via a dot dot attack in the CD command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/vuln-dev/2001-q2/0454.html" source="VULN-DEV" patch="1" adv="1">20010525 WFTPD 32-bit (X86) 3.00 R5 Directory Traversal / Buffer Overflow / DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="texas_imperial_software" name="wftpd">
        <vers num="3.00_r5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0695" published="2001-09-20" name="CVE-2001-0695" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WFTPD 3.00 R5 allows a remote attacker to cause a denial of service by making repeated requests to cd to the floppy drive (A:\).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6496.php" source="XF" patch="1" adv="1">wftpd-cd-dos(6496)</ref>
      <ref url="http://www.securityfocus.com/archive/1/182054" source="BUGTRAQ" patch="1" adv="1">20010503 Potential DOS Vulnerability in WFTPD</ref>
    </refs>
    <vuln_soft>
      <prod vendor="texas_imperial_software" name="wftpd">
        <vers num="3.00_r5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0696" published="2001-09-20" name="CVE-2001-0696" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to cause a denial of service (crash) via a CD command to a directory with an MS-DOS device name such as con.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6712.php" source="XF" patch="1" adv="1">surgeftp-concon-dos(6712)</ref>
      <ref url="http://www.securityfocus.com/bid/2891" source="BID" patch="1" adv="1">2891</ref>
      <ref url="http://www.securityfocus.com/archive/1/191916" source="BUGTRAQ" patch="1" adv="1">20010619 SurgeFTP vulnerabilities</ref>
      <ref url="http://netwinsite.com/surgeftp/manual/updates.htm" source="MISC">http://netwinsite.com/surgeftp/manual/updates.htm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netwin" name="surgeftp">
        <vers num="1.0b" />
        <vers num="2.0a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0697" published="2001-09-20" name="CVE-2001-0697" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">NetWin SurgeFTP prior to 1.1h allows a remote attacker to cause a denial of service (crash) via an 'ls ..' command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6168.php" source="XF" patch="1" adv="1">surgeftp-listing-dos(6168)</ref>
      <ref url="http://www.securityfocus.com/archive/1/165816" source="BUGTRAQ" patch="1" adv="1">20010228 SurgeFTP Denial of Service</ref>
      <ref url="http://www.secadministrator.com/Articles/Index.cfm?ArticleID=20200" source="WIN2KSEC" patch="1" adv="1">20010301 SurgeFTP 1.0b Denial of Service</ref>
      <ref url="http://netwinsite.com/surgeftp/manual/updates.htm" source="CONFIRM">http://netwinsite.com/surgeftp/manual/updates.htm</ref>
      <ref url="http://www.securityfocus.com/bid/2442" source="BID">2442</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netwin" name="surgeftp">
        <vers prev="1" num="1.1h" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0698" published="2001-09-20" name="CVE-2001-0698" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to list arbitrary files and directories via the 'nlist ...' command.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6711.php" source="XF" patch="1" adv="1">surgeftp-nlist-directory-traversal(6711)</ref>
      <ref url="http://www.securityfocus.com/bid/2892" source="BID" patch="1" adv="1">2892</ref>
      <ref url="http://www.securityfocus.com/archive/1/191916" source="BUGTRAQ" patch="1" adv="1">20010619 SurgeFTP vulnerabilities</ref>
      <ref url="http://www.netwinsite.com/surgeftp/manual/updates.htm" source="CONFIRM">http://www.netwinsite.com/surgeftp/manual/updates.htm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netwin" name="surgeftp">
        <vers num="1.0b" />
        <vers num="2.0a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0699" published="2001-09-20" name="CVE-2001-0699" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in cb_reset in the System Service Processor (SSP) package of SunOS 5.8 allows a local user to execute arbitrary code via a long argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6726.php" source="XF" adv="1">sun-cbreset-bo(6726)</ref>
      <ref url="http://www.securityfocus.com/bid/2893" source="BID" adv="1">2893</ref>
      <ref url="http://www.securityfocus.com/archive/1/192299" source="BUGTRAQ" adv="1">20010620 Solaris /opt/SUNWssp/bin/cb_reset Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="5.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0700" published="2001-09-20" name="CVE-2001-0700" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in w3m 0.2.1 and earlier allows a remote attacker to execute arbitrary code via a long base64 encoded MIME header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6725.php" source="XF" patch="1" adv="1">w3m-mime-header-bo(6725)</ref>
