<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://nvd.nist.gov/feeds/cve/1.2" nvd_xml_version="1.2" pub_date="2009-11-21" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd">
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2003-0061" seq="2003-0061" severity="High" type="CVE" published="2002-01-11" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in passwd for HP UX B.10.20 allows local users to execute arbitrary commands with root privileges via a long LANG environment variable.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=87&amp;type=vulnerabilities&amp;flashstatus=true" adv="1">20030203 HP UX passwd Binary Buffer Overflow Vulnerability</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="10.20" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2003-1071" seq="2003-1071" severity="Low" type="CVE" published="2003-01-03" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-10">
        <desc>
            <descript source="cve">rpc.walld (wall daemon) for Solaris 2.6 through 9 allows local users to send messages to logged on users that appear to come from arbitrary user IDs by closing stderr before executing wall, then supplying a spoofed from header.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/944241" adv="1">VU#944241</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/11608" adv="1">solaris-wall-message-spoofing(11608)</ref>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-51980-1" adv="1">51980</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/305105" adv="1">20030103 Solaris 2.x /usr/sbin/wall Advisory</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/7825/" adv="1">7825</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006682">1006682</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1005882">1005882</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6509">6509</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers edition="" num="2.5.1" />
                <vers edition=":x86" num="2.5.1" />
                <vers edition="" num="2.6" />
                <vers edition=":x86" num="2.6" />
                <vers edition="" num="7.0" />
                <vers edition=":x86" num="7.0" />
                <vers edition="" num="8.0" />
                <vers edition=":x86" num="8.0" />
                <vers edition="" num="9.0" />
                <vers edition=":sparc" num="9.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2003-0014" seq="2003-0014" severity="Medium" type="CVE" published="2003-01-11" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">gsinterf.c in bmv 1.2 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files.</descript>
        </desc>
        <sols>
            <sol source="nvd">For the stable distribution this problem has been fixed in version 1.2-14.2. For the unstable distribution this problem has been fixed in version 1.2-17.</sol>
        </sols>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/18823" adv="1">bmv-symlink(18823)</ref>
            <ref source="BID" patch="1" url="http://securityfocus.org/bid/12229" adv="1">12229</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-633" adv="1">DSA-633</ref>
            <ref source="CONFIRM" url="http://packages.debian.org/changelogs/pool/main/b/bmv/bmv_1.2-14.2/changelog" adv="1">http://packages.debian.org/changelogs/pool/main/b/bmv/bmv_1.2-14.2/changelog</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1012847">1012847</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/13796">13796</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/13793">13793</ref>
        </refs>
        <vuln_soft>
            <prod vendor="bmv" name="bmv">
                <vers num="1.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0032" seq="2003-0032" severity="Medium" type="CVE" published="2003-01-17" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Memory leak in libmcrypt before 2.5.5 allows attackers to cause a denial of service (memory exhaustion) via a large number of requests to the application, which causes libmcrypt to dynamically load algorithms via libtool.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-228" adv="1">DSA-228</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104162752401212&amp;w=2" adv="1">20030103 Multiple libmcrypt vulnerabilities</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/10988.php" adv="1">libmcrypt-libtool-memory-leak(10988)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6512">6512</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104188513728573&amp;w=2">20030105 GLSA:  libmcrypt</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000567">CLA-2003:567</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mcrypt" name="libmcrypt">
                <vers num="2.5.1_r4" />
                <vers num="2.5.2" />
                <vers num="2.5.3" />
                <vers num="2.5_.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0031" seq="2003-0031" severity="High" type="CVE" published="2003-01-17" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Multiple buffer overflows in libmcrypt before 2.5.5 allow attackers to cause a denial of service (crash).</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-228" adv="1">DSA-228</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104162752401212&amp;w=2" adv="1">20030103 Multiple libmcrypt vulnerabilities</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006181">1006181</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6510">6510</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104188513728573&amp;w=2">20030105 GLSA:  libmcrypt</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000567">CLA-2003:567</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mcrypt" name="libmcrypt">
                <vers num="2.5.1_r4" />
                <vers num="2.5.2" />
                <vers num="2.5.3" />
                <vers num="2.5_.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0013" seq="2003-0013" severity="High" type="CVE" published="2003-01-17" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">The default .htaccess scripts for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 do not include filenames for backup copies of the localconfig file that are made from editors such as vi and Emacs, which could allow remote attackers to obtain a database password by directly accessing the backup file.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-230" adv="1">DSA-230</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104154319200399&amp;w=2" adv="1">20030102 [BUGZILLA] Security Advisory - remote database password disclosure</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6501">6501</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/6351">6351</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/10970.php">bugzilla-htaccess-database-password(10970)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mozilla" name="bugzilla">
                <vers num="2.14" />
                <vers num="2.14.1" />
                <vers num="2.14.2" />
                <vers num="2.14.3" />
                <vers num="2.14.4" />
                <vers num="2.16" />
                <vers num="2.16.1" />
                <vers num="2.17" />
                <vers num="2.17.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2003-0012" seq="2003-0012" severity="Low" type="CVE" published="2003-01-17" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-10">
        <desc>
            <descript source="cve">The data collection script for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 sets world-writable permissions for the data/mining directory when it runs, which allows local users to modify or delete the data.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104154319200399&amp;w=2" adv="1">20030102 [BUGZILLA] Security Advisory - remote database password disclosure</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/10971.php" adv="1">bugzilla-mining-world-writable(10971)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6502">6502</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-012.html">RHSA-2003:012</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-230">DSA-230</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mozilla" name="bugzilla">
                <vers num="2.14" />
                <vers num="2.14.1" />
                <vers num="2.14.2" />
                <vers num="2.14.3" />
                <vers num="2.14.4" />
                <vers num="2.16" />
                <vers num="2.16.1" />
                <vers num="2.17" />
                <vers num="2.17.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0026" seq="2003-0026" severity="High" type="CVE" published="2003-01-17" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Multiple stack-based buffer overflows in the error handling routines of the minires library, as used in the NSUPDATE capability for ISC DHCPD 3.0 through 3.0.1RC10, allow remote attackers to execute arbitrary code via a DHCP message containing a long hostname.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/284857" adv="1">VU#284857</ref>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-2003-01.html" adv="1">CA-2003-01</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2003-011.html" adv="1">RHSA-2003:011</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-231" adv="1">DSA-231</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11073">dhcpd-minires-multiple-bo(11073)</ref>
            <ref source="SUSE" url="http://www.suse.com/de/security/2003_006_dhcp.html">SuSE-SA:2003:0006</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1005924">1005924</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6627">6627</ref>
            <ref source="OPENPKG" url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2003.002.html">OpenPKG-SA-2003.002</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:007">MDKSA-2003:007</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-031.shtml">N-031</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000562">CLA-2003:562</ref>
            <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-01/0250.html">20030122 [securityslackware.com: [slackware-security] New DHCP packages available]</ref>
        </refs>
        <vuln_soft>
            <prod vendor="isc" name="dhcpd">
                <vers num="3.0" />
                <vers edition="rc1" num="3.0.1" />
                <vers edition="rc2" num="3.0.1" />
                <vers edition="rc3" num="3.0.1" />
                <vers edition="rc4" num="3.0.1" />
                <vers edition="rc5" num="3.0.1" />
                <vers edition="rc6" num="3.0.1" />
                <vers edition="rc7" num="3.0.1" />
                <vers edition="rc8" num="3.0.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0025" seq="2003-0025" severity="High" type="CVE" published="2003-01-17" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Multiple SQL injection vulnerabilities in IMP 2.2.8 and earlier allow remote attackers to perform unauthorized database activities and possibly gain privileges via certain database functions such as check_prefs() in db.pgsql, as demonstrated using mailbox.php3.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-229" adv="1">DSA-229</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104204786206563&amp;w=2" adv="1">20030108 IMP 2.x SQL injection vulnerabilities</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1005904">1005904</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6559">6559</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/306268">20030108 Re: IMP 2.x SQL injection vulnerabilities</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/8177">8177</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/8087">8087</ref>
        </refs>
        <vuln_soft>
            <prod vendor="horde" name="imp">
                <vers num="2.2" />
                <vers num="2.2.1" />
                <vers num="2.2.2" />
                <vers num="2.2.3" />
                <vers num="2.2.4" />
                <vers num="2.2.5" />
                <vers num="2.2.6" />
                <vers num="2.2.7" />
                <vers num="2.2.8" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0001" seq="2003-0001" severity="Medium" type="CVE" published="2003-01-17" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/412115" adv="1">VU#412115</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-025.html">RHSA-2003:025</ref>
            <ref source="MISC" url="http://www.atstake.com/research/advisories/2003/atstake_etherleak_report.pdf">http://www.atstake.com/research/advisories/2003/atstake_etherleak_report.pdf</ref>
            <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2003/a010603-1.txt" adv="1">A010603-1</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104222046632243&amp;w=2" adv="1">20030110 More information regarding Etherleak</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0016.html">20030110 More information regarding Etherleak</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/307564/30/26270/threaded">20030117 Re: More information regarding Etherleak</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/305335/30/26420/threaded">20030106 Etherleak: Ethernet frame padding information leakage (A010603-1)</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-088.html">RHSA-2003:088</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/9962">9962</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/7996">7996</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2665" sig="1">oval:org.mitre.oval:def:2665</ref>
        </refs>
        <vuln_soft>
            <prod vendor="freebsd" name="freebsd">
                <vers num="4.2" />
                <vers num="4.3" />
                <vers num="4.4" />
                <vers num="4.5" />
                <vers num="4.6" />
                <vers num="4.7" />
            </prod>
            <prod vendor="linux" name="linux_kernel">
                <vers num="2.4.1" />
                <vers num="2.4.10" />
                <vers num="2.4.11" />
                <vers num="2.4.12" />
                <vers num="2.4.13" />
                <vers num="2.4.14" />
                <vers num="2.4.15" />
                <vers num="2.4.16" />
                <vers num="2.4.17" />
                <vers num="2.4.18" />
                <vers num="2.4.19" />
                <vers num="2.4.2" />
                <vers num="2.4.20" />
                <vers num="2.4.3" />
                <vers num="2.4.4" />
                <vers num="2.4.5" />
                <vers num="2.4.6" />
                <vers num="2.4.7" />
                <vers num="2.4.8" />
                <vers num="2.4.9" />
            </prod>
            <prod vendor="microsoft" name="windows_2000">
                <vers edition=":datacenter_server" num="" />
                <vers edition=":server" num="" />
                <vers edition=":advanced_server" num="" />
                <vers edition=":professional" num="" />
                <vers edition="sp1" num="" />
                <vers edition="sp1:server" num="" />
                <vers edition="sp1:professional" num="" />
                <vers edition="sp1:advanced_server" num="" />
                <vers edition="sp1:datacenter_server" num="" />
                <vers edition="sp2" num="" />
                <vers edition="sp2:server" num="" />
                <vers edition="sp2:advanced_server" num="" />
                <vers edition="sp2:datacenter_server" num="" />
                <vers edition="sp2:professional" num="" />
            </prod>
            <prod vendor="microsoft" name="windows_2000_terminal_services">
                <vers edition="sp1" num="" />
                <vers edition="sp2" num="" />
            </prod>
            <prod vendor="netbsd" name="netbsd">
                <vers num="1.5" />
                <vers num="1.5.1" />
                <vers num="1.5.2" />
                <vers num="1.5.3" />
                <vers num="1.6" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-1075" seq="2003-1075" severity="Medium" type="CVE" published="2003-01-27" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Unknown vulnerability in the FTP server (in.ftpd) for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (temporary FTP server hang), which affects other active mode FTP clients.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-50240-1" adv="1">50240</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/7968/" adv="1">7968</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11186" adv="1">solaris-ftpd-dos(11186)</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1005996">1005996</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6709">6709</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers edition="" num="2.6" />
                <vers edition=":x86" num="2.6" />
                <vers edition="" num="7.0" />
                <vers edition=":x86" num="7.0" />
                <vers edition="" num="8.0" />
                <vers edition=":x86" num="8.0" />
                <vers edition="" num="9.0" />
                <vers edition=":x86" num="9.0" />
                <vers edition=":sparc" num="9.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2003-1090" seq="2003-1090" severity="High" type="CVE" published="2003-02-06" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in AbsoluteTelnet before 2.12 RC10 allows remote attackers to execute arbitrary code via a long window title.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/666073" adv="1">VU#666073</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/11265" adv="1">absolutetelnet-title-bar-bo(11265)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/6785" adv="1">6785</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104454984001076&amp;w=2" adv="1">20030206 AbsoluteTelnet 2.00 buffer overflow.</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/16024">16024</ref>
        </refs>
        <vuln_soft>
            <prod vendor="celestial_software" name="absolutetelnet">
                <vers num="2.0" />
                <vers num="2.11" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0027" seq="2003-0027" severity="Medium" type="CVE" published="2003-02-07" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/850785" adv="1">VU#850785</ref>
            <ref source="MISC" patch="1" url="http://www.entercept.com/news/uspr/01-22-03.asp" adv="1">http://www.entercept.com/news/uspr/01-22-03.asp</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11129">solaris-kcms-directory-traversal(11129)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6665">6665</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/50104">50104</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104326556329850&amp;w=2">20030122 Entercept Ricochet Advisory: Sun Solaris KCMS Library Service Daemon Arbitrary File Retrieval Vulner</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2592" sig="1">oval:org.mitre.oval:def:2592</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:195" sig="1">oval:org.mitre.oval:def:195</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:120" sig="1">oval:org.mitre.oval:def:120</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers edition="" num="2.5.1" />
                <vers edition=":x86" num="2.5.1" />
                <vers edition="" num="2.6" />
                <vers edition=":x86" num="2.6" />
                <vers edition="" num="7.0" />
                <vers edition=":x86" num="7.0" />
                <vers edition="" num="8.0" />
                <vers edition=":x86" num="8.0" />
                <vers edition="" num="9.0" />
                <vers edition=":sparc" num="9.0" />
                <vers edition="x86_update_2" num="9.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0017" seq="2003-0017" severity="Medium" type="CVE" published="2003-02-07" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Apache 2.0 before 2.0.44 on Windows platforms allows remote attackers to obtain certain files via an HTTP request that ends in certain illegal characters such as ">", which causes a different filename to be processed and served.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://marc.theaimsgroup.com/?l=apache-httpd-announce&amp;m=104313442901017&amp;w=2">http://marc.theaimsgroup.com/?l=apache-httpd-announce&amp;m=104313442901017&amp;w=2</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apache" name="http_server">
                <vers num="2.0.36" />
                <vers num="2.0.37" />
                <vers num="2.0.38" />
                <vers num="2.0.39" />
                <vers num="2.0.40" />
                <vers num="2.0.41" />
                <vers num="2.0.42" />
                <vers num="2.0.43" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0016" seq="2003-0016" severity="High" type="CVE" published="2003-02-07" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Apache before 2.0.44, when running on unpatched Windows 9x and Me operating systems, allows remote attackers to cause a denial of service or execute arbitrary code via an HTTP request containing MS-DOS device names.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/979793">VU#979793</ref>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/825177">VU#825177</ref>
            <ref source="MLIST" patch="1" url="http://marc.theaimsgroup.com/?l=apache-httpd-announce&amp;m=104313442901017&amp;w=2">[apache-httpd-announce] 20030120 [ANNOUNCE] Apache 2.0.44 Released</ref>
            <ref source="CONFIRM" url="http://www.apacheweek.com/issues/03-01-24#security">http://www.apacheweek.com/issues/03-01-24#security</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11125">apache-device-code-execution(11125)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11124">apache-device-name-dos(11124)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6659">6659</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apache" name="http_server">
                <vers num="2.0.36" />
                <vers num="2.0.37" />
                <vers num="2.0.38" />
                <vers num="2.0.39" />
                <vers num="2.0.40" />
                <vers num="2.0.41" />
                <vers num="2.0.42" />
                <vers num="2.0.43" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0015" seq="2003-0015" severity="High" type="CVE" published="2003-02-07" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed Directory request, as demonstrated by bypassing write checks to execute Update-prog and Checkin-prog commands.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/650937" adv="1">VU#650937</ref>
            <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-02.html">CA-2003-02</ref>
            <ref source="MISC" patch="1" url="http://security.e-matters.de/advisories/012003.html" adv="1">http://security.e-matters.de/advisories/012003.html</ref>
            <ref source="REDHAT" patch="1" url="http://rhn.redhat.com/errata/RHSA-2003-013.html" adv="1">RHSA-2003:013</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11108" adv="1">cvs-doublefree-memory-corruption(11108)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6650">6650</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-012.html">RHSA-2003:012</ref>
            <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:009">MDKSA-2003:009</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-233">DSA-233</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-032.shtml">N-032</ref>
            <ref source="FREEBSD" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104438807203491&amp;w=2">FreeBSD-SA-03:01</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104428571204468&amp;w=2">20030202 Exploit for CVS double free() for Linux pserver</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104342550612736&amp;w=2">20030124 Test program for CVS double-free.</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104333092200589&amp;w=2">20030122 [security@slackware.com: [slackware-security] New CVS packages available]</ref>
            <ref source="CONFIRM" url="http://ccvs.cvshome.org/servlets/NewsItemView?newsID=51&amp;JServSessionIdservlets=5of2iuhr14">http://ccvs.cvshome.org/servlets/NewsItemView?newsID=51&amp;JServSessionIdservlets=5of2iuhr14</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0028.html">20030120 Advisory 01/2003: CVS remote vulnerability</ref>
        </refs>
        <vuln_soft>
            <prod vendor="cvs" name="cvs">
                <vers num="1.10.7" />
                <vers num="1.10.8" />
                <vers num="1.11" />
                <vers num="1.11.1" />
                <vers num="1.11.1p1" />
                <vers num="1.11.2" />
                <vers num="1.11.3" />
                <vers num="1.11.4" />
            </prod>
            <prod vendor="freebsd" name="freebsd">
                <vers num="4.4" />
                <vers num="4.5" />
                <vers num="4.6" />
                <vers num="4.7" />
                <vers num="5.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0003" seq="2003-0003" severity="High" type="CVE" published="2003-02-07" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code via an RPC call to the service containing certain parameter information.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/610986" adv="1">VU#610986</ref>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-2003-03.html" adv="1">CA-2003-03</ref>
            <ref source="MS" patch="1" url="http://www.microsoft.com/technet/security/bulletin/ms03-001.asp" adv="1">MS03-001</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11132" adv="1">win-locator-bo(11132)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6666">6666</ref>
            <ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104393588232166&amp;w=2">20030130 Microsoft RPC Locator Buffer Overflow Vulnerability (#NISR29012003)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104394414713415&amp;w=2">20030130 Microsoft RPC Locator Buffer Overflow Vulnerability (#NISR29012003)</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:103" sig="1">oval:org.mitre.oval:def:103</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="windows_2000">
                <vers edition=":server" num="" />
                <vers edition=":server:jp" num="" />
                <vers edition=":professional" num="" />
                <vers edition=":datacenter_server" num="" />
                <vers edition=":advanced_server" num="" />
                <vers edition="sp1" num="" />
                <vers edition="sp1:server" num="" />
                <vers edition="sp1:professional" num="" />
                <vers edition="sp1:datacenter_server" num="" />
                <vers edition="sp1:advanced_server" num="" />
                <vers edition="sp2" num="" />
                <vers edition="sp2:server" num="" />
                <vers edition="sp2:advanced_server" num="" />
                <vers edition="sp2:datacenter_server" num="" />
                <vers edition="sp2:professional" num="" />
                <vers edition="sp3" num="" />
                <vers edition="sp3:advanced_server" num="" />
                <vers edition="sp3:professional" num="" />
                <vers edition="sp3:datacenter_server" num="" />
                <vers edition="sp3:server" num="" />
            </prod>
            <prod vendor="microsoft" name="windows_2000_terminal_services">
                <vers edition="sp1" num="" />
                <vers edition="sp2" num="" />
                <vers edition="sp3" num="" />
            </prod>
            <prod vendor="microsoft" name="windows_nt">
                <vers edition="" num="4.0" />
                <vers edition=":terminal_server" num="4.0" />
                <vers edition=":workstation" num="4.0" />
                <vers edition=":enterprise_server" num="4.0" />
                <vers edition=":server" num="4.0" />
                <vers edition="sp1" num="4.0" />
                <vers edition="sp1:server" num="4.0" />
                <vers edition="sp1:enterprise_server" num="4.0" />
                <vers edition="sp1:workstation" num="4.0" />
                <vers edition="sp1:terminal_server" num="4.0" />
                <vers edition="sp2" num="4.0" />
                <vers edition="sp2:terminal_server" num="4.0" />
                <vers edition="sp2:workstation" num="4.0" />
                <vers edition="sp2:server" num="4.0" />
                <vers edition="sp2:enterprise_server" num="4.0" />
                <vers edition="sp3" num="4.0" />
                <vers edition="sp3:terminal_server" num="4.0" />
                <vers edition="sp3:enterprise_server" num="4.0" />
                <vers edition="sp3:server" num="4.0" />
                <vers edition="sp3:workstation" num="4.0" />
                <vers edition="sp4" num="4.0" />
                <vers edition="sp4:terminal_server" num="4.0" />
                <vers edition="sp4:enterprise_server" num="4.0" />
                <vers edition="sp4:workstation" num="4.0" />
                <vers edition="sp4:server" num="4.0" />
                <vers edition="sp5" num="4.0" />
                <vers edition="sp5:terminal_server" num="4.0" />
                <vers edition="sp5:server" num="4.0" />
                <vers edition="sp5:workstation" num="4.0" />
                <vers edition="sp5:enterprise_server" num="4.0" />
                <vers edition="sp6" num="4.0" />
                <vers edition="sp6:enterprise_server" num="4.0" />
                <vers edition="sp6:terminal_server" num="4.0" />
                <vers edition="sp6:server" num="4.0" />
                <vers edition="sp6:workstation" num="4.0" />
                <vers edition="sp6a" num="4.0" />
                <vers edition="sp6a:terminal_server" num="4.0" />
                <vers edition="sp6a:server" num="4.0" />
                <vers edition="sp6a:workstation" num="4.0" />
                <vers edition="sp6a:enterprise_server" num="4.0" />
            </prod>
            <prod vendor="microsoft" name="windows_xp">
                <vers edition=":64-bit" num="" />
                <vers edition=":home" num="" />
                <vers edition="gold" num="" />
                <vers edition="gold:professional" num="" />
                <vers edition="sp1" num="" />
                <vers edition="sp1:64-bit" num="" />
                <vers edition="sp1:home" num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" name="CVE-2003-0002" seq="2003-0002" severity="Medium" type="CVE" published="2003-02-07" CVSS_version="2.0 incomplete approximation" CVSS_score="6.8" modified="2008-09-10">
        <desc>
            <descript source="cve">Cross-site scripting vulnerability (XSS) in ManualLogin.asp script for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary script via the REASONTXT parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MS" patch="1" url="http://www.microsoft.com/technet/security/bulletin/ms03-002.asp" adv="1">MS03-002</ref>
            <ref source="XF" patch="1" url="http://www.iss.net/security_center/static/10318.php" adv="1">mcms-manuallogin-reasontxt-xss (10318)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=103417794800719&amp;w=2" adv="1">20021007 CSS on Microsoft Content Management Server</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/5922">5922</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="content_management_server">
                <vers edition="sp1" num="2001" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0007" seq="2003-0007" severity="Medium" type="CVE" published="2003-02-07" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Microsoft Outlook 2002 does not properly handle requests to encrypt email messages with V1 Exchange Server Security certificates, which causes Outlook to send the email in plaintext, aka "Flaw in how Outlook 2002 handles V1 Exchange Server Security Certificates could lead to Information Disclosure."</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MS" patch="1" url="http://www.microsoft.com/technet/security/bulletin/ms03-003.asp" adv="1">MS03-003</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11133">outlook-v1-certificate-plaintext(11133)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6667">6667</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="outlook">
                <vers edition="sp1" num="2002" />
                <vers edition="sp2" num="2002" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0039" seq="2003-0039" severity="Medium" type="CVE" published="2003-02-07" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">ISC dhcrelay (dhcp-relay) 3.0rc9 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (packet storm) via a certain BOOTP packet that is forwarded to a broadcast MAC address, causing an infinite loop that is not restricted by a hop count.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/149953">VU#149953</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-245" adv="1">DSA-245</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104310927813830&amp;w=2" adv="1">20030115 DoS against DHCP infrastructure with isc dhcrelay</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11187" adv="1">dhcp-dhcrelay-dos(11187)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6628">6628</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-034.html">RHSA-2003:034</ref>
            <ref source="BUGTRAQ" url="http://www.openpkg.org/security/OpenPKG-SA-2003.012-dhcpd.html">20030219 [OpenPKG-SA-2003.012] OpenPKG Security Advisory (dhcpd)</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000616">CLSA-2003:616</ref>
            <ref source="TURBO" url="http://cc.turbolinux.com/security/TLSA-2003-26.txt">TLSA-2003-26</ref>
        </refs>
        <vuln_soft>
            <prod vendor="isc" name="dhcpd">
                <vers edition="rc1" num="3.0.1" />
                <vers edition="rc10" num="3.0.1" />
                <vers edition="rc2" num="3.0.1" />
                <vers edition="rc3" num="3.0.1" />
                <vers edition="rc4" num="3.0.1" />
                <vers edition="rc5" num="3.0.1" />
                <vers edition="rc6" num="3.0.1" />
                <vers edition="rc7" num="3.0.1" />
                <vers edition="rc8" num="3.0.1" />
                <vers edition="rc9" num="3.0.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2003-0038" seq="2003-0038" severity="Medium" type="CVE" published="2003-02-07" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML into web pages via the (1) email or (2) language parameters.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2004/dsa-436" adv="1">DSA-436</ref>
            <ref source="CONFIRM" patch="1" url="http://telia.dl.sourceforge.net/sourceforge/mailman/xss-2.1.0-patch.txt">http://telia.dl.sourceforge.net/sourceforge/mailman/xss-2.1.0-patch.txt</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104342745916111" adv="1">20030124 Mailman: cross-site scripting bug</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11152">mailman-email-variable-xss(11152)</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1005987">1005987</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6677">6677</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/9205">9205</ref>
        </refs>
        <vuln_soft>
            <prod vendor="gnu" name="mailman">
                <vers num="2.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0037" seq="2003-0037" severity="High" type="CVE" published="2003-02-07" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Buffer overflows in noffle news server 1.0.1 and earlier allow remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-244" adv="1">DSA-244</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11181">noffle-multiple-bo(11181)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6695">6695</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/7955">7955</ref>
        </refs>
        <vuln_soft>
            <prod vendor="noffle" name="noffle">
                <vers num="1.0.1" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" name="CVE-2003-0036" seq="2003-0036" severity="Medium" type="CVE" published="2003-02-07" CVSS_version="2.0 incomplete approximation" CVSS_score="6.2" modified="2008-09-10">
        <desc>
            <descript source="cve">ml85p, as included in the printer-drivers package for Mandrake Linux, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable filenames of the form "mlg85p%d".</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <race />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="MISC" patch="1" url="http://www.idefense.com/advisory/01.21.03.txt" adv="1">http://www.idefense.com/advisory/01.21.03.txt</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0029.html">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1005959">1005959</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/307608/30/26270/threaded">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:010">MDKSA-2003:010</ref>
        </refs>
        <vuln_soft>
            <prod vendor="rildo_pragana" name="ml85p">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2003-0035" seq="2003-0035" severity="High" type="CVE" published="2003-02-07" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-10">
        <desc>
            <descript source="cve">Buffer overflow in escputil, as included in the printer-drivers package in Mandrake Linux, allows local users to execute arbitrary code via a long printer-name command line argument.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="MISC" patch="1" url="http://www.idefense.com/advisory/01.21.03.txt" adv="1">http://www.idefense.com/advisory/01.21.03.txt</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0029.html">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1005959">1005959</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6658">6658</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/307608/30/26270/threaded">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:010">MDKSA-2003:010</ref>
        </refs>
        <vuln_soft>
            <prod vendor="robert_krawitz" name="escputil">
                <vers num="1.15.2.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2003-0034" seq="2003-0034" severity="High" type="CVE" published="2003-02-07" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-10">
        <desc>
            <descript source="cve">Buffer overflow in the mtink status monitor, as included in the printer-drivers package in Mandrake Linux, allows local users to execute arbitrary code via a long HOME environment variable.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="MISC" patch="1" url="http://www.idefense.com/advisory/01.21.03.txt" adv="1">http://www.idefense.com/advisory/01.21.03.txt</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0029.html">20030121 iDEFENSE Security Advisory 01.21.03: Buffer Overflows in Mandrake Linux printer-drivers Package</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1005959">1005959</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6656">6656</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:010">MDKSA-2003:010</ref>
        </refs>
        <vuln_soft>
            <prod vendor="jean-jacques_sarton" name="mtink">
                <vers num="0.9.32" />
                <vers num="0.9.33" />
                <vers num="0.9.52" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0045" seq="2003-0045" severity="Medium" type="CVE" published="2003-02-07" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Jakarta Tomcat before 3.3.1a on certain Windows systems may allow remote attackers to cause a denial of service (thread hang and resource consumption) via a request for a JSP page containing an MS-DOS device name, such as aux.jsp.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/12102" adv="1">jakarta-tomcat-msdos-dos(12102)</ref>
            <ref source="CONFIRM" url="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt" adv="1">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apache" name="tomcat">
                <vers num="3.0" />
                <vers num="3.1" />
                <vers num="3.1.1" />
                <vers num="3.2" />
                <vers num="3.2.1" />
                <vers num="3.2.3" />
                <vers num="3.2.4" />
                <vers num="3.3" />
                <vers num="3.3.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" name="CVE-2003-0044" seq="2003-0044" severity="Medium" type="CVE" published="2003-02-07" CVSS_version="2.0 incomplete approximation" CVSS_score="6.8" modified="2008-09-10">
        <desc>
            <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web applications for Jakarta Tomcat 3.x through 3.3.1a allow remote attackers to insert arbitrary web script or HTML.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-246" adv="1">DSA-246</ref>
            <ref source="HP" url="http://www.securityfocus.com/advisories/5111">HPSBUX0303-249</ref>
            <ref source="CONFIRM" url="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt" adv="1">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt</ref>
            <ref source="CONFIRM" url="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/" adv="1">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11196">tomcat-web-app-xss(11196)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6720">6720</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/9204">9204</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/9203">9203</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-060.shtml">N-060</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/7972">7972</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apache" name="tomcat">
                <vers num="3.0" />
                <vers num="3.1" />
                <vers num="3.1.1" />
                <vers num="3.2" />
                <vers num="3.2.1" />
                <vers num="3.2.3" />
                <vers num="3.2.4" />
                <vers num="3.3" />
                <vers num="3.3.1" />
                <vers num="3.3.1a" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0043" seq="2003-0043" severity="Medium" type="CVE" published="2003-02-07" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when processing the web.xml file, which could allow remote attackers to read portions of some files through the web.xml file.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11195" adv="1">tomcat-webxml-read-files(11195)</ref>
            <ref source="CONFIRM" url="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt" adv="1">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt</ref>
            <ref source="CONFIRM" url="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/" adv="1">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6722">6722</ref>
            <ref source="HP" url="http://www.securityfocus.com/advisories/5111">HPSBUX0303-249</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-246">DSA-246</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-060.shtml">N-060</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apache" name="tomcat">
                <vers num="3.0" />
                <vers num="3.1" />
                <vers num="3.1.1" />
                <vers num="3.2" />
                <vers num="3.2.1" />
                <vers num="3.2.3" />
                <vers num="3.2.4" />
                <vers num="3.3" />
                <vers num="3.3.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0042" seq="2003-0042" severity="Medium" type="CVE" published="2003-02-07" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-246" adv="1">DSA-246</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104394568616290&amp;w=2" adv="1">20030130 Apache Jakarta Tomcat 3 URL parsing vulnerability</ref>
            <ref source="CONFIRM" url="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt" adv="1">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt</ref>
            <ref source="CONFIRM" url="http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/" adv="1">http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11194">tomcat-null-directory-listing(11194)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6721">6721</ref>
            <ref source="HP" url="http://www.securityfocus.com/advisories/5111">HPSBUX0303-249</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-060.shtml">N-060</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/7977">7977</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/7972">7972</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apache" name="tomcat">
                <vers num="3.0" />
                <vers num="3.1" />
                <vers num="3.1.1" />
                <vers num="3.2" />
                <vers num="3.2.1" />
                <vers num="3.2.3" />
                <vers num="3.2.4" />
                <vers num="3.3" />
                <vers num="3.3.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:N/A:N)" CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" name="CVE-2003-1080" seq="2003-1080" severity="Low" type="CVE" published="2003-02-11" CVSS_version="2.0 incomplete approximation" CVSS_score="1.2" modified="2008-09-10">
        <desc>
            <descript source="cve">Unknown vulnerability in mail for Solaris 2.6 through 9 allows local users to read the email of other users.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <race />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/11303" adv="1">solaris-mail-unauthorized-access(11303)</ref>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-50751-1" adv="1">50751</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/8058/" adv="1">8058</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006084">1006084</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6838">6838</ref>
        </refs>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-1079" seq="2003-1079" severity="Medium" type="CVE" published="2003-02-18" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Unknown vulnerability in UDP RPC for Solaris 2.5.1 through 9 for SPARC, and 2.5.1 through 8 for x86, allows remote attackers to cause a denial of service (memory consumption) via certain arguments in RPC calls that cause large amounts of memory to be allocated.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/11368" adv="1">solaris-udp-rpc-dos(11368)</ref>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-50626-1" adv="1">50626</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/8092/" adv="1">8092</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006131">1006131</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6883">6883</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers edition="" num="2.5.1" />
                <vers edition=":x86" num="2.5.1" />
                <vers edition="" num="2.6" />
                <vers edition=":x86" num="2.6" />
                <vers edition="" num="7.0" />
                <vers edition=":x86" num="7.0" />
                <vers edition="" num="8.0" />
                <vers edition=":x86" num="8.0" />
                <vers edition="" num="9.0" />
                <vers edition=":sparc" num="9.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2003-0048" seq="2003-0048" severity="Medium" type="CVE" published="2003-02-19" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-10">
        <desc>
            <descript source="cve">PuTTY 0.53b and earlier does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="MISC" patch="1" url="http://www.idefense.com/advisory/01.28.03.txt" adv="1">http://www.idefense.com/advisory/01.28.03.txt</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006014">1006014</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6724">6724</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104386492422014&amp;w=2">20030129 iDEFENSE Security Advisory 01.28.03: SSH2 Clients Insecurely Store Passwords</ref>
        </refs>
        <vuln_soft>
            <prod vendor="putty" name="putty">
                <vers num="0.48" />
                <vers num="0.49" />
                <vers num="0.53" />
                <vers num="0.53b" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2003-0047" seq="2003-0047" severity="Medium" type="CVE" published="2003-02-19" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-10">
        <desc>
            <descript source="cve">SSH2 clients for VanDyke (1) SecureCRT 4.0.2 and 3.4.7, (2) SecureFX 2.1.2 and 2.0.4, and (3) Entunnel 1.0.2 and earlier, do not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="MISC" patch="1" url="http://www.idefense.com/advisory/01.28.03.txt" adv="1">http://www.idefense.com/advisory/01.28.03.txt</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104386492422014&amp;w=2">20030129 iDEFENSE Security Advisory 01.28.03: SSH2 Clients Insecurely Store Passwords</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006012">1006012</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006011">1006011</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006010">1006010</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6728">6728</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6727">6727</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6726">6726</ref>
        </refs>
        <vuln_soft>
            <prod vendor="van_dyke_technologies" name="entunnel">
                <vers num="1.0.2" prev="1" />
            </prod>
            <prod vendor="van_dyke_technologies" name="securecrt">
                <vers num="3.4.7" />
                <vers num="4.0.2" />
            </prod>
            <prod vendor="van_dyke_technologies" name="securefx">
                <vers num="2.0.4" />
                <vers num="2.1.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2003-0046" seq="2003-0046" severity="Medium" type="CVE" published="2003-02-19" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-10">
        <desc>
            <descript source="cve">AbsoluteTelnet SSH2 client does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="MISC" patch="1" url="http://www.idefense.com/advisory/01.28.03.txt" adv="1">http://www.idefense.com/advisory/01.28.03.txt</ref>
            <ref source="CONFIRM" url="http://www.celestialsoftware.net/telnet/beta_software.html" adv="1">http://www.celestialsoftware.net/telnet/beta_software.html</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104386492422014&amp;w=2">20030129 iDEFENSE Security Advisory 01.28.03: SSH2 Clients Insecurely Store Passwords</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006013">1006013</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6725">6725</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/7686">7686</ref>
        </refs>
        <vuln_soft>
            <prod vendor="celestial_software" name="absolutetelnet">
                <vers num="2.11" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2003-0019" seq="2003-0019" severity="High" type="CVE" published="2003-02-19" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-10">
        <desc>
            <descript source="cve">uml_net in the kernel-utils package for Red Hat Linux 8.0 has incorrect setuid root privileges, which allows local users to modify network interfaces, e.g. by modifying ARP entries or placing interfaces into promiscuous mode.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/134025">VU#134025</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2003-056.html" adv="1">RHSA-2003:056</ref>
            <ref source="XF" patch="1" url="http://www.iss.net/security_center/static/11276.php" adv="1">linux-umlnet-gain-privileges(11276)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6801">6801</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-044.shtml">N-044</ref>
        </refs>
        <vuln_soft>
            <prod vendor="redhat" name="linux">
                <vers edition="" num="8.0" />
                <vers edition=":i386" num="8.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:P)" CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" name="CVE-2003-0018" seq="2003-0018" severity="Low" type="CVE" published="2003-02-19" CVSS_version="2.0 incomplete approximation" CVSS_score="3.6" modified="2008-09-10">
        <desc>
            <descript source="cve">Linux kernel 2.4.10 through 2.4.21-pre4 does not properly handle the O_DIRECT feature, which allows local attackers with write privileges to read portions of previously deleted files, or cause file system corruption.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2003-025.html" adv="1">RHSA-2003:025</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2004/dsa-423" adv="1">DSA-423</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/11249.php" adv="1">linux-odirect-information-leak(11249)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6763">6763</ref>
            <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:014">MDKSA-2003:014</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-358">DSA-358</ref>
            <ref source="CONFIRM" url="http://linux.bkbits.net:8080/linux-2.4/cset@3e2f193drGJDBg9SG6JwaDQwCBnAMQ">http://linux.bkbits.net:8080/linux-2.4/cset@3e2f193drGJDBg9SG6JwaDQwCBnAMQ</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="linux_kernel">
                <vers num="2.4.10" />
                <vers num="2.4.11" />
                <vers num="2.4.12" />
                <vers num="2.4.13" />
                <vers num="2.4.14" />
                <vers num="2.4.15" />
                <vers num="2.4.16" />
                <vers num="2.4.17" />
                <vers num="2.4.18" />
                <vers num="2.4.19" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2003-0041" seq="2003-0041" severity="High" type="CVE" published="2003-02-19" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Kerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the client.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2003-020.html" adv="1">RHSA-2003:020</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0047.html">20030128 MIT Kerberos FTP client remote shell commands execution</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:021">MDKSA-2003:021</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/8114">8114</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/7979">7979</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mit" name="kerberos_ftp_client">
                <vers num="" />
            </prod>
            <prod vendor="redhat" name="linux">
                <vers edition="" num="6.2" />
                <vers edition=":i386" num="6.2" />
                <vers edition="" num="7.0" />
                <vers edition=":i386" num="7.0" />
                <vers edition="" num="7.1" />
                <vers edition=":i386" num="7.1" />
                <vers edition="" num="7.2" />
                <vers edition=":i386" num="7.2" />
                <vers edition=":ia64" num="7.2" />
                <vers edition="" num="7.3" />
                <vers edition=":i386" num="7.3" />
                <vers edition="" num="8.0" />