      <ref url="http://www.securityfocus.com/bid/2895" source="BID" patch="1" adv="1">2895</ref>
      <ref url="http://mi.med.tohoku.ac.jp/~satodai/w3m-dev-en/200106.month/537.html" source="CONFIRM" patch="1" adv="1">http://mi.med.tohoku.ac.jp/~satodai/w3m-dev-en/200106.month/537.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/192371" source="BUGTRAQ">20010621 [SNS Advisory No.32] w3m malformed MIME header Buffer Overflow Vulnerability</ref>
      <ref url="http://www.debian.org/security/2001/dsa-081" source="DEBIAN">DSA-081</ref>
      <ref url="http://www.debian.org/security/2001/dsa-064" source="DEBIAN">DSA-064</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000434" source="CONECTIVA">CLA-2001:434</ref>
    </refs>
    <vuln_soft>
      <prod vendor="w3m" name="w3m">
        <vers num="0.1.10" />
        <vers num="0.1.3" />
        <vers num="0.1.4" />
        <vers num="0.1.6" />
        <vers num="0.1.7" />
        <vers num="0.1.8" />
        <vers num="0.1.9" />
        <vers num="0.2" />
        <vers prev="1" num="0.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0701" published="2001-09-20" name="CVE-2001-0701" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in ptexec in the Sun Validation Test Suite 4.3 and earlier allows a local user to gain privileges via a long -o argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6736.php" source="XF" patch="1" adv="1">sunvts-ptexec-bo(6736)</ref>
      <ref url="http://www.securityfocus.com/bid/2898" source="BID" patch="1" adv="1">2898</ref>
      <ref url="http://www.securityfocus.com/archive/1/192667" source="BUGTRAQ" adv="1">20010621 Solaris /opt/SUNWvts/bin/ptexec Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunvts">
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0702" published="2001-09-20" name="CVE-2001-0702" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cerberus FTP 1.5 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long (1) username, (2) password, or (3) PASV command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6728.php" source="XF" adv="1">cerberus-ftp-bo(6728)</ref>
      <ref url="http://www.securityfocus.com/bid/2901" source="BID" adv="1">2901</ref>
      <ref url="http://www.securityfocus.com/archive/1/192655" source="BUGTRAQ" adv="1">20010621 Cerberus FTP Server 1.x Remote DoS attack Vulnerability</ref>
      <ref url="http://archive.cert.uni-stuttgart.de/archive/bugtraq/2001/07/msg00070.html" source="BUGTRAQ">20010704 CesarFTPd, Cerberus FTPd</ref>
    </refs>
    <vuln_soft>
      <prod vendor="grant_averett" name="ceberus_ftp_server">
        <vers num="1.0" />
        <vers num="1.01" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.22" />
        <vers num="1.3" />
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0703" published="2001-09-20" name="CVE-2001-0703" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to cause a denial of service via a URL request with an MS-DOS device name in the template parameter.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2905" source="BID" patch="1" adv="1">2905</ref>
      <ref url="http://xforce.iss.net/static/6739.php" source="XF" adv="1">arcadia-tradecli-dos(6739)</ref>
      <ref url="http://www.securityfocus.com/archive/1/192651" source="BUGTRAQ" adv="1">20010621 NERF Advisory #2 - 1C:Arcadia multiple vulnerablilities.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="arcadia" name="arcadia_internet_store">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0704" published="2001-09-20" name="CVE-2001-0704" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to discover the full path to the working directory via a URL with a template argument for a file that does not exist.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2904" source="BID" patch="1" adv="1">2904</ref>
      <ref url="http://xforce.iss.net/static/6738.php" source="XF" adv="1">arcadia-tradecli-reveal-path(6738)</ref>
      <ref url="http://www.securityfocus.com/archive/1/192651" source="BUGTRAQ" adv="1">20010621 NERF Advisory #2 - 1C:Arcadia multiple vulnerablilities.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="arcadia" name="arcadia_internet_store">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0705" published="2001-09-20" name="CVE-2001-0705" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to read arbitrary files on the web server via a URL with "dot dot" sequences in the template argument.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/2902" source="BID" patch="1" adv="1">2902</ref>
      <ref url="http://xforce.iss.net/static/6737.php" source="XF" adv="1">arcadia-tradecli-directory-traversal(6737)</ref>