                <vers edition=":i386" num="8.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0040" seq="2003-0040" severity="High" type="CVE" published="2003-02-19" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">SQL injection vulnerability in the PostgreSQL auth module for courier 0.40 and earlier allows remote attackers to execute SQL code via the user name.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/6738" adv="1">6738</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-247" adv="1">DSA-247</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11213">courierimap-authmysqllib-sql-injection(11213)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="double_precision_incorporated" name="courier_mta">
                <vers num="0.37.3" />
            </prod>
            <prod vendor="inter7" name="courier-imap">
                <vers num="1.6" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2003-0004" seq="2003-0004" severity="High" type="CVE" published="2003-02-19" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-10">
        <desc>
            <descript source="cve">Buffer overflow in the Windows Redirector function in Microsoft Windows XP allows local users to execute arbitrary code via a long parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="MS" patch="1" url="http://www.microsoft.com/technet/security/bulletin/ms03-005.asp" adv="1">MS03-005</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6778">6778</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/11260.php">winxp-windows-redirector-bo(11260)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104878038418534&amp;w=2">20030327 NSFOCUS SA2003-01: Microsoft Windows XP Redirector Local Buffer Overflow Vulnerability</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0154.html">20030327 NSFOCUS SA2003-01: Microsoft Windows XP Redirector Local Buffer Overflow Vulnerability</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="windows_xp">
                <vers edition=":64-bit" num="" />
                <vers edition=":home" num="" />
                <vers edition="gold" num="" />
                <vers edition="gold:professional" num="" />
                <vers edition="sp1" num="" />
                <vers edition="sp1:64-bit" num="" />
                <vers edition="sp1:home" num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2003-0056" seq="2003-0056" severity="High" type="CVE" published="2003-02-19" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-10">
        <desc>
            <descript source="cve">Buffer overflow in secure locate (slocate) before 2.7 allows local users to execute arbitrary code via a long (1) -c or (2) -r command line argument.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-252" adv="1">DSA-252</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104428624705363&amp;w=2" adv="1">20030202 GLSA:  slocate</ref>
            <ref source="MISC" url="http://www.usg.org.uk/advisories/2003.001.txt" adv="1">http://www.usg.org.uk/advisories/2003.001.txt</ref>
            <ref source="CONECTIVA" url="http://www.net-security.org/advisory.php?id=2010">CLA-2003:643</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:015">MDKSA-2003:015</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/8749">8749</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/8236">8236</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/8118/">8118</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/8007">8007</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/7982">7982</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/7947">7947</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/10720">10720</ref>
            <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2004-041.html">RHSA-2004:041</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104348607205691&amp;w=2">20030125 Re: [USG- SA- 2003.001] USG Security Advisory (slocate)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104342864418213&amp;w=2">20030124 [USG- SA- 2003.001] USG Security Advisory (slocate)</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc">20040202-01-U</ref>
            <ref source="CALDERA" url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-009.0.txt">CSSA-2003-009.0</ref>
        </refs>
        <vuln_soft>
            <prod vendor="slocate" name="slocate">
                <vers num="2.5" />
                <vers num="2.6" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0057" seq="2003-0057" severity="High" type="CVE" published="2003-02-19" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Multiple buffer overflows in Hypermail 2 before 2.1.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code (1) via a long attachment filename that is not properly handled by the hypermail executable, or (2) by connecting to the mail CGI program from an IP address that reverse-resolves to a long hostname.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104369136703903&amp;w=2" adv="1">20030127 Hypermail buffer overflows</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11158">hypermail-long-hostname-bo(11158)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11157">hypermail-mail-attachment-bo(11157)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6690">6690</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6689">6689</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-248">DSA-248</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/8030">8030</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0042.html">20030126 Hypermail buffer overflows</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hypermail" name="hypermail">
                <vers num="2.0b25" />
                <vers num="2.1.1" />
                <vers num="2.1.2" />
                <vers num="2.1.3" />
                <vers num="2.1.4" />
                <vers num="2.1.5" />
                <vers num="2.1_.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0058" seq="2003-0058" severity="Medium" type="CVE" published="2003-02-19" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to cause a denial of service (crash) on KDCs within the same realm via a certain protocol request that causes a null dereference.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/661243" adv="1">VU#661243</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/6683" adv="1">6683</ref>
            <ref source="CONFIRM" patch="1" url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt" adv="1">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/10099">kerberos-kdc-null-pointer-dos(10099)</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-168.html">RHSA-2003:168</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-052.html">RHSA-2003:052</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-051.html">RHSA-2003:051</ref>
            <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:043">MDKSA-2003:043</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/50142">50142</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000639">CLSA-2003:639</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1110" sig="1">oval:org.mitre.oval:def:1110</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mit" name="kerberos">
                <vers num="5-1.2.1" />
                <vers num="5-1.2.2" />
                <vers num="5-1.2.3" />
                <vers num="5-1.2.4" />
            </prod>
            <prod vendor="sun" name="enterprise_authentication_mechanism">
                <vers num="1.0" />
            </prod>
            <prod vendor="sun" name="solaris">
                <vers edition="" num="8.0" />
                <vers edition=":x86" num="8.0" />
                <vers edition="" num="9.0" />
                <vers edition=":sparc" num="9.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0059" seq="2003-0059" severity="High" type="CVE" published="2003-02-19" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Unknown vulnerability in the chk_trans.c of the libkrb5 library for MIT Kerberos V5 before 1.2.5 allows users from one realm to impersonate users in other realms that have the same inter-realm keys.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/684563" adv="1">VU#684563</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/6714" adv="1">6714</ref>
            <ref source="CONFIRM" patch="1" url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt" adv="1">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11188">kerberos-kdc-user-spoofing(11188)</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-168.html">RHSA-2003:168</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-052.html">RHSA-2003:052</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-051.html">RHSA-2003:051</ref>
            <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:043">MDKSA-2003:043</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000639">CLSA-2003:639</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mit" name="kerberos">
                <vers num="5-1.2.1" />
                <vers num="5-1.2.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0060" seq="2003-0060" severity="High" type="CVE" published="2003-02-19" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Format string vulnerabilities in the logging routines for MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in Kerberos principal names.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/787523" adv="1">VU#787523</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/6712" adv="1">6712</ref>
            <ref source="CONFIRM" patch="1" url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt" adv="1">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11189">kerberos-kdc-format-string(11189)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4879">4879</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000639">CLSA-2003:639</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mit" name="kerberos">
                <vers num="5-1.2.1" />
                <vers num="5-1.2.2" />
                <vers num="5-1.2.3" />
                <vers num="5-1.2.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2003-0062" seq="2003-0062" severity="High" type="CVE" published="2003-02-19" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-10">
        <desc>
            <descript source="cve">Buffer overflow in Eset Software NOD32 for UNIX before 1.013 allows local users to execute arbitrary code via a long path name.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="MISC" patch="1" url="http://www.idefense.com/advisory/02.10.03.txt" adv="1">http://www.idefense.com/advisory/02.10.03.txt</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6803">6803</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/11282.php" adv="1">nod32-pathname-bo(11282)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104490777824360&amp;w=2">20030210 iDEFENSE Security Advisory 02.10.03: Buffer Overflow In NOD32 Antivirus Software for Unix</ref>
        </refs>
        <vuln_soft>
            <prod vendor="eset_software" name="nod32_antivirus">
                <vers num="1.0.11" />
                <vers num="1.0.12" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0073" seq="2003-0073" severity="Medium" type="CVE" published="2003-02-19" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Double-free vulnerability in mysqld for MySQL before 3.23.55 allows attackers with MySQL access to cause a denial of service (crash) via mysql_change_user.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-303" adv="1">DSA-303</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104385719107879&amp;w=2" adv="1">20030129 [OpenPKG-SA-2003.008] OpenPKG Security Advisory (mysql)</ref>
            <ref source="CONFIRM" url="http://www.mysql.com/doc/en/News-3.23.55.html" adv="1">http://www.mysql.com/doc/en/News-3.23.55.html</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6718">6718</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-166.html">RHSA-2003:166</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-094.html">RHSA-2003:094</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-093.html">RHSA-2003:093</ref>
            <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:013">MDKSA-2003:013</ref>
            <ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/engarde_advisory-2873.html">ESA-20030220-004</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/11199.php">mysql-mysqlchangeuser-doublefree-dos(11199)</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000743">CLA-2003:743</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:436" sig="1">oval:org.mitre.oval:def:436</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mysql" name="mysql">
                <vers num="3.23.31" />
                <vers num="3.23.36" />
                <vers num="3.23.41" />
                <vers num="3.23.47" />
                <vers num="3.23.52" />
                <vers num="3.23.53" />
                <vers num="3.23.54" />
                <vers num="3.23.54a" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2003-0074" seq="2003-0074" severity="High" type="CVE" published="2003-02-19" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Format string vulnerability in mpmain.c for plpnfsd of the plptools package allows remote attackers to execute arbitrary code via the functions (1) debuglog, (2) errorlog, and (3) infolog.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/6715" adv="1">6715</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/11193.php">plptools-plpnsfd-format-string(11193)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104386699725019&amp;w=2" adv="1">20030129 Re: Local root vuln in SuSE 8.0 plptools package</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104385772908969&amp;w=2" adv="1">20030129 Local root vuln in SuSE 8.0 plptools package</ref>
        </refs>
        <vuln_soft>
            <prod vendor="plptools" name="plptools">
                <vers num="0.6" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0075" seq="2003-0075" severity="High" type="CVE" published="2003-02-19" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Integer signedness error in the myFseek function of samplein.c for Blade encoder (BladeEnc) 0.94.2 and earlier allows remote attackers to execute arbitrary code via a negative offset value following a "fmt" wave chunk.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/6745" adv="1">6745</ref>
            <ref source="MISC" patch="1" url="http://www.pivx.com/luigi/adv/blade942-adv.txt" adv="1">http://www.pivx.com/luigi/adv/blade942-adv.txt</ref>
            <ref source="GENTOO" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104446346127432&amp;w=2">GLSA-200302-04</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/11227.php" adv="1">bladeenc-myfseek-code-execution(11227)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104428700106672&amp;w=2">20030202 Bladeenc 0.94.2 code execution</ref>
        </refs>
        <vuln_soft>
            <prod vendor="bladeenc" name="bladeenc">
                <vers num="0.92.7" />
                <vers num="0.93.10" />
                <vers num="0.94.0" />
                <vers num="0.94.1" />
                <vers num="0.94.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" name="CVE-2003-0076" seq="2003-0076" severity="Medium" type="CVE" published="2003-02-19" CVSS_version="2.0 incomplete approximation" CVSS_score="6.4" modified="2008-09-05">
        <desc>
            <descript source="cve">Unknown vulnerability in the directory parser for Direct Connect 4 Linux (dcgui) before 0.2.2 allows remote attackers to read files outside the sharelist.</descript>
        </desc>
        <loss_types>
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104437720116243&amp;w=2">20030204 GLSA:  qt-dcgui</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/11246.php" adv="1">qtdcgui-directory-download-files(11246)</ref>
            <ref source="CONFIRM" url="http://dc.ketelhot.de/pipermail/dc/2003-January/000094.html" adv="1">http://dc.ketelhot.de/pipermail/dc/2003-January/000094.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="dcgui" name="dcgui">
                <vers num="0.2" />
                <vers num="0.2.1" />
            </prod>
            <prod vendor="qt-dcgui" name="qt-dcgui">
                <vers num="0.2" />
                <vers num="0.2.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-1326" seq="2003-1326" severity="High" type="CVE" published="2003-02-19" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model to run malicious script or arbitrary programs via dialog boxes, aka "Improper Cross Domain Security Validation with dialog box."</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <access />
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MS" patch="1" url="http://www.microsoft.com/technet/security/bulletin/ms03-004.asp" adv="1">MS03-004</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/11258.php" adv="1">ie-dialog-zone-bypass(11258)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6779">6779</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-038.shtml">N-038</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:49" sig="1">oval:org.mitre.oval:def:49</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:178" sig="1">oval:org.mitre.oval:def:178</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:126" sig="1">oval:org.mitre.oval:def:126</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="ie">
                <vers edition="sp1" num="5.0.1" />
                <vers edition="sp2" num="5.0.1" />
                <vers edition="sp3" num="5.0.1" />
                <vers edition="sp1" num="5.5" />
                <vers edition="sp2" num="5.5" />
                <vers edition="sp1" num="6.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-1326" seq="2003-1326" severity="High" type="CVE" published="2003-02-19" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model to run malicious script or arbitrary programs via dialog boxes, aka "Improper Cross Domain Security Validation with dialog box."</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <access />
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MS" patch="1" url="http://www.microsoft.com/technet/security/bulletin/ms03-004.asp" adv="1">MS03-004</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/11258.php" adv="1">ie-dialog-zone-bypass(11258)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6779">6779</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-038.shtml">N-038</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:49" sig="1">oval:org.mitre.oval:def:49</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:178" sig="1">oval:org.mitre.oval:def:178</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:126" sig="1">oval:org.mitre.oval:def:126</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="ie">
                <vers edition="sp1" num="5.0.1" />
                <vers edition="sp2" num="5.0.1" />
                <vers edition="sp3" num="5.0.1" />
                <vers edition="sp1" num="5.5" />
                <vers edition="sp2" num="5.5" />
                <vers edition="sp1" num="6.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-1078" seq="2003-1078" severity="High" type="CVE" published="2003-02-28" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">The FTP client for Solaris 2.6, 7, and 8 with the debug (-d) flag enabled displays the user password on the screen during login.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/11436" adv="1">solaris-ftp-plaintext-password(11436)</ref>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-51081-1" adv="1">51081</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/8186/" adv="1">8186</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006195">1006195</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6989">6989</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers edition="" num="2.6" />
                <vers edition=":x86" num="2.6" />
                <vers edition="" num="7.0" />
                <vers edition=":x86" num="7.0" />
                <vers edition="" num="8.0" />
                <vers edition=":x86" num="8.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0021" seq="2003-0021" severity="Medium" type="CVE" published="2003-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">The "screen dump" feature in Eterm 0.9.1 and earlier allows attackers to overwrite arbitrary files via a certain character escape sequence when it is echoed to a user's terminal, e.g. when the user views a file containing the malicious sequence.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://www.iss.net/security_center/static/11413.php" adv="1">terminal-emulator-screen-dump(11413)</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" adv="1">20030224 Terminal Emulator Security Issues</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6936">6936</ref>
            <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:040">MDKSA-2003:040</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref>
        </refs>
        <vuln_soft>
            <prod vendor="michael_jennings" name="eterm">
                <vers num="0.8.10" />
                <vers num="0.9.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0022" seq="2003-0022" severity="Medium" type="CVE" published="2003-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">The "screen dump" feature in rxvt 2.7.8 allows attackers to overwrite arbitrary files via a certain character escape sequence when it is echoed to a user's terminal, e.g. when the user views a file containing the malicious sequence.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://www.iss.net/security_center/static/11413.php" adv="1">terminal-emulator-screen-dump(11413)</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" adv="1">20030224 Terminal Emulator Security Issues</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6938">6938</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-055.html">RHSA-2003:055</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-054.html">RHSA-2003:054</ref>
            <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:034">MDKSA-2003:034</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref>
        </refs>
        <vuln_soft>
            <prod vendor="rxvt" name="rxvt">
                <vers num="2.6.1" />
                <vers num="2.6.2" />
                <vers num="2.6.3" />
                <vers num="2.6.4" />
                <vers num="2.7.5" />
                <vers num="2.7.6" />
                <vers num="2.7.7" />
                <vers num="2.7.8" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0023" seq="2003-0023" severity="Medium" type="CVE" published="2003-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">The menuBar feature in rxvt 2.7.8 allows attackers to modify menu options and execute arbitrary commands via a certain character escape sequence that inserts the commands into the menu.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://www.iss.net/security_center/static/11416.php" adv="1">terminal-emulator-menu-modification(11416)</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" adv="1">20030224 Terminal Emulator Security Issues</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6947">6947</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-055.html">RHSA-2003:055</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-054.html">RHSA-2003:054</ref>
            <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:034">MDKSA-2003:034</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref>
        </refs>
        <vuln_soft>
            <prod vendor="rxvt" name="rxvt">
                <vers num="2.6.1" />
                <vers num="2.6.2" />
                <vers num="2.6.3" />
                <vers num="2.6.4" />
                <vers num="2.7.5" />
                <vers num="2.7.6" />
                <vers num="2.7.7" />
                <vers num="2.7.8" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0024" seq="2003-0024" severity="High" type="CVE" published="2003-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">The menuBar feature in aterm 0.42 allows attackers to modify menu options and execute arbitrary commands via a certain character escape sequence that inserts the commands into the menu.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://www.iss.net/security_center/static/11416.php" adv="1">terminal-emulator-menu-modification(11416)</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" adv="1">20030224 Terminal Emulator Security Issues</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6949">6949</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref>
        </refs>
        <vuln_soft>
            <prod vendor="aterm" name="aterm">
                <vers num="0.42" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0068" seq="2003-0068" severity="High" type="CVE" published="2003-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">The Eterm terminal emulator 0.9.1 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://www.iss.net/security_center/static/11414.php" adv="1">terminal-emulator-window-title(11414)</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" adv="1">20030224 Terminal Emulator Security Issues</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/10237">10237</ref>
            <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:040">MDKSA-2003:040</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-496">DSA-496</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref>
        </refs>
        <vuln_soft>
            <prod vendor="michael_jennings" name="eterm">
                <vers num="0.8.10" />
                <vers num="0.9.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0070" seq="2003-0070" severity="High" type="CVE" published="2003-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">VTE, as used by default in gnome-terminal terminal emulator 2.2 and as an option in gnome-terminal 2.0, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://www.iss.net/security_center/static/11414.php" adv="1">terminal-emulator-window-title(11414)</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" adv="1">20030224 Terminal Emulator Security Issues</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-053.html">RHSA-2003:053</ref>
            <ref source="GENTOO" url="http://seclists.org/lists/bugtraq/2003/Mar/0010.html">GLSA-200303-2</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref>
        </refs>
        <vuln_soft>
            <prod vendor="gnome" name="gnome-terminal">
                <vers num="2.1" />
                <vers num="2.1.1" />
                <vers num="2.1.2" />
                <vers num="2.1.3" />
                <vers num="2.1.4" />
                <vers num="2.2" />
                <vers num="2.2.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2003-0071" seq="2003-0071" severity="Low" type="CVE" published="2003-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-10">
        <desc>
            <descript source="cve">The DEC UDK processing feature in the xterm terminal emulator in XFree86 4.2.99.4 and earlier allows attackers to cause a denial of service via a certain character escape sequence that causes the terminal to enter a tight loop.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" url="http://www.iss.net/security_center/static/11415.php" adv="1">terminal-emulator-dec-udk(11415)</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" adv="1">20030224 Terminal Emulator Security Issues</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6950">6950</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-067.html">RHSA-2003:067</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-066.html">RHSA-2003:066</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-065.html">RHSA-2003:065</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-064.html">RHSA-2003:064</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-380">DSA-380</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref>
        </refs>
        <vuln_soft>
            <prod vendor="xfree86_project" name="x11r6">
                <vers num="4.0" />
                <vers num="4.0.1" />
                <vers num="4.0.3" />
                <vers num="4.1.0" />
                <vers num="4.2.0" />
                <vers num="4.2.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0078" seq="2003-0078" severity="Medium" type="CVE" published="2003-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing discrepancy) that may make it easier to launch cryptographic attacks that rely on distinguishing between padding and MAC verification errors, possibly leading to extraction of the original plaintext, aka the "Vaudenay timing attack."</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.openssl.org/news/secadv_20030219.txt" adv="1">http://www.openssl.org/news/secadv_20030219.txt</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104568426824439&amp;w=2" adv="1">20030219 [OpenPKG-SA-2003.013] OpenPKG Security Advisory (openssl)</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/11369.php" adv="1">ssl-cbc-information-leak(11369)</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-253" adv="1">DSA-253</ref>
            <ref source="TRUSTIX" url="http://www.trustix.org/errata/2003/0005">2003-0005</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6884">6884</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-205.html">RHSA-2003:205</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-104.html">RHSA-2003:104</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-082.html">RHSA-2003:082</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-063.html">RHSA-2003:063</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-062.html">RHSA-2003:062</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/3945">3945</ref>
            <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:020">MDKSA-2003:020</ref>
            <ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/engarde_advisory-2874.html">ESA-20030220-005</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-051.shtml">N-051</ref>
            <ref source="GENTOO" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104577183206905&amp;w=2">GLSA-200302-10</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104567627211904&amp;w=2">20030219 OpenSSL 0.9.7a and 0.9.6i released</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000570">CLSA-2003:570</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030501-01-I">20030501-01-I</ref>
            <ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-001.txt.asc">NetBSD-SA2003-001</ref>
        </refs>
        <vuln_soft>
            <prod vendor="openssl" name="openssl">
                <vers num="0.9.1c" />
                <vers num="0.9.2b" />
                <vers num="0.9.3" />
                <vers num="0.9.4" />
                <vers num="0.9.5" />
                <vers num="0.9.5a" />
                <vers num="0.9.6" />
                <vers num="0.9.6a" />
                <vers num="0.9.6b" />
                <vers num="0.9.6c" />
                <vers num="0.9.6d" />
                <vers num="0.9.6e" />
                <vers num="0.9.6g" />
                <vers num="0.9.6h" />
                <vers edition="beta1" num="0.9.7" />
                <vers edition="beta2" num="0.9.7" />
                <vers edition="beta3" num="0.9.7" />
            </prod>
            <prod vendor="freebsd" name="freebsd">
                <vers num="4.2" />
                <vers num="4.3" />
                <vers num="4.4" />
                <vers num="4.5" />
                <vers num="4.6" />
                <vers num="4.7" />
                <vers edition="pre-release" num="4.8" />
                <vers num="5.0" />
            </prod>
            <prod vendor="openbsd" name="openbsd">
                <vers num="3.1" />
                <vers num="3.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2003-0079" seq="2003-0079" severity="Low" type="CVE" published="2003-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-10">
        <desc>
            <descript source="cve">The DEC UDK processing feature in the hanterm (hanterm-xf) terminal emulator before 2.0.5 allows attackers to cause a denial of service via a certain character escape sequence that causes the terminal to enter a tight loop.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" url="http://www.iss.net/security_center/static/11415.php" adv="1">terminal-emulator-dec-udk(11415)</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" adv="1">20030224 Terminal Emulator Security Issues</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6944">6944</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-071.html">RHSA-2003:071</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-070.html">RHSA-2003:070</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4918">4918</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hanterm" name="hanterm-xf">
                <vers num="2.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0063" seq="2003-0063" severity="High" type="CVE" published="2003-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">The xterm terminal emulator in XFree86 4.2.0 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://www.iss.net/security_center/static/11414.php" adv="1">terminal-emulator-window-title(11414)</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" adv="1">20030224 Terminal Emulator Security Issues</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6940">6940</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-067.html">RHSA-2003:067</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-066.html">RHSA-2003:066</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-065.html">RHSA-2003:065</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-064.html">RHSA-2003:064</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-380">DSA-380</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref>
        </refs>
        <vuln_soft>
            <prod vendor="xfree86_project" name="x11r6">
                <vers num="4.0" />
                <vers num="4.0.1" />
                <vers num="4.0.3" />
                <vers num="4.1.0" />
                <vers num="4.2.0" />
                <vers num="4.2.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0064" seq="2003-0064" severity="High" type="CVE" published="2003-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://www.iss.net/security_center/static/11414.php" adv="1">terminal-emulator-window-title(11414)</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" adv="1">20030224 Terminal Emulator Security Issues</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6942">6942</ref>
            <ref source="HP" url="http://www.securityfocus.com/advisories/6236">HPSBUX0401-309</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="hp-ux">
                <vers num="10.20" />
                <vers num="10.24" />
                <vers num="10.26" />
                <vers num="10.30" />
                <vers num="10.34" />
                <vers num="11.00" />
                <vers num="11.04" />
                <vers num="11.11" />
                <vers num="11.20" />
                <vers num="11.22" />
            </prod>
            <prod vendor="ibm" name="aix">
                <vers num="4.3" />
                <vers num="4.3.1" />
                <vers num="4.3.2" />
                <vers num="4.3.3" />
                <vers num="5.1" />
                <vers num="5.2" />
            </prod>
            <prod vendor="sgi" name="irix">
                <vers num="5.0" />
                <vers num="5.0.1" />
                <vers num="5.1" />
                <vers num="5.1.1" />
                <vers num="5.2" />
                <vers num="5.3" />
                <vers num="6.0" />
                <vers num="6.0.1" />
                <vers num="6.1" />
                <vers num="6.2" />
                <vers num="6.3" />
                <vers num="6.4" />
                <vers num="6.5" />
                <vers num="6.5.1" />
                <vers num="6.5.10" />
                <vers num="6.5.10f" />
                <vers num="6.5.10m" />
                <vers num="6.5.11" />
                <vers num="6.5.11f" />
                <vers num="6.5.11m" />
                <vers num="6.5.12" />
                <vers num="6.5.12f" />
                <vers num="6.5.12m" />
                <vers num="6.5.13" />
                <vers num="6.5.13f" />
                <vers num="6.5.13m" />
                <vers num="6.5.14" />
                <vers num="6.5.14f" />
                <vers num="6.5.14m" />
                <vers num="6.5.15" />
                <vers num="6.5.15f" />
                <vers num="6.5.15m" />
                <vers num="6.5.16" />
                <vers num="6.5.16f" />
                <vers num="6.5.16m" />
                <vers num="6.5.17" />
                <vers num="6.5.17f" />
                <vers num="6.5.17m" />
                <vers num="6.5.18" />
                <vers num="6.5.18f" />
                <vers num="6.5.18m" />
                <vers num="6.5.2" />
                <vers num="6.5.2f" />
                <vers num="6.5.2m" />
                <vers num="6.5.3" />
                <vers num="6.5.3f" />
                <vers num="6.5.3m" />
                <vers num="6.5.4" />
                <vers num="6.5.4f" />
                <vers num="6.5.4m" />
                <vers num="6.5.5" />
                <vers num="6.5.5f" />
                <vers num="6.5.5m" />
                <vers num="6.5.6" />
                <vers num="6.5.6f" />
                <vers num="6.5.6m" />
                <vers num="6.5.7" />
                <vers num="6.5.7f" />
                <vers num="6.5.7m" />
                <vers num="6.5.8" />
                <vers num="6.5.8f" />
                <vers num="6.5.8m" />
                <vers num="6.5.9" />
                <vers num="6.5.9f" />
                <vers num="6.5.9m" />
            </prod>
            <prod vendor="sun" name="solaris">
                <vers edition="" num="2.5.1" />
                <vers edition=":x86" num="2.5.1" />
                <vers edition="" num="2.6" />
                <vers edition=":x86" num="2.6" />
                <vers edition="" num="7.0" />
                <vers edition=":x86" num="7.0" />
                <vers edition="" num="8.0" />
                <vers edition=":x86" num="8.0" />
                <vers edition="" num="9.0" />
                <vers edition=":sparc" num="9.0" />
                <vers edition=":x86" num="9.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0065" seq="2003-0065" severity="High" type="CVE" published="2003-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">The uxterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://www.iss.net/security_center/static/11414.php" adv="1">terminal-emulator-window-title(11414)</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" adv="1">20030224 Terminal Emulator Security Issues</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6945">6945</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref>
        </refs>
        <vuln_soft>
            <prod vendor="national_university_of_singapore" name="uxterm">
                <vers num="2.3" />
                <vers num="2.4.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0066" seq="2003-0066" severity="High" type="CVE" published="2003-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">The rxvt terminal emulator 2.7.8 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://www.iss.net/security_center/static/11414.php" adv="1">terminal-emulator-window-title(11414)</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" adv="1">20030224 Terminal Emulator Security Issues</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6953">6953</ref>
            <ref source="GENTOO" url="http://www.securityfocus.com/advisories/5137">200303-16</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-055.html">RHSA-2003:055</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-054.html">RHSA-2003:054</ref>
            <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:003">MDKSA-2003:003</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref>
        </refs>
        <vuln_soft>
            <prod vendor="rxvt" name="rxvt">
                <vers num="2.6.1" />
                <vers num="2.6.2" />
                <vers num="2.6.3" />
                <vers num="2.6.4" />
                <vers num="2.7.5" />
                <vers num="2.7.6" />
                <vers num="2.7.7" />
                <vers num="2.7.8" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0049" seq="2003-0049" severity="High" type="CVE" published="2003-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Apple File Protocol (AFP) in Mac OS X before 10.2.4 allows administrators to log in as other users by using the administrator password.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://docs.info.apple.com/article.html?artnum=61798" adv="1">http://docs.info.apple.com/article.html?artnum=61798</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/11333.php" adv="1">macos-afp-unauthorized-access(11333)</ref>
            <ref source="CONFIRM" url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6860">6860</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1006107">1006107</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apple" name="mac_os_x">
                <vers num="10.2" />
                <vers num="10.2.1" />
                <vers num="10.2.2" />
                <vers num="10.2.3" />
            </prod>
            <prod vendor="apple" name="mac_os_x_server">
                <vers num="10.2" />
                <vers num="10.2.1" />
                <vers num="10.2.2" />
                <vers num="10.2.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0093" seq="2003-0093" severity="Medium" type="CVE" published="2003-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">The RADIUS decoder in tcpdump 3.6.2 and earlier allows remote attackers to cause a denial of service (crash) via an invalid RADIUS packet with a header length field of 0, which causes tcpdump to generate data within an infinite loop.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MISC" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=81585" adv="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=81585</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11324">tcpdump-radius-decoder-dos(11324)</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-214.html">RHSA-2003:214</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-033.html">RHSA-2003:033</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-032.html">RHSA-2003:032</ref>
            <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:027">MDKSA-2003:027</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-261">DSA-261</ref>
        </refs>
        <vuln_soft>
            <prod vendor="lbl" name="tcpdump">
                <vers num="3.4" />
                <vers num="3.4a6" />
                <vers num="3.5" />
                <vers num="3.5.2" />
                <vers num="3.6.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0094" seq="2003-0094" severity="Medium" type="CVE" published="2003-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">A patch for mcookie in the util-linux package for Mandrake Linux 8.2 and 9.0 uses /dev/urandom instead of /dev/random, which causes mcookie to use an entropy source that is more predictable than expected, which may make it easier for certain types of attacks to succeed.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11318" adv="1">utillinux-mcookie-cookie-predictable(11318)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6855">6855</ref>
            <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:016">MDKSA-2003:016</ref>
        </refs>
        <vuln_soft>
            <prod vendor="andries_brouwer" name="util-linux">
                <vers num="2.11n" />
                <vers num="2.11u" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2003-0095" seq="2003-0095" severity="High" type="CVE" published="2003-03-03" CVSS_version="2.0" CVSS_score="10.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Buffer overflow in ORACLE.EXE for Oracle Database Server 9i, 8i, 8.1.7, and 8.0.6 allows remote attackers to execute arbitrary code via a long username that is provided during login, as exploitable through client applications that perform their own authentication, as demonstrated using LOADPSP.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/953746">VU#953746</ref>
            <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-05.html" adv="1">CA-2003-05</ref>
            <ref source="CONFIRM" patch="1" url="http://otn.oracle.com/deploy/security/pdf/2003alert51.pdf" adv="1">http://otn.oracle.com/deploy/security/pdf/2003alert51.pdf</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6849">6849</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/6319">6319</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/11328.php" adv="1">oracle-username-bo(11328)</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-046.shtml">N-046</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104549693426042&amp;w=2" adv="1">20030217 Oracle unauthenticated remote system compromise (#NISR16022003a)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="database_server">
                <vers num="8.0.6" />
                <vers num="9.2.1" />
                <vers num="9.2.2" />
            </prod>
            <prod vendor="oracle" name="oracle8i">
                <vers num="8.1.7" />
                <vers num="8.1.7.1" />
            </prod>
            <prod vendor="oracle" name="oracle9i">
                <vers num="9.0" />
                <vers num="9.0.1" />
                <vers num="9.0.1.2" />
                <vers num="9.0.1.3" />
                <vers num="9.0.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" name="CVE-2003-0096" seq="2003-0096" severity="High" type="CVE" published="2003-03-03" CVSS_version="2.0" CVSS_score="9.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Multiple buffer overflows in Oracle 9i Database release 2, Release 1, 8i, 8.1.7, and 8.0.6 allow remote attackers to execute arbitrary code via (1) a long conversion string argument to the TO_TIMESTAMP_TZ function, (2) a long time zone argument to the TZ_OFFSET function, or (3) a long DIRECTORY parameter to the BFILENAME function.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/840666" adv="1">VU#840666</ref>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/743954">VU#743954</ref>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/663786">VU#663786</ref>
            <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-05.html">CA-2003-05</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6850">6850</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6848">6848</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6847">6847</ref>
            <ref source="MISC" url="http://www.nextgenss.com/advisories/ora-tzofstbo.txt">http://www.nextgenss.com/advisories/ora-tzofstbo.txt</ref>
            <ref source="MISC" url="http://www.nextgenss.com/advisories/ora-tmstmpbo.txt">http://www.nextgenss.com/advisories/ora-tmstmpbo.txt</ref>
            <ref source="MISC" url="http://www.nextgenss.com/advisories/ora-bfilebo.txt">http://www.nextgenss.com/advisories/ora-bfilebo.txt</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/11327.php" adv="1">oracle-totimestamptz-bo(11327)</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/11326.php">oracle-tzoffset-bo(11326)</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/11325.php">oracle-bfilename-directory-bo(11325)</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-046.shtml">N-046</ref>
            <ref source="CONFIRM" url="http://otn.oracle.com/deploy/security/pdf/2003alert50.pdf">http://otn.oracle.com/deploy/security/pdf/2003alert50.pdf</ref>
            <ref source="CONFIRM" url="http://otn.oracle.com/deploy/security/pdf/2003alert49.pdf">http://otn.oracle.com/deploy/security/pdf/2003alert49.pdf</ref>
            <ref source="CONFIRM" url="http://otn.oracle.com/deploy/security/pdf/2003alert48.pdf">http://otn.oracle.com/deploy/security/pdf/2003alert48.pdf</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104550346303295&amp;w=2">20030217 Oracle bfilename function buffer overflow vulnerability (#NISR16022003e)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104549782327321&amp;w=2">20030217 Oracle TZ_OFFSET Remote System Buffer Overrun (#NISR16022003c)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104549743326864&amp;w=2">20030217 Oracle TO_TIMESTAMP_TZ Remote System Buffer Overrun (#NISR16022003b)</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0083.html">20030217 Oracle bfilename function buffer overflow vulnerability (#NISR16022003e)</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0075.html">20030217 Oracle TZ_OFFSET Remote System Buffer Overrun (#NISR16022003c)</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0073.html">20030217 Oracle unauthenticated remote system compromise (#NISR16022003a)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="database_server">
                <vers num="8.0.6" />
                <vers num="9.2.1" />
                <vers num="9.2.2" />
            </prod>
            <prod vendor="oracle" name="oracle8i">
                <vers num="8.1.7" />
                <vers num="8.1.7.1" />
            </prod>
            <prod vendor="oracle" name="oracle9i">
                <vers num="9.0" />
                <vers num="9.0.1" />
                <vers num="9.0.1.2" />
                <vers num="9.0.1.3" />
                <vers num="9.0.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0097" seq="2003-0097" severity="High" type="CVE" published="2003-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Unknown vulnerability in CGI module for PHP 4.3.0 allows attackers to access arbitrary files as the PHP user, and possibly execute PHP code, by bypassing the CGI force redirect settings (cgi.force_redirect or --enable-force-cgi-redirect).</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="GENTOO" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104567042700840&amp;w=2" adv="1">GLSA-200302-09</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104550977011668&amp;w=2" adv="1">20030217 PHP Security Advisory: CGI vulnerability in PHP version 4.3.0</ref>
            <ref source="CONFIRM" url="http://www.slackware.com/changelog/current.php?cpu=i386">http://www.slackware.com/changelog/current.php?cpu=i386</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/11343.php" adv="1">php-cgi-sapi-access(11343)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6875">6875</ref>
            <ref source="GENTOO" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104567137502557&amp;w=2">GLSA-200302-09.1</ref>
        </refs>
        <vuln_soft>
            <prod vendor="php" name="php">
                <vers num="4.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2003-0098" seq="2003-0098" severity="High" type="CVE" published="2003-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Unknown vulnerability in apcupsd before 3.8.6, and 3.10.x before 3.10.5, allows remote attackers to gain root privileges, possibly via format strings in a request to a slave server.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-277" adv="1">DSA-277</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/7200">7200</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_022_apcupsd.html">SuSE-SA:2003:022</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/11334.php">apcupsd-logevent-format-string(11334)</ref>
            <ref source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=137900">http://sourceforge.net/project/shownotes.php?release_id=137900</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1006108">1006108</ref>
            <ref source="MISC" url="http://hsj.shadowpenguin.org/misc/apcupsd_exp.txt">http://hsj.shadowpenguin.org/misc/apcupsd_exp.txt</ref>
            <ref source="CONFIRM" url="http://cvs.sourceforge.net/cgi-bin/viewcvs.cgi/apcupsd/apcupsd/src/apcnisd.c.diff?r1=1.5&amp;r2=1.6" adv="1">http://cvs.sourceforge.net/cgi-bin/viewcvs.cgi/apcupsd/apcupsd/src/apcnisd.c.diff?r1=1.5&amp;r2=1.6</ref>
            <ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-015.0.txt">CSSA-2003-015.0</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6828">6828</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:018">MDKSA-2003:018</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apc" name="apcupsd">
                <vers num="3.10.4" prev="1" />
                <vers num="3.8.5" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2003-0099" seq="2003-0099" severity="High" type="CVE" published="2003-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-10">
        <desc>
            <descript source="cve">Multiple buffer overflows in apcupsd before 3.8.6, and 3.10.x before 3.10.5, may allow attackers to cause a denial of service or execute arbitrary code, related to usage of the vsprintf function.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-277" adv="1">DSA-277</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/7200">7200</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/11491.php" adv="1">apcupsd-vsprintf-multiple-bo(11491)</ref>
            <ref source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=137900" adv="1">http://sourceforge.net/project/shownotes.php?release_id=137900</ref>
            <ref source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=137892">http://sourceforge.net/project/shownotes.php?release_id=137892</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_022_apcupsd.html">SuSE-SA:2003:022</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:018">MDKSA-2003:018</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1006108">1006108</ref>
            <ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-015.0.txt">CSSA-2003-015.0</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apc" name="apcupsd">
                <vers num="3.8.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0100" seq="2003-0100" severity="High" type="CVE" published="2003-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Buffer overflow in Cisco IOS 11.2.x to 12.0.x allows remote attackers to cause a denial of service and possibly execute commands via a large number of OSPF neighbor announcements.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104587206702715&amp;w=2">20030221 Re: Cisco IOS OSPF exploit</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/11373.php" adv="1">cisco-ios-ospf-bo(11373)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104576100719090&amp;w=2">20030220 Cisco IOS OSPF exploit</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6895">6895</ref>
        </refs>
        <vuln_soft>
            <prod vendor="cisco" name="ios">
                <vers num="11.1" />
                <vers num="11.1(13)" />
                <vers num="11.1(13)aa" />
                <vers num="11.1(13)ca" />
                <vers num="11.1(13)ia" />
                <vers num="11.1(15)aa" />
                <vers num="11.1(15)ca" />
                <vers num="11.1(15)ia" />