      <ref url="http://www.securityfocus.com/archive/1/192651" source="BUGTRAQ" adv="1">20010621 NERF Advisory #2 - 1C:Arcadia multiple vulnerablilities.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="arcadia" name="arcadia_internet_store">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0706" published="2001-09-20" name="CVE-2001-0706" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Maximum Rumpus FTP Server 2.0.3 dev and before allows an attacker to cause a denial of service (crash) via a mkdir command that specifies a large number of sub-folders.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6699.php" source="XF" patch="1" adv="1">rumpus-ftp-directory-dos(6699)</ref>
      <ref url="http://www.securityfocus.com/bid/2864" source="BID" patch="1" adv="1">2864</ref>
      <ref url="http://www.securityfocus.com/archive/1/190932" source="BUGTRAQ" adv="1">20010612 Rumpus FTP DoS vol. 2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maxum_development_corporation" name="rumpus_ftp_server">
        <vers num="1.3.2" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="2.0.3dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0707" published="2001-09-20" name="CVE-2001-0707" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denicomp RSHD 2.18 and earlier allows a remote attacker to cause a denial of service (crash) via a long string to port 514.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6523.php" source="XF" adv="1">denicomp-rshd-dos(6523)</ref>
      <ref url="http://www.securityfocus.com/archive/1/183911" source="BUGTRAQ" adv="1">20010503 Denicomp REXECD/RSHD Denial of Service Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="denicomp" name="rshd">
        <vers prev="1" num="2.18" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0708" published="2001-09-20" name="CVE-2001-0708" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Denicomp REXECD 1.05 and earlier allows a remote attacker to cause a denial of service (crash) via a long string.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6524.php" source="XF" adv="1">denicomp-rexecd-dos(6524)</ref>
      <ref url="http://www.securityfocus.com/archive/1/183911" source="BUGTRAQ" adv="1">20010503 Denicomp REXECD/RSHD Denial of Service Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="denicomp" name="rexecd">
        <vers prev="1" num="1.05" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0709" published="2001-09-20" name="CVE-2001-0709" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft IIS 4.0 and before, when installed on a FAT partition, allows a remote attacker to obtain source code of ASP files via a URL encoded with Unicode.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6742.php" source="XF" patch="1" adv="1">iis-unicode-asp-disclosure(6742)</ref>
      <ref url="http://www.securityfocus.com/bid/2909" source="BID" patch="1" adv="1">2909</ref>
      <ref url="http://www.securityfocus.com/archive/1/192802" source="BUGTRAQ" patch="1" adv="1">20010622 [VIGILANTE-2001001] ASP source code retrieved with Unicode extens ion</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers prev="1" num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0710" published="2001-09-20" name="CVE-2001-0710" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">NetBSD 1.5 and earlier and FreeBSD 4.3 and earlier allows a remote attacker to cause a denial of service by sending a large number of IP fragments to the machine, exhausting the mbuf pool.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6636.php" source="XF" patch="1" adv="1">bsd-ip-fragments-dos(6636)</ref>
      <ref url="http://www.securityfocus.com/bid/2799" source="BID" patch="1" adv="1">2799</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2001-006.txt.asc" source="NETBSD" patch="1" adv="1">NetBSD-SA2001-006</ref>
      <ref url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:52.fragment.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-01:52</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers prev="1" num="4.3" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers prev="1" num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0711" published="2001-08-31" name="CVE-2001-0711" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco IOS 11.x and 12.0 with ATM support allows attackers to cause a denial of service via the undocumented Interim Local Management Interface (ILMI) SNMP community string.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/ios-snmp-ilmi-vuln-pub.shtml" source="CISCO" patch="1" adv="1">20010207 Cisco IOS Software SNMP Read-Write ILMI Community String Vulnerability</ref>
      <ref url="http://xforce.iss.net/static/6169.php" source="XF">cisco-ios-modify-snmp(6169)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="11" />