                <vers num="11.1(16)aa" />
                <vers num="11.1(16)ia" />
                <vers num="11.1(17)cc" />
                <vers num="11.1(17)ct" />
                <vers num="11.1(20)aa4" />
                <vers num="11.1(24a)" />
                <vers num="11.1(24b)" />
                <vers num="11.1(28a)ct" />
                <vers num="11.1(28a)ia" />
                <vers num="11.1(36)ca2" />
                <vers num="11.1(36)cc2" />
                <vers num="11.1(36)cc4" />
                <vers num="11.1(7)aa" />
                <vers num="11.1(7)ca" />
                <vers num="11.1(9)ia" />
                <vers num="11.1aa" />
                <vers num="11.1ca" />
                <vers num="11.1cc" />
                <vers num="11.1ct" />
                <vers num="11.1ia" />
                <vers num="11.2" />
                <vers num="11.2(10)bc" />
                <vers num="11.2(11b)t2" />
                <vers num="11.2(17)" />
                <vers num="11.2(19)gs0.2" />
                <vers num="11.2(19a)gs6" />
                <vers num="11.2(23a)bc1" />
                <vers num="11.2(26)p2" />
                <vers num="11.2(26a)" />
                <vers num="11.2(26b)" />
                <vers num="11.2(4)" />
                <vers num="11.2(4)f" />
                <vers num="11.2(4)f1" />
                <vers num="11.2(4)xa" />
                <vers num="11.2(4)xaf" />
                <vers num="11.2(8)p" />
                <vers num="11.2(8)sa1" />
                <vers num="11.2(8)sa3" />
                <vers num="11.2(8)sa5" />
                <vers num="11.2(8.9)sa6" />
                <vers num="11.2(9)p" />
                <vers num="11.2(9)xa" />
                <vers num="11.2bc" />
                <vers num="11.2f" />
                <vers num="11.2gs" />
                <vers num="11.2p" />
                <vers num="11.2sa" />
                <vers num="11.2wa3" />
                <vers num="11.2wa4" />
                <vers num="11.2xa" />
                <vers num="11.3" />
                <vers num="11.3(1)ed" />
                <vers num="11.3(1)t" />
                <vers num="11.3(11)b" />
                <vers num="11.3(11b)" />
                <vers num="11.3(11b)t2" />
                <vers num="11.3(11c)" />
                <vers num="11.3(2)xa" />
                <vers num="11.3(7)db1" />
                <vers num="11.3(8)db2" />
                <vers num="11.3aa" />
                <vers num="11.3da" />
                <vers num="11.3db" />
                <vers num="11.3ha" />
                <vers num="11.3ma" />
                <vers num="11.3na" />
                <vers num="11.3t" />
                <vers num="11.3wa4" />
                <vers num="11.3xa" />
                <vers num="12.0" />
                <vers num="12.0(1)" />
                <vers num="12.0(1)w" />
                <vers num="12.0(1)xa3" />
                <vers num="12.0(1)xb" />
                <vers num="12.0(1)xe" />
                <vers num="12.0(10)s7" />
                <vers num="12.0(10)w5" />
                <vers num="12.0(10)w5(18f)" />
                <vers num="12.0(10)w5(18g)" />
                <vers num="12.0(10a)" />
                <vers num="12.0(11)s6" />
                <vers num="12.0(11)st4" />
                <vers num="12.0(11a)" />
                <vers num="12.0(12)s3" />
                <vers num="12.0(12a)" />
                <vers num="12.0(13)s6" />
                <vers num="12.0(13)w5(19c)" />
                <vers num="12.0(13)wt6(1)" />
                <vers num="12.0(13a)" />
                <vers num="12.0(14)s7" />
                <vers num="12.0(14)st" />
                <vers num="12.0(14)st3" />
                <vers num="12.0(14)w5(20)" />
                <vers num="12.0(14a)" />
                <vers num="12.0(15)s3" />
                <vers num="12.0(15)s6" />
                <vers num="12.0(15a)" />
                <vers num="12.0(16)s8" />
                <vers num="12.0(16)sc3" />
                <vers num="12.0(16)st1" />
                <vers num="12.0(16)w5(21)" />
                <vers num="12.0(16.06)s" />
                <vers num="12.0(16a)" />
                <vers num="12.0(17)" />
                <vers num="12.0(17)s" />
                <vers num="12.0(17)s4" />
                <vers num="12.0(17)sl2" />
                <vers num="12.0(17)sl6" />
                <vers num="12.0(17)st1" />
                <vers num="12.0(17)st5" />
                <vers num="12.0(17a)" />
                <vers num="12.0(18)s" />
                <vers num="12.0(18)s5" />
                <vers num="12.0(18)st1" />
                <vers num="12.0(18)w5(22b)" />
                <vers num="12.0(18b)" />
                <vers num="12.0(2)" />
                <vers num="12.0(2)xc" />
                <vers num="12.0(2)xd" />
                <vers num="12.0(2)xe" />
                <vers num="12.0(2)xf" />
                <vers num="12.0(2)xg" />
                <vers num="12.0(2b)" />
                <vers num="12.0(3)" />
                <vers num="12.0(3)t2" />
                <vers num="12.0(3d)" />
                <vers num="12.0(4)s" />
                <vers num="12.0(4)t" />
                <vers num="12.0(4)xe" />
                <vers num="12.0(4)xe1" />
                <vers num="12.0(4)xm" />
                <vers num="12.0(4)xm1" />
                <vers num="12.0(5)t" />
                <vers num="12.0(5)t1" />
                <vers num="12.0(5)wc" />
                <vers num="12.0(5)wc2" />
                <vers num="12.0(5)wc2b" />
                <vers num="12.0(5)wc3" />
                <vers num="12.0(5)wc3b" />
                <vers num="12.0(5)wx" />
                <vers num="12.0(5)xe" />
                <vers num="12.0(5)xk" />
                <vers num="12.0(5)xk2" />
                <vers num="12.0(5)xn" />
                <vers num="12.0(5)xn1" />
                <vers num="12.0(5)xs" />
                <vers num="12.0(5)xu" />
                <vers num="12.0(5)yb4" />
                <vers num="12.0(5.1)xp" />
                <vers num="12.0(5.2)xu" />
                <vers num="12.0(5.3)wc1" />
                <vers num="12.0(5.4)wc1" />
                <vers num="12.0(6b)" />
                <vers num="12.0(7)db2" />
                <vers num="12.0(7)dc1" />
                <vers num="12.0(7)s1" />
                <vers num="12.0(7)sc" />
                <vers num="12.0(7)t" />
                <vers num="12.0(7)t2" />
                <vers num="12.0(7)wx5(15a)" />
                <vers num="12.0(7)xe" />
                <vers num="12.0(7)xe2" />
                <vers num="12.0(7)xf" />
                <vers num="12.0(7)xf1" />
                <vers num="12.0(7)xk" />
                <vers num="12.0(7)xk3" />
                <vers num="12.0(7)xv" />
                <vers num="12.0(7.4)s" />
                <vers num="12.0(7a)" />
                <vers num="12.0(8)" />
                <vers num="12.0(8)s1" />
                <vers num="12.0(8.0.2)s" />
                <vers num="12.0(8.3)sc" />
                <vers num="12.0(8a)" />
                <vers num="12.0(9)" />
                <vers num="12.0(9)s" />
                <vers num="12.0(9)s8" />
                <vers num="12.0(9a)" />
                <vers num="12.0da" />
                <vers num="12.0db" />
                <vers num="12.0dc" />
                <vers num="12.0s" />
                <vers num="12.0sc" />
                <vers num="12.0sl" />
                <vers num="12.0sp" />
                <vers num="12.0st" />
                <vers num="12.0sx" />
                <vers num="12.0t" />
                <vers num="12.0w5" />
                <vers num="12.0wc" />
                <vers num="12.0wt" />
                <vers num="12.0wx" />
                <vers num="12.0xa" />
                <vers num="12.0xb" />
                <vers num="12.0xc" />
                <vers num="12.0xd" />
                <vers num="12.0xe" />
                <vers num="12.0xf" />
                <vers num="12.0xg" />
                <vers num="12.0xh" />
                <vers num="12.0xi" />
                <vers num="12.0xj" />
                <vers num="12.0xk" />
                <vers num="12.0xl" />
                <vers num="12.0xm" />
                <vers num="12.0xn" />
                <vers num="12.0xp" />
                <vers num="12.0xq" />
                <vers num="12.0xr" />
                <vers num="12.0xs" />
                <vers num="12.0xu" />
                <vers num="12.0xv" />
                <vers num="12.0xw" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2003-0101" seq="2003-0101" severity="High" type="CVE" published="2003-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-10">
        <desc>
            <descript source="cve">miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage returns (CRLF) in Base-64 encoded strings during Basic authentication, which allows remote attackers to spoof a session ID and gain root privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://marc.theaimsgroup.com/?l=webmin-announce&amp;m=104587858408101&amp;w=2">http://marc.theaimsgroup.com/?l=webmin-announce&amp;m=104587858408101&amp;w=2</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104610300325629&amp;w=2" adv="1">20030224 [SNS Advisory No.62] Webmin/Usermin Session ID Spoofing Vulnerability "Episode 2"</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6915">6915</ref>
            <ref source="MISC" url="http://www.lac.co.jp/security/english/snsadv_e/62_e.html">http://www.lac.co.jp/security/english/snsadv_e/62_e.html</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/11390.php" adv="1">webmin-usermin-root-access(11390)</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-319">DSA-319</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-058.shtml">N-058</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104610336226274&amp;w=2">20030224 GLSA:  usermin (200302-14)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104610245624895&amp;w=2">20030224 Webmin 1.050 - 1.060 remote exploit</ref>
            <ref source="ENGARDE" url="http://archives.neohapsis.com/archives/linux/engarde/2003-q1/0008.html">ESA-20030225-006</ref>
            <ref source="HP" url="http://archives.neohapsis.com/archives/hp/2003-q1/0063.html">HPSBUX0303-250</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030602-01-I">20030602-01-I</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006160">1006160</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:025">MDKSA-2003:025</ref>
            <ref source="CONFIRM" url="http://www.linuxsecurity.com/advisories/gentoo_advisory-2886.html">http://www.linuxsecurity.com/advisories/gentoo_advisory-2886.html</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/8163">8163</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/8115">8115</ref>
        </refs>
        <vuln_soft>
            <prod vendor="engardelinux" name="guardian_digital_webtool">
                <vers num="1.2" />
            </prod>
            <prod vendor="usermin" name="usermin">
                <vers num="0.4" />
                <vers num="0.5" />
                <vers num="0.6" />
                <vers num="0.7" />
                <vers num="0.8" />
                <vers num="0.9" />
                <vers num="0.91" />
                <vers num="0.92" />
                <vers num="0.93" />
                <vers num="0.94" />
                <vers num="0.95" />
                <vers num="0.96" />
                <vers num="0.97" />
                <vers num="0.98" />
                <vers num="0.99" />
            </prod>
            <prod vendor="webmin" name="webmin">
                <vers num="1.0.50" />
                <vers num="1.0.60" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2003-0087" seq="2003-0087" severity="High" type="CVE" published="2003-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-10">
        <desc>
            <descript source="cve">Buffer overflow in libIM library (libIM.a) for National Language Support (NLS) on AIX 4.3 through 5.2 allows local users to gain privileges via several possible attack vectors, including a long -im argument to aixterm.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="MISC" patch="1" url="http://www.idefense.com/advisory/02.12.03.txt" adv="1">http://www.idefense.com/advisory/02.12.03.txt</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11309">aix-aixterm-libim-bo(11309)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6840">6840</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/7996">7996</ref>
            <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY40320&amp;apar=only">IY40320</ref>
            <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY40317&amp;apar=only">IY40317</ref>
            <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY40307&amp;apar=only">IY40307</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104508833214691&amp;w=2">20030212 libIM.a buffer overflow vulnerability</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104508375107938&amp;w=2">20030212 iDEFENSE Security Advisory 02.12.03: Buffer Overflow in AIX libIM.a</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0066.html">20030212 iDEFENSE Security Advisory 02.12.03: Buffer Overflow in AIX libIM.a</ref>
        </refs>
        <vuln_soft>
            <prod vendor="national_language_support" name="libim">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2003-0088" seq="2003-0088" severity="High" type="CVE" published="2003-03-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-10">
        <desc>
            <descript source="cve">TruBlueEnvironment for MacOS 10.2.3 and earlier allows local users to overwrite or create arbitrary files and gain root privileges by setting a certain environment variable that is used to write debugging information.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="ATSTAKE" patch="1" url="http://www.atstake.com/research/advisories/2003/a021403-1.txt" adv="1">A021403-1</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/11332.php" adv="1">macos-trublueenvironment-gain-privileges(11332)</ref>
            <ref source="CONFIRM" url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref>
            <ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=61798">http://docs.info.apple.com/article.html?artnum=61798</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6859">6859</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apple" name="mac_os_x">
                <vers num="10.2" />
                <vers num="10.2.1" />
                <vers num="10.2.2" />
                <vers num="10.2.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2003-1077" seq="2003-1077" severity="Low" type="CVE" published="2003-03-05" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-10">
        <desc>
            <descript source="cve">Unknown vulnerability in UFS for Solaris 9 for SPARC, with logging enabled, allows local users to cause a denial of service (UFS file system hang).</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-51300-1" adv="1">51300</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/8234/" adv="1">8234</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11481" adv="1">solaris-ufs-logging-dos(11481)</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006233">1006233</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/7032">7032</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers edition="" num="9.0" />
                <vers edition=":sparc" num="9.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0103" seq="2003-0103" severity="Medium" type="CVE" published="2003-03-07" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Format string vulnerability in Nokia 6210 handset allows remote attackers to cause a denial of service (crash, lockup, or restart) via a Multi-Part vCard with fields containing a large number of format string specifiers.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/6952" adv="1">6952</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/11421.php">nokia-6210-vcard-dos(11421)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="nokia" name="6210_handset">
                <vers num="5.27" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0107" seq="2003-0107" severity="High" type="CVE" published="2003-03-07" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Buffer overflow in the gzprintf function in zlib 1.1.4, when zlib is compiled without vsnprintf or when long inputs are truncated using vsnprintf, allows attackers to cause a denial of service or possibly execute arbitrary code.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/142121">VU#142121</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/11381.php" adv="1">zlib-gzprintf-bo(11381)</ref>
            <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/312869">20030222 buffer overrun in zlib 1.1.4</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104610337726297&amp;w=2">20030223 poc zlib sploit just for fun :)</ref>
            <ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00038.html">http://lists.apple.com/mhonarc/security-announce/msg00038.html</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6913">6913</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-081.html">RHSA-2003:081</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-079.html">RHSA-2003:079</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/6599">6599</ref>
            <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:033">MDKSA-2003:033</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F57405">57405</ref>
            <ref source="GENTOO" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104887247624907&amp;w=2">GLSA-200303-25</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104620610427210&amp;w=2">20030225 [sorcerer-spells] ZLIB-SORCERER2003-02-25</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104610536129508&amp;w=2">20030224 Re: buffer overrun in zlib 1.1.4</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com/atualizacoes/?id=a&amp;anuncio=000619">CLSA-2003:619</ref>
            <ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-004.txt.asc">NetBSD-SA2003-004</ref>
            <ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-011.0.txt">CSSA-2003-011.0</ref>
        </refs>
        <vuln_soft>
            <prod vendor="gnu" name="zlib">
                <vers num="1.1.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0108" seq="2003-0108" severity="Medium" type="CVE" published="2003-03-07" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">isakmp_sub_print in tcpdump 3.6 through 3.7.1 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed ISAKMP packet to UDP port 500, which causes tcpdump to enter an infinite loop.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/6974" adv="1">6974</ref>
            <ref source="MISC" patch="1" url="http://www.idefense.com/advisory/02.27.03.txt" adv="1">http://www.idefense.com/advisory/02.27.03.txt</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-255" adv="1">DSA-255</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/11434.php" adv="1">tcpdump-isakmp-dos(11434)</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-214.html">RHSA-2003:214</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-085.html">RHSA-2003:085</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-032.html">RHSA-2003:032</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_015_tcpdump.html">SuSE-SA:2003:0015</ref>
            <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:027">MDKSA-2003:027</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104678787109030&amp;w=2">20030304 [OpenPKG-SA-2003.014] OpenPKG Security Advisory (tcpdump)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104637420104189&amp;w=2">20030227 iDEFENSE Security Advisory 02.27.03: TCPDUMP Denial of Service Vulnerability in ISAKMP Packet Parsin</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000629">CLA-2003:629</ref>
        </refs>
        <vuln_soft>
            <prod vendor="lbl" name="tcpdump">
                <vers num="3.5.2" />
                <vers num="3.6.2" />
                <vers num="3.7" />
                <vers num="3.7.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" name="CVE-2003-0120" seq="2003-0120" severity="Low" type="CVE" published="2003-03-07" CVSS_version="2.0 incomplete approximation" CVSS_score="1.2" modified="2008-09-05">
        <desc>
            <descript source="cve">adb2mhc in the mhc-utils package before 0.25+20010625-7.1 allows local users to overwrite arbitrary files via a symlink attack on a default temporary directory with a predictable name.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <race />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-256" adv="1">DSA-256</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6978">6978</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/11439.php">mhc-adb2mhc-insecure-tmp(11439)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mhc-utils" name="mhc-utils">
                <vers num="0.25_snap2001-06-25" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0050" seq="2003-0050" severity="High" type="CVE" published="2003-03-07" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via shell metacharacters.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104618904330226&amp;w=2" adv="1">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/11401.php" adv="1">quicktime-darwin-command-execution(11401)</ref>
            <ref source="CONFIRM" url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6954">6954</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apple" name="darwin_streaming_server">
                <vers num="4.1.2" />
            </prod>
            <prod vendor="apple" name="quicktime_streaming_server">
                <vers num="4.1.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0051" seq="2003-0051" severity="Medium" type="CVE" published="2003-03-07" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to obtain the physical path of the server's installation path via a NULL file parameter.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104618904330226&amp;w=2" adv="1">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/11402.php" adv="1">quicktime-darwin-path-disclosure(11402)</ref>
            <ref source="CONFIRM" url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6956">6956</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apple" name="darwin_streaming_server">
                <vers num="4.1.2" />
            </prod>
            <prod vendor="apple" name="quicktime_streaming_server">
                <vers num="4.1.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0052" seq="2003-0052" severity="Medium" type="CVE" published="2003-03-07" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to list arbitrary directories.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104618904330226&amp;w=2" adv="1">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/11403.php" adv="1">quicktime-darwin-directory-disclosure(11403)</ref>
            <ref source="CONFIRM" url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6955">6955</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apple" name="darwin_streaming_server">
                <vers num="4.1.2" />
            </prod>
            <prod vendor="apple" name="quicktime_streaming_server">
                <vers num="4.1.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2003-0053" seq="2003-0053" severity="Medium" type="CVE" published="2003-03-07" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-10">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to insert arbitrary script via the filename parameter, which is inserted into an error message.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104618904330226&amp;w=2" adv="1">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/11404.php" adv="1">quicktime-darwin-parsexml-xss(11404)</ref>
            <ref source="CONFIRM" url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6958">6958</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apple" name="darwin_streaming_server">
                <vers num="4.1.2" />
            </prod>
            <prod vendor="apple" name="quicktime_streaming_server">
                <vers num="4.1.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0054" seq="2003-0054" severity="High" type="CVE" published="2003-03-07" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute certain code via a request to port 7070 with the script in an argument to the rtsp DESCRIBE method, which is inserted into a log file and executed when the log is viewed using a browser.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104618904330226&amp;w=2" adv="1">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/11405.php" adv="1">quicktime-darwin-describe-xss(11405)</ref>
            <ref source="CONFIRM" url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6960">6960</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apple" name="darwin_streaming_server">
                <vers num="4.1.2" />
            </prod>
            <prod vendor="apple" name="quicktime_streaming_server">
                <vers num="4.1.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0055" seq="2003-0055" severity="High" type="CVE" published="2003-03-07" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Buffer overflow in the MP3 broadcasting module of Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via a long filename.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104618904330226&amp;w=2" adv="1">20030224 QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/11406.php" adv="1">quicktime-darwin-mp3-bo(11406)</ref>
            <ref source="CONFIRM" url="http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt">http://lists.apple.com/archives/security-announce/2003/Feb/25/applesa20030225macosx102.txt</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6957">6957</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apple" name="quicktime_darwin_mp3_broadcaster">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" name="CVE-2003-0009" seq="2003-0009" severity="Medium" type="CVE" published="2003-03-07" CVSS_version="2.0 incomplete approximation" CVSS_score="6.8" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in Help and Support Center for Microsoft Windows Me allows remote attackers to execute arbitrary script in the Local Computer security context via an hcp:// URL with the malicious script in the topic parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/489721">VU#489721</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/6966" adv="1">6966</ref>
            <ref source="MS" patch="1" url="http://www.microsoft.com/technet/security/bulletin/ms03-006.asp" adv="1">MS03-006</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104636383018686&amp;w=2" adv="1">20030227 MS-Windows ME IE/Outlook/HelpCenter critical vulnerability</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/11425.php" adv="1">winme-hsc-hcp-bo(11425)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/6074">6074</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-047.shtml">N-047</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="windows_me">
                <vers num="" />
            </prod>
            <prod vendor="microsoft" name="windows_xp">
                <vers edition=":home" num="" />
                <vers edition="gold" num="" />
                <vers edition="gold:professional" num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2003-0033" seq="2003-0033" severity="High" type="CVE" published="2003-03-07" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in the RPC preprocessor for Snort 1.8 and 1.9.x before 1.9.1 allows remote attackers to execute arbitrary code via fragmented RPC packets.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/916785" adv="1">VU#916785</ref>
            <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-13.html">CA-2003-13</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/6963" adv="1">6963</ref>
            <ref source="XF" patch="1" url="http://www.iss.net/security_center/static/10956.php" adv="1">snort-rpc-fragment-bo(10956)</ref>
            <ref source="ISS" patch="1" url="http://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21951" adv="1">20030303 Snort RPC Preprocessing Vulnerability</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4418">4418</ref>
            <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:029">MDKSA-2003:029</ref>
            <ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/engarde_advisory-2944.html">ESA-20030307-007</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-297">DSA-297</ref>
            <ref source="GENTOO" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105154530427824&amp;w=2">GLSA-200304-06</ref>
            <ref source="GENTOO" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104716001503409&amp;w=2">GLSA-200303-6.1</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104673386226064&amp;w=2">20030303 Snort RPC Vulnerability (fwd)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="snort" name="snort">
                <vers num="1.8.0" />
                <vers num="1.8.1" />
                <vers num="1.8.2" />
                <vers num="1.8.3" />
                <vers num="1.8.4" />
                <vers num="1.8.5" />
                <vers num="1.8.6" />
                <vers num="1.8.7" />
                <vers num="1.9.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0020" seq="2003-0020" severity="Medium" type="CVE" published="2003-03-18" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/9930" adv="1">9930</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/11412.php" adv="1">apache-esc-seq-injection(11412)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2" adv="1">20030224 Terminal Emulator Security Issues</ref>
            <ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0027">2004-0027</ref>
            <ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0017">2004-0017</ref>
            <ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2004&amp;m=slackware-security.529643">SSA:2004-133</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-244.html">RHSA-2003:244</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-243.html">RHSA-2003:243</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-139.html">RHSA-2003:139</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-104.html">RHSA-2003:104</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-083.html">RHSA-2003:083</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-082.html">RHSA-2003:082</ref>
            <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:050">MDKSA-2003:050</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57628-1">57628</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101555-1">101555</ref>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200405-22.xml">GLSA-200405-22</ref>
            <ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108731648532365&amp;w=2">SSRT4717</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108437852004207&amp;w=2">20040512 [OpenPKG-SA-2004.021] OpenPKG Security Advisory (apache)</ref>
            <ref source="APPLE" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108369640424244&amp;w=2">APPLE-SA-2004-05-03</ref>
            <ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2004:046">MDKSA-2004:046</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html">20030224 Terminal Emulator Security Issues</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4114" sig="1">oval:org.mitre.oval:def:4114</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:150" sig="1">oval:org.mitre.oval:def:150</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100109" sig="1">oval:org.mitre.oval:def:100109</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apache" name="http_server">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0067" seq="2003-0067" severity="High" type="CVE" published="2003-03-18" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">The aterm terminal emulator 0.42 allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://www.iss.net/security_center/static/11414.php" adv="1">terminal-emulator-window-title(11414)</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" adv="1">20030224 Terminal Emulator Security Issues</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref>
        </refs>
        <vuln_soft>
            <prod vendor="aterm" name="aterm">
                <vers num="0.42" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0081" seq="2003-0081" severity="High" type="CVE" published="2003-03-18" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Format string vulnerability in packet-socks.c of the SOCKS dissector for Ethereal 0.8.7 through 0.9.9 allows remote attackers to execute arbitrary code via SOCKS packets containing format string specifiers.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7049" adv="1">7049</ref>
            <ref source="MISC" patch="1" url="http://www.guninski.com/etherre.html" adv="1">http://www.guninski.com/etherre.html</ref>
            <ref source="CONFIRM" patch="1" url="http://www.ethereal.com/appnotes/enpa-sa-00008.html" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00008.html</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-258" adv="1">DSA-258</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11497">ethereal-socks-format-string(11497)</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-077.html">RHSA-2003:077</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-076.html">RHSA-2003:076</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_019_ethereal.html">SuSE-SA:2003:019</ref>
            <ref source="GENTOO" url="http://www.linuxsecurity.com/advisories/gentoo_advisory-2949.html">GLSA-200303-10</ref>
            <ref source="FULLDISC" url="http://seclists.org/lists/fulldisclosure/2003/Mar/0080.html">20030308 Ethereal format string bug, yet still ethereal much better than windows</ref>
            <ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2003:051">MDKSA-2003:051</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000627">CLSA-2003:627</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:54" sig="1">oval:org.mitre.oval:def:54</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ethereal_group" name="ethereal">
                <vers num="0.8.18" />
                <vers num="0.9.0" />
                <vers num="0.9.1" />
                <vers num="0.9.2" />
                <vers num="0.9.3" />
                <vers num="0.9.4" />
                <vers num="0.9.5" />
                <vers num="0.9.6" />
                <vers num="0.9.7" />
                <vers num="0.9.8" />
                <vers num="0.9.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0069" seq="2003-0069" severity="High" type="CVE" published="2003-03-18" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">The PuTTY terminal emulator 0.53 allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://www.iss.net/security_center/static/11414.php" adv="1">terminal-emulator-window-title(11414)</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" adv="1">20030224 Terminal Emulator Security Issues</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/8347">8347</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref>
        </refs>
        <vuln_soft>
            <prod vendor="putty" name="putty">
                <vers num="0.53" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0077" seq="2003-0077" severity="High" type="CVE" published="2003-03-18" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">The hanterm (hanterm-xf) terminal emulator 2.0.5 and earlier, and possibly later versions, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://www.iss.net/security_center/static/11414.php" adv="1">terminal-emulator-window-title(11414)</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html" adv="1">20030224 Terminal Emulator Security Issues</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-071.html">RHSA-2003:071</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-070.html">RHSA-2003:070</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4917">4917</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104612710031920&amp;w=2">20030224 Terminal Emulator Security Issues</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hanterm" name="hanterm-xf">
                <vers num="2.0.5" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0121" seq="2003-0121" severity="High" type="CVE" published="2003-03-18" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Clearswift MAILsweeper 4.x allows remote attackers to bypass attachment detection via an attachment that does not specify a MIME-Version header field, which is processed by some mail clients.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7044" adv="1">7044</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104716030503607&amp;w=2" adv="1">20030307 Corsaire Security Advisory - Clearswift MAILsweeper MIME attachment evasion issue</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/316311">20030326 RE: Corsaire Security Advisory - Clearswift MAILsweeper MIME attachment evasion issue</ref>
        </refs>
        <vuln_soft>
            <prod vendor="clearswift" name="mailsweeper">
                <vers num="4.0" />
                <vers num="4.1" />
                <vers num="4.2" />
                <vers num="4.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0122" seq="2003-0122" severity="Medium" type="CVE" published="2003-03-18" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in Notes server before Lotus Notes R4, R5 before 5.0.11, and early R6 allows remote attackers to execute arbitrary code via a long distinguished name (DN) during NotesRPC authentication and an outer field length that is less than that of the DN field.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/433489">VU#433489</ref>
            <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-11.html">CA-2003-11</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7037" adv="1">7037</ref>
            <ref source="CONFIRM" patch="1" url="http://www-1.ibm.com/support/docview.wss?rs=482&amp;q=Domino&amp;uid=swg21105101" adv="1">http://www-1.ibm.com/support/docview.wss?rs=482&amp;q=Domino&amp;uid=swg21105101</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104757319829443&amp;w=2" adv="1">20030313 R7-0010: Buffer Overflow in Lotus Notes Protocol Authentication</ref>
            <ref source="MISC" url="http://www.rapid7.com/advisories/R7-0010.html">http://www.rapid7.com/advisories/R7-0010.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11526">lotus-nrpc-bo(11526)</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-065.shtml">N-065</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0125.html">20030313 R7-0010: Buffer Overflow in Lotus Notes Protocol Authentication</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ibm" name="lotus_domino">
                <vers num="4.6.1" />
                <vers num="4.6.3" />
                <vers num="4.6.4" />
                <vers num="5.0" />
                <vers num="5.0.1" />
                <vers num="5.0.10" />
                <vers num="5.0.11" />
                <vers num="5.0.2" />
                <vers num="5.0.3" />
                <vers edition="" num="5.0.4" />
                <vers edition=":solaris" num="5.0.4" />
                <vers num="5.0.4a" />
                <vers edition="" num="5.0.5" />
                <vers edition=":" num="5.0.5" />
                <vers edition="::french" num="5.0.5" />
                <vers num="5.0.6" />
                <vers num="5.0.6a" />
                <vers edition="" num="5.0.7" />
                <vers edition=":solaris" num="5.0.7" />
                <vers num="5.0.7a" />
                <vers edition="" num="5.0.8" />
                <vers edition=":" num="5.0.8" />
                <vers edition="::french" num="5.0.8" />
                <vers num="5.0.8a" />
                <vers num="5.0.9" />
                <vers num="5.0.9a" />
            </prod>
            <prod vendor="ibm" name="lotus_notes_client">
                <vers num="5.0" />
                <vers num="5.0.1" />
                <vers num="5.0.10" />
                <vers num="5.0.11" />
                <vers num="5.0.2" />
                <vers num="5.0.3" />
                <vers num="5.0.4" />
                <vers num="5.0.5" />
                <vers num="5.0.9a" />
                <vers num="r5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0123" seq="2003-0123" severity="Medium" type="CVE" published="2003-03-18" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in Web Retriever client for Lotus Notes/Domino R4.5 through R6 allows remote malicious web servers to cause a denial of service (crash) via a long HTTP status line.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/411489">VU#411489</ref>
            <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-11.html">CA-2003-11</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7038" adv="1">7038</ref>
            <ref source="CONFIRM" patch="1" url="http://www-1.ibm.com/support/docview.wss?rs=482&amp;q=Domino&amp;uid=swg21105060" adv="1">http://www-1.ibm.com/support/docview.wss?rs=482&amp;q=Domino&amp;uid=swg21105060</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104757545500368&amp;w=2" adv="1">20030313 R7-0011: Lotus Notes/Domino Web Retriever HTTP Status Buffer Overflow</ref>
            <ref source="MISC" url="http://www.rapid7.com/advisories/R7-0011.html">http://www.rapid7.com/advisories/R7-0011.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11525">lotus-web-retriever-bo(11525)</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-065.shtml">N-065</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ibm" name="lotus_domino">
                <vers num="4.6.1" />
                <vers num="4.6.3" />
                <vers num="4.6.4" />
                <vers num="5.0" />
                <vers num="5.0.1" />
                <vers num="5.0.10" />
                <vers num="5.0.11" />
                <vers num="5.0.2" />
                <vers num="5.0.3" />
                <vers edition="" num="5.0.4" />
                <vers edition=":solaris" num="5.0.4" />
                <vers num="5.0.4a" />
                <vers edition="" num="5.0.5" />
                <vers edition=":" num="5.0.5" />
                <vers edition="::french" num="5.0.5" />
                <vers num="5.0.6" />
                <vers num="5.0.6a" />
                <vers edition="" num="5.0.7" />
                <vers edition=":solaris" num="5.0.7" />
                <vers num="5.0.7a" />
                <vers edition="" num="5.0.8" />
                <vers edition=":" num="5.0.8" />
                <vers edition="::french" num="5.0.8" />
                <vers num="5.0.8a" />
                <vers num="5.0.9" />
                <vers num="5.0.9a" />
            </prod>
            <prod vendor="ibm" name="lotus_notes_client">
                <vers num="5.0" />
                <vers num="5.0.1" />
                <vers num="5.0.10" />
                <vers num="5.0.11" />
                <vers num="5.0.2" />
                <vers num="5.0.3" />
                <vers num="5.0.4" />
                <vers num="5.0.5" />
                <vers num="5.0.9a" />
                <vers num="r5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2003-0124" seq="2003-0124" severity="Medium" type="CVE" published="2003-03-18" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">man before 1.5l allows attackers to execute arbitrary code via a malformed man file with improper quotes, which causes the my_xsprintf function to return a string with the value "unsafe," which is then executed as a program via a system call if it is in the search path of the user who runs man.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7066" adv="1">7066</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104740927915154&amp;w=2" adv="1">20030311 Vulnerability in man &lt; 1.5l</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11512">man-myxsprintf-code-execution(11512)</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-134.html">RHSA-2003:134</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-133.html">RHSA-2003:133</ref>
            <ref source="GENTOO" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104802285112752&amp;w=2">GLSA-200303-13</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000620">CLSA-2003:620</ref>
        </refs>
        <vuln_soft>
            <prod vendor="andries_brouwer" name="man">
                <vers num="1.5h1" />
                <vers num="1.5i" />
                <vers num="1.5i2" />
                <vers num="1.5j" />
                <vers num="1.5k" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0125" seq="2003-0125" severity="Medium" type="CVE" published="2003-03-18" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in the web interface for SOHO Routefinder 550 before firmware 4.63 allows remote attackers to cause a denial of service (reboot) and execute arbitrary code via a long GET /OPTIONS value.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MISC" patch="1" url="http://www.krusesecurity.dk/advisories/routefind550bof.txt" adv="1">http://www.krusesecurity.dk/advisories/routefind550bof.txt</ref>
            <ref source="CONFIRM" url="ftp://ftp.multitech.com/Routers/RF550VPN.TXT" adv="1">ftp://ftp.multitech.com/Routers/RF550VPN.TXT</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11514">routefinder-vpn-options-bo(11514)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/7067">7067</ref>
        </refs>
        <vuln_soft>
            <prod vendor="multitech" name="routefinder_550_vpn">
                <vers num="4.63" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0126" seq="2003-0126" severity="High" type="CVE" published="2003-03-18" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">The web interface for SOHO Routefinder 550 firmware 4.63 and earlier, and possibly later versions, has a default "admin" account with a blank password, which could allow attackers on the LAN side to conduct unauthorized activities.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MISC" patch="1" url="http://www.krusesecurity.dk/advisories/routefind550bof.txt" adv="1">http://www.krusesecurity.dk/advisories/routefind550bof.txt</ref>
        </refs>
        <vuln_soft>
            <prod vendor="multitech" name="routefinder_550_vpn">
                <vers num="4.63" prev="1" />
                <vers num="4.64_beta" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0104" seq="2003-0104" severity="Medium" type="CVE" published="2003-03-18" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Directory traversal vulnerability in PeopleTools 8.10 through 8.18, 8.40, and 8.41 allows remote attackers to overwrite arbitrary files via the SchedulerTransfer servlet.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7053" adv="1">7053</ref>
            <ref source="XF" patch="1" url="http://www.iss.net/security_center/static/10962.php" adv="1">peoplesoft-schedulertransfer-create-files(10962)</ref>
            <ref source="ISS" patch="1" url="http://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21999" adv="1">20030310 PeopleSoft PeopleTools Remote Command Execution Vulnerability</ref>
        </refs>
        <vuln_soft>
            <prod vendor="peoplesoft" name="peopletools">
                <vers num="8.10" />
                <vers num="8.11" />
                <vers num="8.12" />
                <vers num="8.13" />
                <vers num="8.14" />
                <vers num="8.15" />
                <vers num="8.16" />
                <vers num="8.17" />
                <vers num="8.18" />
                <vers num="8.40" />
                <vers num="8.41" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2003-0102" seq="2003-0102" severity="Medium" type="CVE" published="2003-03-18" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-10">
        <desc>
            <descript source="cve">Buffer overflow in tryelf() in readelf.c of the file command allows attackers to execute arbitrary code as the user running file, possibly via a large entity size value in an ELF header (elfhdr.e_shentsize).</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/611865">VU#611865</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7008" adv="1">7008</ref>
            <ref source="MISC" patch="1" url="http://www.idefense.com/advisory/03.04.03.txt" adv="1">http://www.idefense.com/advisory/03.04.03.txt</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11469">file-afctr-read-bo(11469)</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-087.html">RHSA-2003:087</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-086.html">RHSA-2003:086</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_017_file.html">SuSE-SA:2003:017</ref>
            <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:030">MDKSA-2003:030</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-260">DSA-260</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104680706201721&amp;w=2">20030304 iDEFENSE Security Advisory 03.04.03: Locally Exploitable Buffer Overflow in file(1)</ref>
            <ref source="IMMUNIX" url="http://lwn.net/Alerts/34908/">IMNX-2003-7+-012-01</ref>
            <ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-003.txt.asc">NetBSD-SA2003-003</ref>
        </refs>
        <vuln_soft>
            <prod vendor="file" name="file">
                <vers num="3.28" />
                <vers num="3.30" />
                <vers num="3.32" />
                <vers num="3.33" />
                <vers num="3.34" />
                <vers num="3.35" />
                <vers num="3.36" />
                <vers num="3.37" />
                <vers num="3.39" />
                <vers num="3.40" />
            </prod>
            <prod vendor="netbsd" name="netbsd">
                <vers num="1.5" />
                <vers num="1.5.1" />
                <vers num="1.5.2" />
                <vers num="1.5.3" />
                <vers num="1.6" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2003-0030" seq="2003-0030" severity="High" type="CVE" published="2003-03-18" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflows in protegrity.dll of Protegrity Secure.Data Extension Feature (SEF) before 2.2.3.9 allow attackers with SQL access to execute arbitrary code via the extended stored procedures (1) xp_pty_checkusers, (2) xp_pty_insert, or (3) xp_pty_select.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/247545" adv="1">VU#247545</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/7085" adv="1">7085</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/7084" adv="1">7084</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/7083" adv="1">7083</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104758650516677&amp;w=2" adv="1">20030313 Protegrity buffer overflow</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/8294">8294</ref>
        </refs>
        <vuln_soft>
            <prod vendor="protegrity" name="secure.data">
                <vers num="2.2.3.7" />
                <vers num="2.2.3.8" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0137" seq="2003-0137" severity="Medium" type="CVE" published="2003-03-18" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">SNMP daemon in the DX200 based network element for Nokia Serving GPRS support node (SGSN) allows remote attackers to read SNMP options via arbitrary community strings.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2003/a031303-2.txt" adv="1">A031303-2</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/8301">8301</ref>
        </refs>
        <vuln_soft>
            <prod vendor="nokia" name="sgsn_dx200">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2003-0143" seq="2003-0143" severity="High" type="CVE" published="2003-03-18" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">The pop_msg function in qpopper 4.0.x before 4.0.5fc2 does not null terminate a message buffer after a call to Qvsnprintf, which could allow authenticated users to execute arbitrary code via a buffer overflow in a mdef command with a long macro name.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7058" adv="1">7058</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-259" adv="1">DSA-259</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11516" adv="1">qpopper-popmsg-macroname-bo(11516)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104739841223916&amp;w=2" adv="1">20030310 QPopper 4.0.x buffer overflow vulnerability</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_018_qpopper.html">SuSE-SA:2003:018</ref>
            <ref source="GENTOO" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104792541215354&amp;w=2">GLSA-200303-12</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104768137314397&amp;w=2">20030314 [OpenPKG-SA-2003.018] OpenPKG Security Advisory (qpopper)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104748775900481&amp;w=2">20030312 Re: QPopper 4.0.x buffer overflow vulnerability</ref>
        </refs>
        <vuln_soft>
            <prod vendor="qualcomm" name="qpopper">
                <vers num="4.0.1" />
                <vers num="4.0.2" />
                <vers num="4.0.3" />
                <vers num="4.0.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2003-1095" seq="2003-1095" severity="Medium" type="CVE" published="2003-03-18" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">BEA WebLogic Server and Express 7.0 and 7.0.0.1, when using "memory" session persistence for web applications, does not clear authentication information when a web application is redeployed, which could allow users of that application to gain access without having to re-authenticate.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/691153" adv="1">VU#691153</ref>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/11555" adv="1">weblogic-app-reauthentication-bypass(11555)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7130" adv="1">7130</ref>
        </refs>
        <vuln_soft>
            <prod vendor="bea" name="weblogic_server">
                <vers edition="" num="7.0" />
                <vers edition=":win32" num="7.0" />
                <vers edition="sp1" num="7.0" />
                <vers edition="sp1:win32" num="7.0" />
                <vers edition="" num="7.0.0.1" />
                <vers edition=":win32" num="7.0.0.1" />
                <vers edition="sp1" num="7.0.0.1" />
                <vers edition="sp1:win32" num="7.0.0.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2003-1203" seq="2003-1203" severity="Medium" type="CVE" published="2003-03-18" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-10">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php for Mambo Site Server 4.0.10 allows remote attackers to execute script on other clients via the ?option parameter.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11601" adv="1">mambo-option-index-xss(11601)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/7135">7135</ref>