        <vers num="12.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0712" published="2001-10-30" name="CVE-2001-0712" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The rendering engine in Internet Explorer determines the MIME type independently of the type that is specified by the server, which allows remote servers to automatically execute script which is placed in a file whose MIME type does not normally support scripting, such as text (.txt), JPEG (.jpg), etc.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/200291" source="BUGTRAQ" patch="1" adv="1">20010729 Re: TXT or HTML? -- IE NEW BUG</ref>
      <ref url="http://www.securityfocus.com/archive/1/200109" source="BUGTRAQ" patch="1" adv="1">20010727 TXT or HTML? -- IE NEW BUG</ref>
      <ref url="http://www.securityfocus.com/bid/3116" source="BID" adv="1">3116</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0713" published="2001-10-30" name="CVE-2001-0713" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Sendmail before 8.12.1 does not properly drop privileges when the -C option is used to load custom configuration files, which allows local users to gain privileges via malformed arguments in the configuration file whose names contain characters with the high bit set, such as (1) macro names that are one character long, (2) a variable setting which is processed by the setoption function, or (3) a Modifiers setting which is processed by the getmodifiers function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://razor.bindview.com/publish/advisories/adv_sm812.html" source="BINDVIEW" adv="1">20011001 Multiple Local Sendmail Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/bid/3377" source="BID">3377</ref>
      <ref url="http://www.iss.net/security_center/static/7192.php" source="XF">sendmail-setregid-gain-privileges(7192)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sendmail" name="sendmail">
        <vers prev="1" num="8.12.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0714" published="2001-10-30" name="CVE-2001-0714" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Sendmail before 8.12.1, without the RestrictQueueRun option enabled, allows local users to cause a denial of service (data loss) by (1) setting a high initial message hop count option (-h), which causes Sendmail to drop queue entries, (2) via the -qR option, or (3) via the -qS option.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://razor.bindview.com/publish/advisories/adv_sm812.html" source="BINDVIEW" patch="1" adv="1">20011001 Multiple Local Sendmail Vulnerabilities</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20011101-01-I" source="SGI">20011101-01-I</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sendmail" name="sendmail">
        <vers prev="1" num="8.12.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2001-0715" published="2001-10-30" name="CVE-2001-0715" modified="2011-03-07" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Sendmail before 8.12.1, without the RestrictQueueRun option enabled, allows local users to obtain potentially sensitive information about the mail queue by setting debugging flags to enable debug mode.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://razor.bindview.com/publish/advisories/adv_sm812.html" source="BINDVIEW" patch="1" adv="1">20011001 Multiple Local Sendmail Vulnerabilities</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20011101-01-I" source="SGI">20011101-01-I</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sendmail" name="sendmail">
        <vers prev="1" num="8.12.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0716" published="2001-12-06" name="CVE-2001-0716" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Citrix MetaFrame 1.8 Server with Service Pack 3, and XP Server Service Pack 1 and earlier, allows remote attackers to cause a denial of service (crash) via a large number of incomplete connections to the server.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/alerts/advise99.php" source="ISS" patch="1" adv="1">20011016 Citrix MetaFrame Remote Denial of Service Vulnerability</ref>
      <ref url="http://xforce.iss.net/static/7068.php" source="XF">metaframe-multiple-sessions-dos(7068)</ref>
      <ref url="http://www.securityfocus.com/bid/3440" source="BID">3440</ref>
    </refs>
    <vuln_soft>
      <prod vendor="citrix" name="metaframe">
        <vers num="1.8" edition="sp3" />
        <vers num="xp_server" />
        <vers prev="1" num="xp_server_service_pack_1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0717" published="2001-10-30" name="CVE-2001-0717" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in ToolTalk database server rpc.ttdbserverd allows remote attackers to execute arbitrary commands via format string specifiers that are passed to the syslog function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2001-27.html" source="CERT">CA-2001-27</ref>