            <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2003-03/0275.html">20030318 Some XSS vulns</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mambo" name="mambo_site_server">
                <vers num="4.0.10" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-1201" seq="2003-1201" severity="Medium" type="CVE" published="2003-03-20" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">ldbm_back_exop_passwd in the back-ldbm backend in passwd.c for OpenLDAP 2.1.12 and earlier, when the slap_passwd_parse function does not return LDAP_SUCCESS, attempts to free an uninitialized pointer, which allows remote attackers to cause a denial of service (segmentation fault).</descript>
        </desc>
        <sols>
            <sol source="nvd">This was fixed in OpenLDAP version 2.1.17.</sol>
        </sols>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7656">7656</ref>
            <ref source="CONFIRM" patch="1" url="http://www.openldap.org/its/index.cgi?findid=2390">http://www.openldap.org/its/index.cgi?findid=2390</ref>
            <ref source="GENTOO" patch="1" url="http://security.gentoo.org/glsa/glsa-200403-12.xml">GLSA-200403-12</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/9203">9203</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/11261">11261</ref>
            <ref source="CONECTIVA" patch="1" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000685">CLSA-2003:685</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/12520" adv="1">openldap-back-ldbm-dos(12520)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/17000">17000</ref>
        </refs>
        <vuln_soft>
            <prod vendor="openldap" name="openldap">
                <vers num="2.0" />
                <vers num="2.0.1" />
                <vers num="2.0.10" />
                <vers num="2.0.11" />
                <vers num="2.0.11_11" />
                <vers num="2.0.11_11s" />
                <vers num="2.0.11_9" />
                <vers num="2.0.12" />
                <vers num="2.0.13" />
                <vers num="2.0.14" />
                <vers num="2.0.15" />
                <vers num="2.0.16" />
                <vers num="2.0.17" />
                <vers num="2.0.18" />
                <vers num="2.0.19" />
                <vers num="2.0.2" />
                <vers num="2.0.20" />
                <vers num="2.0.21" />
                <vers num="2.0.22" />
                <vers num="2.0.23" />
                <vers num="2.0.25" />
                <vers num="2.0.27" />
                <vers num="2.0.3" />
                <vers num="2.0.4" />
                <vers num="2.0.5" />
                <vers num="2.0.6" />
                <vers num="2.0.7" />
                <vers num="2.0.8" />
                <vers num="2.0.9" />
                <vers num="2.1.10" />
                <vers num="2.1.11" />
                <vers num="2.1.12" />
                <vers num="2.1.13" />
                <vers num="2.1.14" />
                <vers num="2.1.15" />
                <vers num="2.1.16" />
                <vers num="2.1.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0138" seq="2003-0138" severity="High" type="CVE" published="2003-03-24" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Version 4 of the Kerberos protocol (krb4), as used in Heimdal and other packages, allows an attacker to impersonate any principal in a realm via a chosen-plaintext attack.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/623217" adv="1">VU#623217</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-266" adv="1">DSA-266</ref>
            <ref source="CONFIRM" patch="1" url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txt" adv="1">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txt</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-091.html">RHSA-2003:091</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-052.html">RHSA-2003:052</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-051.html">RHSA-2003:051</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-273">DSA-273</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-269">DSA-269</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/7113">7113</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/316960/30/25250/threaded">20030331 GLSA: krb5 &amp; mit-krb5 (200303-28)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104791775804776&amp;w=2">20030317 MITKRB5-SA-2003-004: Cryptographic weaknesses in Kerberos v4 protocol</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:248" sig="1">oval:org.mitre.oval:def:248</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mit" name="kerberos">
                <vers num="4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0139" seq="2003-0139" severity="High" type="CVE" published="2003-03-24" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Certain weaknesses in the implementation of version 4 of the Kerberos protocol (krb4) in the krb5 distribution, when triple-DES keys are used to key krb4 services, allow an attacker to create krb4 tickets for unauthorized principals using a cut-and-paste attack and "ticket splicing."</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/442569" adv="1">VU#442569</ref>
            <ref source="CONFIRM" patch="1" url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txt" adv="1">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-004-krb4.txt</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104791775804776&amp;w=2" adv="1">20030319 MITKRB5-SA-2003-004: Cryptographic weaknesses in Kerberos v4</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-091.html">RHSA-2003:091</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-052.html">RHSA-2003:052</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-051.html">RHSA-2003:051</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-273">DSA-273</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-266">DSA-266</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/317130/30/25250/threaded">20030330 GLSA: openafs (200303-26)</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/316960/30/25250/threaded">20030331 GLSA: krb5 &amp; mit-krb5 (200303-28)</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:250" sig="1">oval:org.mitre.oval:def:250</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mit" name="kerberos">
                <vers num="4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0140" seq="2003-0140" severity="High" type="CVE" published="2003-03-24" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Buffer overflow in Mutt 1.4.0 and possibly earlier versions, 1.5.x up to 1.5.3, and other programs that use Mutt code such as Balsa before 2.0.10, allows a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a crafted folder.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7120" adv="1">7120</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104818814931378&amp;w=2" adv="1">20030320 CORE-20030304-02: Vulnerability in Mutt Mail User Agent</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11583" adv="1">mutt-folder-name-bo(11583)</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/315679" adv="1">20030319 mutt-1.4.1 fixes a buffer overflow.</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-109.html">RHSA-2003:109</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_020_mutt.html">SuSE-SA:2003:020</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-268">DSA-268</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:041">MDKSA-2003:041</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200303-19.xml">GLSA-200303-19</ref>
            <ref source="MISC" url="http://www.coresecurity.com/common/showdoc.php?idx=310&amp;idxseccion=10">http://www.coresecurity.com/common/showdoc.php?idx=310&amp;idxseccion=10</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105171507629573&amp;w=2">20030430 GLSA:  balsa (200304-10)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104852190605988&amp;w=2">20030322 GLSA:  mutt (200303-19)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104817995421439&amp;w=2">20030320 [OpenPKG-SA-2003.025] OpenPKG Security Advisory (mutt)</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000630">CLA-2003:630</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000626">CLA-2003:626</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:434" sig="1">oval:org.mitre.oval:def:434</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2" sig="1">oval:org.mitre.oval:def:2</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mutt" name="mutt">
                <vers num="1.3.12" />
                <vers num="1.3.16" />
                <vers num="1.3.17" />
                <vers num="1.3.22" />
                <vers num="1.3.24" />
                <vers num="1.3.25" />
                <vers num="1.3.27" />
                <vers num="1.4.0" />
                <vers num="1.5.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0128" seq="2003-0128" severity="Medium" type="CVE" published="2003-03-24" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">The try_uudecoding function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malicious uuencoded (UUE) header, possibly triggering a heap-based buffer overflow.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7117" adv="1">7117</ref>
            <ref source="MISC" patch="1" url="http://www.coresecurity.com/common/showdoc.php?idx=309&amp;idxseccion=10" adv="1">http://www.coresecurity.com/common/showdoc.php?idx=309&amp;idxseccion=10</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-108.html">RHSA-2003:108</ref>
            <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0141.html">20030319 CORE-2003-03-04-01: Multiple vulnerabilities in Ximian 's Evolution Mail User Agent</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:045">MDKSA-2003:045</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200303-18.xml">GLSA-200303-18</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104826470527308&amp;w=2">20030321 GLSA:  evolution (200303-18)</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000648">CLA-2003:648</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:107" sig="1">oval:org.mitre.oval:def:107</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ximian" name="evolution">
                <vers num="1.0.3" />
                <vers num="1.0.4" />
                <vers num="1.0.5" />
                <vers num="1.0.6" />
                <vers num="1.0.7" />
                <vers num="1.0.8" />
                <vers num="1.1.1" />
                <vers num="1.2" />
                <vers num="1.2.1" />
                <vers num="1.2.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0129" seq="2003-0129" severity="Medium" type="CVE" published="2003-03-24" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (memory consumption) via a mail message that is uuencoded multiple times.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7118" adv="1">7118</ref>
            <ref source="MISC" patch="1" url="http://www.coresecurity.com/common/showdoc.php?idx=309&amp;idxseccion=10" adv="1">http://www.coresecurity.com/common/showdoc.php?idx=309&amp;idxseccion=10</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104826470527308&amp;w=2" adv="1">20030321 GLSA:  evolution (200303-18)</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-108.html">RHSA-2003:108</ref>
            <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0141.html">20030319 CORE-2003-03-04-01: Multiple vulnerabilities in Ximian 's Evolution Mail User Agent</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:045">MDKSA-2003:045</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200303-18.xml">GLSA-200303-18</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000648">CLA-2003:648</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:108" sig="1">oval:org.mitre.oval:def:108</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ximian" name="evolution">
                <vers num="1.0.3" />
                <vers num="1.0.4" />
                <vers num="1.0.5" />
                <vers num="1.0.6" />
                <vers num="1.0.7" />
                <vers num="1.0.8" />
                <vers num="1.1.1" />
                <vers num="1.2" />
                <vers num="1.2.1" />
                <vers num="1.2.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0130" seq="2003-0130" severity="Medium" type="CVE" published="2003-03-24" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">The handle_image function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier does not properly escape HTML characters, which allows remote attackers inject arbitrary data and HTML via a MIME Content-ID header in a MIME-encoded image.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7119" adv="1">7119</ref>
            <ref source="MISC" patch="1" url="http://www.coresecurity.com/common/showdoc.php?idx=309&amp;idxseccion=10" adv="1">http://www.coresecurity.com/common/showdoc.php?idx=309&amp;idxseccion=10</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104826470527308&amp;w=2" adv="1">20030321 GLSA:  evolution (200303-18)</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-108.html">RHSA-2003:108</ref>
            <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0141.html">20030319 CORE-2003-03-04-01: Multiple vulnerabilities in Ximian 's Evolution Mail User Agent</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:045">MDKSA-2003:045</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200303-18.xml">GLSA-200303-18</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000648">CLA-2003:648</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:111" sig="1">oval:org.mitre.oval:def:111</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ximian" name="evolution">
                <vers num="1.0.3" />
                <vers num="1.0.4" />
                <vers num="1.0.5" />
                <vers num="1.0.6" />
                <vers num="1.0.7" />
                <vers num="1.0.8" />
                <vers num="1.1.1" />
                <vers num="1.2" />
                <vers num="1.2.1" />
                <vers num="1.2.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0131" seq="2003-0131" severity="High" type="CVE" published="2003-03-24" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">The SSL and TLS components for OpenSSL 0.9.6i and earlier, 0.9.7, and 0.9.7a allow remote attackers to perform an unauthorized RSA private key operation via a modified Bleichenbacher attack that uses a large number of SSL or TLS connections using PKCS #1 v1.5 padding that cause OpenSSL to leak information regarding the relationship between ciphertext and the associated plaintext, aka the "Klima-Pokorny-Rosa attack."</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/888801" adv="1">VU#888801</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7148" adv="1">7148</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104811162730834&amp;w=2" adv="1">20030319 [OpenSSL Advisory] Klima-Pokorny-Rosa attack on PKCS #1 v1.5 padding</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11586" adv="1">ssl-premaster-information-leak(11586)</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-102.html">RHSA-2003:102</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-101.html">RHSA-2003:101</ref>
            <ref source="CONFIRM" url="http://www.openssl.org/news/secadv_20030319.txt">http://www.openssl.org/news/secadv_20030319.txt</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_024_openssl.html">SuSE-SA:2003:024</ref>
            <ref source="MISC" url="http://www.linuxsecurity.com/advisories/immunix_advisory-3066.html">http://www.linuxsecurity.com/advisories/immunix_advisory-3066.html</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-288">DSA-288</ref>
            <ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00028.html">http://lists.apple.com/mhonarc/security-announce/msg00028.html</ref>
            <ref source="MISC" url="http://eprint.iacr.org/2003/052/" adv="1">http://eprint.iacr.org/2003/052/</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030501-01-I">20030501-01-I</ref>
            <ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-007.txt.asc">NetBSD-SA2003-007</ref>
            <ref source="SUSE" url="http://www.suse.de/de/security/2003_024_openssl.html">SuSE-SA:2003:024</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/316577/30/25310/threaded">20030327 Immunix Secured OS 7+ openssl update</ref>
            <ref source="OPENPKG" url="http://www.openpkg.org/security/OpenPKG-SA-2003.026-openssl.html">OpenPKG-SA-2003.026</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:035">MDKSA-2003:035</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200303-20.xml">GLSA-200303-20</ref>
            <ref source="TRUSTIX" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104878215721135&amp;w=2">2003-0013</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104852637112330&amp;w=2">20030324 GLSA:  openssl (200303-20)</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000625">CLA-2003:625</ref>
            <ref source="CALDERA" url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-014.0.txt">CSSA-2003-014.0</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:461" sig="1">oval:org.mitre.oval:def:461</ref>
        </refs>
        <vuln_soft>
            <prod vendor="openssl" name="openssl">
                <vers num="0.9.6" />
                <vers num="0.9.6a" />
                <vers num="0.9.6b" />
                <vers num="0.9.6c" />
                <vers num="0.9.6d" />
                <vers num="0.9.6e" />
                <vers num="0.9.6g" />
                <vers num="0.9.6h" />
                <vers num="0.9.6i" />
                <vers num="0.9.7" />
                <vers num="0.9.7a" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0156" seq="2003-0156" severity="Medium" type="CVE" published="2003-03-24" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Directory traversal vulnerability in Cross-Referencing Linux (LXR) allows remote attackers to read arbitrary files via .. (dot dot) sequences in the v parameter.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7062" adv="1">7062</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-264" adv="1">DSA-264</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104739747222492&amp;w=2" adv="1">20030311 Cross-Referencing Linux vulnerability</ref>
        </refs>
        <vuln_soft>
            <prod vendor="cross_referencer" name="lxr">
                <vers num="0.3" />
                <vers num="0.8" />
                <vers num="0.9" />
                <vers num="0.9.1" />
                <vers num="0.9.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry reject="1" name="CVE-2003-0157" seq="2003-0157" type="CVE" published="2003-03-24" modified="2008-09-10">
        <desc>
            <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0138.  Reason: This candidate is a reservation duplicate of CVE-2003-0138 due to incomplete coordination.  Notes: All CVE users should reference CVE-2003-0138 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
        </desc>
        <refs />
    </entry>
    <entry reject="1" name="CVE-2003-0158" seq="2003-0158" type="CVE" published="2003-03-24" modified="2008-09-10">
        <desc>
            <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0139.  Reason: This candidate is a reservation duplicate of CVE-2003-0139 due to incomplete coordination.  Notes: All CVE users should reference CVE-2003-0139 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
        </desc>
        <refs />
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" name="CVE-2003-0150" seq="2003-0150" severity="High" type="CVE" published="2003-03-24" CVSS_version="2.0" CVSS_score="9.0" modified="2008-09-10">
        <desc>
            <descript source="cve">MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the "SELECT * INFO OUTFILE" operator to overwrite a configuration file and cause mysql to run as root upon restart, as demonstrated by modifying my.cnf.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/203897">VU#203897</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7052" adv="1">7052</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104800948128630&amp;w=2" adv="1">20030318 [OpenPKG-SA-2003.022] OpenPKG Security Advisory (mysql)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11510">mysql-datadir-root-privileges(11510)</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-093.html">RHSA-2003:093</ref>
            <ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/engarde_advisory-3046.html">ESA-20030324-012</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-303">DSA-303</ref>
            <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2003-094.html">RHSA-2003:094</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104802285012750&amp;w=2">20030318 GLSA:  mysql (200303-14)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104800948128630&amp;w=2">20030318 [OpenPKG-SA-2003.022] OpenPKG Security Advisory (mysql)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104739810523433&amp;w=2">20030310 Re: MySQL user can be changed to root</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104715840202315&amp;w=2">20030308 MySQL_user_can_be_changed_to_root?</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104715840202315&amp;w=2" adv="1">20030308 MySQL_user_can_be_changed_to_root?</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000743">CLA-2003:743</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:057">MDKSA-2003:057</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:442" sig="1">oval:org.mitre.oval:def:442</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mysql" name="mysql">
                <vers num="3.23.52" />
                <vers num="3.23.53" />
                <vers num="3.23.53a" />
                <vers num="3.23.54" />
                <vers num="3.23.54a" />
                <vers num="3.23.55" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0151" seq="2003-0151" severity="High" type="CVE" published="2003-03-24" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">BEA WebLogic Server and Express 6.0 through 7.0 does not properly restrict access to certain internal servlets that perform administrative functions, which allows remote attackers to read arbitrary files or execute arbitrary code.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104792544515384&amp;w=2" adv="1">20030317 S21SEC-011 - Multiple vulnerabilities in BEA WebLogic Server</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104792477914620&amp;w=2" adv="1">20030317 SPI ADVISORY: Remote Administration of BEA WebLogic Server and Express</ref>
            <ref source="MISC" url="http://www.s21sec.com/en/avisos/s21sec-011-en.txt">http://www.s21sec.com/en/avisos/s21sec-011-en.txt</ref>
            <ref source="CONFIRM" url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-28.jsp">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA03-28.jsp</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/7124">7124</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/7122">7122</ref>
        </refs>
        <vuln_soft>
            <prod vendor="bea" name="weblogic_server">
                <vers edition="" num="6.0" />
                <vers edition=":express" num="6.0" />
                <vers edition="sp1" num="6.0" />
                <vers edition="sp1:express" num="6.0" />
                <vers edition="sp2" num="6.0" />
                <vers edition="sp2:express" num="6.0" />
                <vers edition="" num="6.1" />
                <vers edition=":express" num="6.1" />
                <vers edition="sp1" num="6.1" />
                <vers edition="sp1:express" num="6.1" />
                <vers edition="sp2" num="6.1" />
                <vers edition="sp2:express" num="6.1" />
                <vers edition="sp3" num="6.1" />
                <vers edition="sp3:express" num="6.1" />
                <vers edition="sp4" num="6.1" />
                <vers edition="sp4:express" num="6.1" />
                <vers edition="" num="7.0" />
                <vers edition=":express" num="7.0" />
                <vers edition="sp1" num="7.0" />
                <vers edition="sp1:express" num="7.0" />
                <vers edition="sp2" num="7.0" />
                <vers edition="sp2:express" num="7.0" />
                <vers edition="" num="7.0.0.1" />
                <vers edition=":express" num="7.0.0.1" />
                <vers edition="sp1" num="7.0.0.1" />
                <vers edition="sp1:express" num="7.0.0.1" />
                <vers edition="sp2" num="7.0.0.1" />
                <vers edition="sp2:express" num="7.0.0.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0010" seq="2003-0010" severity="High" type="CVE" published="2003-03-24" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7146" adv="1">7146</ref>
            <ref source="MS" patch="1" url="http://www.microsoft.com/technet/security/bulletin/ms03-008.asp" adv="1">MS03-008</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104812108307645&amp;w=2" adv="1">20030319 iDEFENSE Security Advisory 03.19.03: Heap Overflow in Windows Script Engine</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0139.html">20030319 Windows Scripting Engine issue</ref>
            <ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=26">20030319 Heap Overflow in Windows Script Engine</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:795" sig="1">oval:org.mitre.oval:def:795</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:794" sig="1">oval:org.mitre.oval:def:794</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:200" sig="1">oval:org.mitre.oval:def:200</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:134" sig="1">oval:org.mitre.oval:def:134</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="windows_2000">
                <vers edition=":professional" num="" />
                <vers edition=":datacenter_server" num="" />
                <vers edition=":server" num="" />
                <vers edition=":advanced_server" num="" />
                <vers edition="sp1" num="" />
                <vers edition="sp1:server" num="" />
                <vers edition="sp1:professional" num="" />
                <vers edition="sp1:datacenter_server" num="" />
                <vers edition="sp1:advanced_server" num="" />
                <vers edition="sp2" num="" />
                <vers edition="sp2:server" num="" />
                <vers edition="sp2:advanced_server" num="" />
                <vers edition="sp2:datacenter_server" num="" />
                <vers edition="sp2:professional" num="" />
                <vers edition="sp3" num="" />
                <vers edition="sp3:advanced_server" num="" />
                <vers edition="sp3:professional" num="" />
                <vers edition="sp3:datacenter_server" num="" />
                <vers edition="sp3:server" num="" />
            </prod>
            <prod vendor="microsoft" name="windows_2000_terminal_services">
                <vers edition="sp1" num="" />
                <vers edition="sp2" num="" />
                <vers edition="sp3" num="" />
            </prod>
            <prod vendor="microsoft" name="windows_98">
                <vers edition="gold" num="" />
            </prod>
            <prod vendor="microsoft" name="windows_98se">
                <vers num="" />
            </prod>
            <prod vendor="microsoft" name="windows_me">