      <ref url="http://xforce.iss.net/alerts/advise98.php" source="ISS" patch="1" adv="1">20011002 Multi-Vendor Format String Vulnerability in ToolTalk Service</ref>
      <ref url="http://xforce.iss.net/static/7069.php" source="XF">tooltalk-ttdbserverd-format-string(7069)</ref>
      <ref url="http://www.securityfocus.com/bid/3382" source="BID">3382</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/m-002.shtml" source="CIAC">M-002</ref>
      <ref url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/212" source="SUN">00212</ref>
      <ref url="http://securitytracker.com/id?1002479" source="SECTRACK">1002479</ref>
      <ref url="http://online.securityfocus.com/advisories/3584" source="HP">HPSBUX0110-168</ref>
      <ref url="http://ftp.support.compaq.com/patches/.new/html/SSRT0767U.shtml" source="COMPAQ">SSRT0767U</ref>
      <ref url="ftp://stage.caldera.com/pub/security/openunix/CSSA-2001-SCO.28/CSSA-2001-SCO.28.txt" source="CALDERA">CSSA-2001-SCO.28</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tooltalk" name="tooltalk_database_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0718" published="2001-10-30" name="CVE-2001-0718" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Vulnerability in (1) Microsoft Excel 2002 and earlier and (2) Microsoft PowerPoint 2002 and earlier allows attackers to bypass macro restrictions and execute arbitrary commands by modifying the data stream in the document.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2001-28.html" source="CERT" patch="1" adv="1">CA-2001-28</ref>
      <ref url="http://www.kb.cert.org/vuls/id/287067" source="CERT-VN">VU#287067</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms01-050.asp" source="MS" patch="1" adv="1">MS01-050</ref>
      <ref url="http://xforce.iss.net/static/7223.php" source="XF">ms-malformed-document-macro(7223)</ref>
      <ref url="http://www.securityfocus.com/bid/3402" source="BID">3402</ref>
      <ref url="http://online.securityfocus.com/archive/1/218802" source="BUGTRAQ">20011005 Symantec Security Response SecBul-10042001, Revision1, Malformed Microsoft Excel or PowerPoint documents bypass Microsoft macro security features</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers prev="1" num="2002" />
      </prod>
      <prod vendor="microsoft" name="powerpoint">
        <vers prev="1" num="2002" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0719" published="2001-12-06" name="CVE-2001-0719" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Windows Media Player 6.4 allows remote attackers to execute arbitrary code via a malformed Advanced Streaming Format (ASF) file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-056.asp" source="MS" patch="1" adv="1">MS01-056</ref>
      <ref url="http://www.securityfocus.com/bid/3156" source="BID">3156</ref>
      <ref url="http://www.osvdb.org/5558" source="OSVDB">5558</ref>
      <ref url="http://www.iss.net/security_center/static/6962.php" source="XF">mediaplayer-asf-marker-bo(6962)</ref>
      <ref url="http://online.securityfocus.com/archive/1/202470" source="BUGTRAQ">20010807 MS Windows Media Player ASF Marker Buffer Overflow</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:287" source="OVAL" sig="1">oval:org.mitre.oval:def:287</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_media_player">
        <vers num="6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0720" published="2001-12-06" name="CVE-2001-0720" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Internet Explorer 5.1 for Macintosh on Mac OS X allows remote attackers to execute arbitrary commands by causing a BinHex or MacBinary file type to be downloaded, which causes the files to be executed if automatic decoding is enabled.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-053.asp" source="MS" patch="1" adv="1">MS01-053</ref>
      <ref url="http://xforce.iss.net/static/7336.php" source="XF">ie-mac-downloaded-file-execution(7336)</ref>
      <ref url="http://www.securityfocus.com/bid/3471" source="BID">3471</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/m-013.shtml" source="CIAC">M-013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0721" published="2001-12-06" name="CVE-2001-0721" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Universal Plug and Play (UPnP) in Windows 98, 98SE, ME, and XP allows remote attackers to cause a denial of service (memory consumption or crash) via a malformed UPnP request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-054.asp" source="MS" patch="1" adv="1">MS01-054</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=100528449024158&amp;w=2" source="BUGTRAQ" adv="1">20011109 Important Information Regarding MS01-054 and WindowsME</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=100467787323377&amp;w=2" source="BUGTRAQ" adv="1">20011101 Three Windows XP UPNP DOS attacks</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0722" published="2001-12-06" name="CVE-2001-0722" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript in an about: URL, aka the "First Cookie Handling Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/221612" source="BUGTRAQ" patch="1" adv="1">20011019 Minor IE vulnerability: about: URLs</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-055.asp" source="MS" patch="1" adv="1">MS01-055</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=100527618108521&amp;w=2" source="BUGTRAQ" adv="1">20011108 Microsoft IE cookies readable via about: URLS</ref>
      <ref url="http://xforce.iss.net/static/7486.php" source="XF">ie-about-cookie-information(7486)</ref>
      <ref url="http://www.securityfocus.com/bid/3513" source="BID">3513</ref>
      <ref url="http://www.osvdb.org/1982" source="OSVDB">1982</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/m-016.shtml" source="CIAC">M-016</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.5" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0723" published="2001-11-14" name="CVE-2001-0723" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript, aka the "Second Cookie Handling Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/3546" source="BID" patch="1" adv="1">3546</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-055.asp" source="MS" patch="1" adv="1">MS01-055</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.5" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0724" published="2001-11-14" name="CVE-2001-0724" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Internet Explorer 5.5 allows remote attackers to bypass security restrictions via malformed URLs that contain dotless IP addresses, which causes Internet Explorer to process the page in the Intranet Zone, which may have fewer security restrictions, aka the "Zone Spoofing Vulnerability variant" of CVE-2001-0664.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-055.asp" source="MS" patch="1" adv="1">MS01-055</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/8471" source="XF">ie-incorrect-security-zone-variant(8471)</ref>
      <ref url="http://www.osvdb.org/5556" source="OSVDB">5556</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0726" published="2001-12-06" name="CVE-2001-0726" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Outlook Web Access (OWA) in Microsoft Exchange 5.5 Server, when used with Internet Explorer, does not properly detect certain inline script, which can allow remote attackers to perform arbitrary actions on a user's Exchange mailbox via an HTML e-mail message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/MS01-057.asp" source="MS" patch="1" adv="1">MS01-057</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/7663" source="XF">exchange-owa-embedded-script-execution(7663)</ref>
      <ref url="http://www.securityfocus.com/bid/3650" source="BID">3650</ref>
      <ref url="http://www.osvdb.org/5557" source="OSVDB">5557</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0727" published="2001-12-14" name="CVE-2001-0727" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Internet Explorer 6.0 allows remote attackers to execute arbitrary code by modifying the Content-Disposition and Content-Type header fields in a way that causes Internet Explorer to believe that the file is safe to open without prompting the user, aka the "File Execution Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cert.org/advisories/CA-2001-36.html" source="CERT" patch="1" adv="1">CA-2001-36</ref>
      <ref url="http://www.kb.cert.org/vuls/id/443699" source="CERT-VN">VU#443699</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms01-058.asp" source="MS" patch="1" adv="1">MS01-058</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=100835204509262&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20011214 MSIE may download and run progams automatically</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=100861273114437&amp;w=2" source="BUGTRAQ" adv="1">20011216 Re: MSIE may download and run progams automatically - NOT SO FAST</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/7703" source="XF">ie-file-download-execution(7703)</ref>
      <ref url="http://www.securityfocus.com/bid/3578" source="BID">3578</ref>
      <ref url="http://www.osvdb.org/3033" source="OSVDB">3033</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/m-027.shtml" source="CIAC">M-027</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:921" source="OVAL" sig="1">oval:org.mitre.oval:def:921</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.5" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0728" published="2001-10-30" name="CVE-2001-0728" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in Compaq Management Agents before 5.2, included in Compaq Web-enabled Management Software, allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/275979" source="CERT-VN">VU#275979</ref>
      <ref url="http://www.compaq.com/products/servers/management/mgtsw-advisory2.html" source="COMPAQ" patch="1" adv="1">SSRT0758</ref>
      <ref url="http://xforce.iss.net/static/7189.php" source="XF">compaq-wbm-bo(7189)</ref>
      <ref url="http://www.securityfocus.com/bid/3376" source="BID">3376</ref>
    </refs>
    <vuln_soft>
      <prod vendor="compaq" name="management_agents">
        <vers prev="1" num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0729" published="2001-10-30" name="CVE-2001-0729" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apache 1.3.20 on Windows servers allows remote attackers to bypass the default index page and list directory contents via a URL with a large number of / (slash) characters.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.apacheweek.com/issues/01-09-28#security" source="CONFIRM">http://www.apacheweek.com/issues/01-09-28#security</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA">23794</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="1.3.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0730" published="2001-10-30" name="CVE-2001-0730" modified="2008-09-10" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">split-logfile in Apache 1.3.20 allows remote attackers to overwrite arbitrary files that end in the .log extension via an HTTP request with a / (slash) in the Host: header.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.apacheweek.com/issues/01-09-28#security" source="CONFIRM">http://www.apacheweek.com/issues/01-09-28#security</ref>
      <ref url="http://xforce.iss.net/static/7419.php" source="XF">apache-log-file-overwrite(7419)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-164.html" source="REDHAT">RHSA-2001:164</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-126.html" source="REDHAT">RHSA-2001:126</ref>
      <ref url="http://www.linuxsecurity.com/advisories/other_advisory-1649.html" source="ENGARDE">ESA-20011019-01</ref>
      <ref url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2001:077" source="MANDRAKE">MDKSA-2001:077</ref>
      <ref url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000430" source="CONECTIVA">CLA-2001:430</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="1.3.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2001-0731" published="2001-10-01" name="CVE-2001-0731" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apache 1.3.20 with Multiviews enabled allows remote attackers to view directory contents and bypass the index page via a URL containing the "M=D" query string.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.apacheweek.com/issues/01-10-05#security" source="CONFIRM" patch="1">http://www.apacheweek.com/issues/01-10-05#security</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/8275" source="XF">apache-multiviews-directory-listing(8275)</ref>
      <ref url="http://www.securityfocus.com/bid/3009" source="BID">3009</ref>
      <ref url="http://www.securityfocus.com/archive/1/20010709214744.A28765@brasscannon.net" source="BUGTRAQ">20010709 How Google indexed a file with no external link</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-164.html" source="REDHAT">RHSA-2001:164</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2001-126.html" source="REDHAT">RHSA-2001:126</ref>
      <ref url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2001:077" source="MANDRAKE">MDKSA-2001:077</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20020301-01-P" source="SGI">20020301-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="1.3.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2001-0733" published="2001-10-18" name="CVE-2001-0733" modified="2008-09-05" CVSS_version="2.0 incomplete approximation" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The #sinclude directive in Embedded Perl (ePerl) 2.2.14 and earlier allows a remote attacker to execute arbitrary code by modifying the 'sinclude' file to point to another file that contains a #include directive that references a file that contains the code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/static/6743.php" source="XF" patch="1" adv="1">eperl-embedded-code-execution(6743)</ref>
      <ref url="http://www.securityfocus.com/archive/1/192711" source="BUGTRAQ" patch="1" adv="1">20010