                <vers num="" />
            </prod>
            <prod vendor="microsoft" name="windows_nt">
                <vers edition="" num="4.0" />
                <vers edition=":terminal_server" num="4.0" />
                <vers edition=":workstation" num="4.0" />
                <vers edition=":enterprise_server" num="4.0" />
                <vers edition=":server" num="4.0" />
                <vers edition="sp1" num="4.0" />
                <vers edition="sp1:server" num="4.0" />
                <vers edition="sp1:enterprise_server" num="4.0" />
                <vers edition="sp1:workstation" num="4.0" />
                <vers edition="sp1:terminal_server" num="4.0" />
                <vers edition="sp2" num="4.0" />
                <vers edition="sp2:terminal_server" num="4.0" />
                <vers edition="sp2:workstation" num="4.0" />
                <vers edition="sp2:server" num="4.0" />
                <vers edition="sp2:enterprise_server" num="4.0" />
                <vers edition="sp3" num="4.0" />
                <vers edition="sp3:terminal_server" num="4.0" />
                <vers edition="sp3:enterprise_server" num="4.0" />
                <vers edition="sp3:server" num="4.0" />
                <vers edition="sp3:workstation" num="4.0" />
                <vers edition="sp4" num="4.0" />
                <vers edition="sp4:terminal_server" num="4.0" />
                <vers edition="sp4:enterprise_server" num="4.0" />
                <vers edition="sp4:workstation" num="4.0" />
                <vers edition="sp4:server" num="4.0" />
                <vers edition="sp5" num="4.0" />
                <vers edition="sp5:terminal_server" num="4.0" />
                <vers edition="sp5:server" num="4.0" />
                <vers edition="sp5:workstation" num="4.0" />
                <vers edition="sp5:enterprise_server" num="4.0" />
                <vers edition="sp6" num="4.0" />
                <vers edition="sp6:enterprise_server" num="4.0" />
                <vers edition="sp6:terminal_server" num="4.0" />
                <vers edition="sp6:server" num="4.0" />
                <vers edition="sp6:workstation" num="4.0" />
                <vers edition="sp6a" num="4.0" />
                <vers edition="sp6a:terminal_server" num="4.0" />
                <vers edition="sp6a:server" num="4.0" />
                <vers edition="sp6a:workstation" num="4.0" />
                <vers edition="sp6a:enterprise_server" num="4.0" />
            </prod>
            <prod vendor="microsoft" name="windows_xp">
                <vers edition=":home" num="" />
                <vers edition="gold" num="" />
                <vers edition="gold:professional" num="" />
                <vers edition="sp1" num="" />
                <vers edition="sp1:home" num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0011" seq="2003-0011" severity="Medium" type="CVE" published="2003-03-24" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Unknown vulnerability in the DNS intrusion detection application filter for Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (blocked traffic to DNS servers) via a certain type of incoming DNS request that is not properly handled.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7145" adv="1">7145</ref>
            <ref source="MS" patch="1" url="http://www.microsoft.com/technet/security/bulletin/ms03-009.asp" adv="1">MS03-009</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="isa_server">
                <vers edition="sp1" num="2000" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0028" seq="2003-0028" severity="High" type="CVE" published="2003-03-25" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-2003-10.html" adv="1">CA-2003-10</ref>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/516825">VU#516825</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105362148313082&amp;w=2" adv="1">20030522 [slackware-security]  glibc XDR overflow fix (SSA:2003-141-03)</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-091.html">RHSA-2003:091</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-089.html">RHSA-2003:089</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-052.html">RHSA-2003:052</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-051.html">RHSA-2003:051</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_027_glibc.html">SuSE-SA:2003:027</ref>
            <ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/engarde_advisory-3024.html">ESA-20030321-010</ref>
            <ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD20030318.html" adv="1">AD20030318</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-282">DSA-282</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-272">DSA-272</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-266">DSA-266</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105362148313082&amp;w=2">20030522 [slackware-security]  glibc XDR overflow fix (SSA:2003-141-03)</ref>
            <ref source="TRUSTIX" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104878237121402&amp;w=2">2003-0014</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104860855114117&amp;w=2">20030325 GLSA:  glibc (200303-22)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104811415301340&amp;w=2">20030319 MITKRB5-SA-2003-003: faulty length checks in xdrmem_getbytes</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104810574423662&amp;w=2">20030319 EEYE: XDR Integer Overflow</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0140.html">20030319 EEYE: XDR Integer Overflow</ref>
            <ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-008.txt.asc">NetBSD-SA2003-008</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/316960/30/25250/threaded">20030331 GLSA: krb5 &amp; mit-krb5 (200303-28)</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/316931/30/25250/threaded">20030331 GLSA: dietlibc (200303-29)</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/315638/30/25430/threaded">20030319 RE: EEYE: XDR Integer Overflow</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:037">MDKSA-2003:037</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:230" sig="1">oval:org.mitre.oval:def:230</ref>
        </refs>
        <vuln_soft>
            <prod vendor="gnu" name="glibc">
                <vers num="2.1" />
                <vers num="2.1.1" />
                <vers num="2.1.2" />
                <vers num="2.1.3" />
                <vers num="2.2" />
                <vers num="2.2.1" />
                <vers num="2.2.2" />
                <vers num="2.2.3" />
                <vers num="2.2.4" />
                <vers num="2.2.5" />
                <vers num="2.3" />
                <vers num="2.3.1" />
                <vers num="2.3.2" />
            </prod>
            <prod vendor="mit" name="kerberos">
                <vers num="5-1.2" />
                <vers num="5-1.2.1" />
                <vers num="5-1.2.2" />
                <vers num="5-1.2.3" />
                <vers num="5-1.2.4" />
                <vers num="5-1.2.5" />
                <vers num="5-1.2.6" />
                <vers num="5-1.2.7" />
            </prod>
            <prod vendor="openafs" name="openafs">
                <vers num="1.0" />
                <vers num="1.0.1" />
                <vers num="1.0.2" />
                <vers num="1.0.3" />
                <vers num="1.0.4" />
                <vers num="1.0.4a" />
                <vers num="1.1" />
                <vers num="1.1.1" />
                <vers num="1.1.1a" />
                <vers num="1.2" />
                <vers num="1.2.1" />
                <vers num="1.2.2" />
                <vers num="1.2.2a" />
                <vers num="1.2.2b" />
                <vers num="1.2.3" />
                <vers num="1.2.4" />
                <vers num="1.2.5" />
                <vers num="1.2.6" />
                <vers num="1.3" />
                <vers num="1.3.1" />
                <vers num="1.3.2" />
            </prod>
            <prod vendor="cray" name="unicos">
                <vers num="6.0" />
                <vers num="6.0e" />
                <vers num="6.1" />
                <vers num="7.0" />
                <vers num="8.0" />
                <vers num="8.3" />
                <vers num="9.0" />
                <vers num="9.0.2.5" />
                <vers num="9.2" />
                <vers num="9.2.4" />
            </prod>
            <prod vendor="freebsd" name="freebsd">
                <vers num="4.0" />
                <vers num="4.1" />
                <vers edition="release" num="4.1.1" />
                <vers edition="stable" num="4.1.1" />
                <vers edition="stable" num="4.2" />
                <vers edition="release" num="4.3" />
                <vers edition="stable" num="4.3" />
                <vers edition="stable" num="4.4" />
                <vers edition="release" num="4.5" />
                <vers edition="stable" num="4.5" />
                <vers edition="release" num="4.6" />
                <vers edition="stable" num="4.6" />
                <vers num="4.6.2" />
                <vers edition="release" num="4.7" />
                <vers edition="stable" num="4.7" />
                <vers num="5.0" />
            </prod>
            <prod vendor="hp" name="hp-ux">
                <vers num="10.20" />
                <vers num="10.24" />
                <vers num="11.00" />
                <vers num="11.04" />
                <vers num="11.11" />
                <vers num="11.20" />
                <vers num="11.22" />
            </prod>
            <prod vendor="hp" name="hp-ux_series_700">
                <vers num="10.20" />
            </prod>
            <prod vendor="hp" name="hp-ux_series_800">
                <vers num="10.20" />
            </prod>
            <prod vendor="ibm" name="aix">
                <vers num="4.3.3" />
                <vers num="5.1" />
                <vers num="5.2" />
            </prod>
            <prod vendor="openbsd" name="openbsd">
                <vers num="2.0" />
                <vers num="2.1" />
                <vers num="2.2" />
                <vers num="2.3" />
                <vers num="2.4" />
                <vers num="2.5" />
                <vers num="2.6" />
                <vers num="2.7" />
                <vers num="2.8" />
                <vers num="2.9" />
                <vers num="3.0" />
                <vers num="3.1" />
                <vers num="3.2" />
            </prod>
            <prod vendor="sgi" name="irix">
                <vers num="6.5" />
                <vers num="6.5.1" />
                <vers num="6.5.10" />
                <vers num="6.5.10f" />
                <vers num="6.5.10m" />
                <vers num="6.5.11" />
                <vers num="6.5.11f" />
                <vers num="6.5.11m" />
                <vers num="6.5.12" />
                <vers num="6.5.12f" />
                <vers num="6.5.12m" />
                <vers num="6.5.13" />
                <vers num="6.5.13f" />
                <vers num="6.5.13m" />
                <vers num="6.5.14" />
                <vers num="6.5.14f" />
                <vers num="6.5.14m" />
                <vers num="6.5.15" />
                <vers num="6.5.15f" />
                <vers num="6.5.15m" />
                <vers num="6.5.16" />
                <vers num="6.5.16f" />
                <vers num="6.5.16m" />
                <vers num="6.5.17" />
                <vers num="6.5.17f" />
                <vers num="6.5.17m" />
                <vers num="6.5.18" />
                <vers num="6.5.18f" />
                <vers num="6.5.18m" />
                <vers num="6.5.19" />
                <vers num="6.5.2" />
                <vers num="6.5.20" />
                <vers num="6.5.2f" />
                <vers num="6.5.2m" />
                <vers num="6.5.3" />
                <vers num="6.5.3f" />
                <vers num="6.5.3m" />
                <vers num="6.5.4" />
                <vers num="6.5.4f" />
                <vers num="6.5.4m" />
                <vers num="6.5.5" />
                <vers num="6.5.5f" />
                <vers num="6.5.5m" />
                <vers num="6.5.6" />
                <vers num="6.5.6f" />
                <vers num="6.5.6m" />
                <vers num="6.5.7" />
                <vers num="6.5.7f" />
                <vers num="6.5.7m" />
                <vers num="6.5.8" />
                <vers num="6.5.8f" />
                <vers num="6.5.8m" />
                <vers num="6.5.9" />
                <vers num="6.5.9f" />
                <vers num="6.5.9m" />
            </prod>
            <prod vendor="sun" name="solaris">
                <vers edition="" num="2.5.1" />
                <vers edition=":x86" num="2.5.1" />
                <vers edition="" num="2.6" />
                <vers edition=":x86" num="2.6" />
                <vers edition="" num="7.0" />
                <vers edition=":x86" num="7.0" />
                <vers edition="" num="8.0" />
                <vers edition=":x86" num="8.0" />
                <vers edition="" num="9.0" />
                <vers edition=":x86" num="9.0" />
                <vers edition=":sparc" num="9.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2003-1074" seq="2003-1074" severity="High" type="CVE" published="2003-03-28" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-10">
        <desc>
            <descript source="cve">Unknown vulnerability in newtask for Solaris 9 allows local users to gain root privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input bound="1" />
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/8454/">8454</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11657" adv="1">solaris-newtask-root-access(11657)</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-52111-1" adv="1">52111</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006411">1006411</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/7252">7252</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers edition="" num="9.0" />
                <vers edition=":x86" num="9.0" />
                <vers edition=":sparc" num="9.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0080" seq="2003-0080" severity="High" type="CVE" published="2003-03-31" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">The iptables ruleset in Gnome-lokkit in Red Hat Linux 8.0 does not include any rules in the FORWARD chain, which could allow attackers to bypass intended access restrictions if packet forwarding is enabled.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7128" adv="1">7128</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2003-072.html" adv="1">RHSA-2003:072</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11552" adv="1">gnomelokkit-forward-bypass-firewall(11552)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/4400">4400</ref>
        </refs>
        <vuln_soft>
            <prod vendor="gnome" name="gnome-lokkit">
                <vers num="0.50_21" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2003-0085" seq="2003-0085" severity="High" type="CVE" published="2003-03-31" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, allows remote attackers to execute arbitrary code.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/298233">VU#298233</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7106" adv="1">7106</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-262" adv="1">DSA-262</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104792723017768&amp;w=2" adv="1">20030317 Security Bugfix for Samba - Samba 2.2.8 Released</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104792646416629&amp;w=2" adv="1">20030317 GLSA:  samba (200303-11)</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-095.html">RHSA-2003:095</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_016_samba.html">SuSE-SA:2003:016</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030302-01-I">20030302-01-I</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/317145/30/25220/threaded">20030401 Immunix Secured OS 7+ samba update</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/316165/30/25370/threaded">20030325 Fwd: APPLE-SA-2003-03-24 Samba, OpenSSL</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-096.html">RHSA-2003:096</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:032">MDKSA-2003:032</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200303-11.xml">GLSA-200303-11</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/8303">8303</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/8299">8299</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104801012929374&amp;w=2">20030318 [OpenPKG-SA-2003.021] OpenPKG Security Advisory (samba)</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:552" sig="1">oval:org.mitre.oval:def:552</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="cifs-9000_server">
                <vers num="a.01.05" />
                <vers num="a.01.06" />
                <vers num="a.01.07" />
                <vers num="a.01.08" />
                <vers num="a.01.08.01" />
                <vers num="a.01.09" />
                <vers num="a.01.09.01" />
            </prod>
            <prod vendor="samba" name="samba">
                <vers num="2.0.0" />
                <vers num="2.0.1" />
                <vers num="2.0.10" />
                <vers num="2.0.2" />
                <vers num="2.0.3" />
                <vers num="2.0.4" />
                <vers num="2.0.5" />
                <vers num="2.0.6" />
                <vers num="2.0.7" />
                <vers num="2.0.8" />
                <vers num="2.0.9" />
                <vers num="2.2.0" />
                <vers num="2.2.0a" />
                <vers num="2.2.1a" />
                <vers num="2.2.2" />
                <vers num="2.2.3" />
                <vers num="2.2.3a" />
                <vers num="2.2.4" />
                <vers num="2.2.5" />
                <vers num="2.2.6" />
                <vers num="2.2.7" />
                <vers num="2.2.7a" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" name="CVE-2003-0086" seq="2003-0086" severity="Low" type="CVE" published="2003-03-31" CVSS_version="2.0 incomplete approximation" CVSS_score="1.2" modified="2008-09-10">
        <desc>
            <descript source="cve">The code for writing reg files in Samba before 2.2.8 allows local users to overwrite arbitrary files via a race condition involving chown.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <race />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7107" adv="1">7107</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-262" adv="1">DSA-262</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104792646416629&amp;w=2" adv="1">20030317 GLSA:  samba (200303-11)</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-095.html">RHSA-2003:095</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_016_samba.html">SuSE-SA:2003:016</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030302-01-I">20030302-01-I</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/316165/30/25370/threaded">20030325 Fwd: APPLE-SA-2003-03-24 Samba, OpenSSL</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-096.html">RHSA-2003:096</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:032">MDKSA-2003:032</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200303-11.xml">GLSA-200303-11</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/8303">8303</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/8299">8299</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104801012929374&amp;w=2">20030318 [OpenPKG-SA-2003.021] OpenPKG Security Advisory (samba)</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:554" sig="1">oval:org.mitre.oval:def:554</ref>
        </refs>
        <vuln_soft>
            <prod vendor="samba" name="samba">
                <vers num="2.0.0" />
                <vers num="2.0.1" />
                <vers num="2.0.10" />
                <vers num="2.0.2" />
                <vers num="2.0.3" />
                <vers num="2.0.4" />
                <vers num="2.0.5" />
                <vers num="2.0.6" />
                <vers num="2.0.7" />
                <vers num="2.0.8" />
                <vers num="2.0.9" />
                <vers num="2.2.0" />
                <vers num="2.2.0a" />
                <vers num="2.2.1a" />
                <vers num="2.2.2" />
                <vers num="2.2.3" />
                <vers num="2.2.3a" />
                <vers num="2.2.4" />
                <vers num="2.2.5" />
                <vers num="2.2.6" />
                <vers num="2.2.7" />
                <vers num="2.2.7a" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2003-0144" seq="2003-0144" severity="High" type="CVE" published="2003-03-31" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-10">
        <desc>
            <descript source="cve">Buffer overflow in the lprm command in the lprold lpr package on SuSE 7.1 through 7.3, OpenBSD 3.2 and earlier, and possibly other operating systems, allows local users to gain root privileges via long command line arguments such as (1) request ID or (2) user name.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7025" adv="1">7025</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11473" adv="1">lprm-bo(11473)</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_014_lprold.html">SuSE-SA:2003:0014</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-275">DSA-275</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-267">DSA-267</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030406-02-P">20030406-02-P</ref>
            <ref source="CONFIRM" url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/010_lprm.patch">ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.2/common/010_lprm.patch</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:059">MDKSA-2003:059</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/8293">8293</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104714441925019&amp;w=2">20030308 OpenBSD lprm(1) exploit</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104690434504429&amp;w=2">20030305 potential buffer overflow in lprm (fwd)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="lprold" name="lprold">
                <vers num="3.0.48" />
            </prod>
            <prod vendor="bsd" name="lpr">
                <vers num="0.48" />
                <vers num="2000-05-07" />
            </prod>
            <prod vendor="freebsd" name="freebsd">
                <vers num="2.2" />
                <vers num="2.2.2" />
                <vers num="2.2.3" />
                <vers num="2.2.4" />
                <vers num="2.2.5" />
                <vers num="2.2.6" />
            </prod>
            <prod vendor="openbsd" name="openbsd">
                <vers num="2.0" />
                <vers num="2.1" />
                <vers num="2.2" />
                <vers num="2.3" />
                <vers num="2.4" />
                <vers num="2.5" />
                <vers num="2.6" />
                <vers num="2.7" />
                <vers num="2.8" />
                <vers num="2.9" />
                <vers num="3.0" />
                <vers num="3.1" />
                <vers num="3.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0145" seq="2003-0145" severity="Medium" type="CVE" published="2003-03-31" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Unknown vulnerability in tcpdump before 3.7.2 related to an inability to "Handle unknown RADIUS attributes properly," allows remote attackers to cause a denial of service (infinite loop), a different vulnerability than CAN-2003-0093.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" url="http://www.tcpdump.org/tcpdump-changes.txt" adv="1">http://www.tcpdump.org/tcpdump-changes.txt</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11857">tcpdump-radius-attribute-dos(11857)</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-214.html">RHSA-2003:214</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-151.html">RHSA-2003:151</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-032.html">RHSA-2003:032</ref>
            <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:027">MDKSA-2003:027</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-261">DSA-261</ref>
        </refs>
        <vuln_soft>
            <prod vendor="lbl" name="tcpdump">
                <vers num="3.5.2" />
                <vers num="3.6.2" />
                <vers num="3.7" />
                <vers num="3.7.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0146" seq="2003-0146" severity="High" type="CVE" published="2003-03-31" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple vulnerabilities in NetPBM 9.20 and earlier, and possibly other versions, may allow remote attackers to cause a denial of service or execute arbitrary code via "maths overflow errors" such as (1) integer signedness errors or (2) integer overflows, which lead to buffer overflows.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/630433">VU#630433</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-263" adv="1">DSA-263</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11463">netpbm-multiple-bo(11463)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6979">6979</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-060.html">RHSA-2003:060</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104644687816522&amp;w=2" adv="1">20030228 NetPBM, multiple vulnerabilities</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000656">CLSA-2003:656</ref>
        </refs>
        <vuln_soft>
            <prod vendor="netpbm" name="netpbm">
                <vers num="9.20" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0147" seq="2003-0147" severity="Medium" type="CVE" published="2003-03-31" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms ("Karatsuba" and normal).</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/997481" adv="1">VU#997481</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-102.html">RHSA-2003:102</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-101.html">RHSA-2003:101</ref>
            <ref source="CONFIRM" url="http://www.openssl.org/news/secadv_20030317.txt">http://www.openssl.org/news/secadv_20030317.txt</ref>
            <ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:035">MDKSA-2003:035</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-288">DSA-288</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104792570615648&amp;w=2" adv="1">20030317 [ADVISORY] Timing Attack on OpenSSL</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104766550528628&amp;w=2" adv="1">20030313 Vulnerability in OpenSSL</ref>
            <ref source="MISC" url="http://crypto.stanford.edu/~dabo/papers/ssl-timing.pdf">http://crypto.stanford.edu/~dabo/papers/ssl-timing.pdf</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0130.html" adv="1">20030313 OpenSSL Private Key Disclosure</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030501-01-I">20030501-01-I</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/316577/30/25310/threaded">20030327 Immunix Secured OS 7+ openssl update</ref>
            <ref source="APPLE" url="http://www.securityfocus.com/archive/1/archive/1/316165/30/25370/threaded">APPLE-SA-2003-03-24</ref>
            <ref source="OPENPKG" url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2003.019.html">OpenPKG-SA-2003.019</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200303-23.xml">GLSA-200303-23</ref>
            <ref source="GENTOO" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104861762028637&amp;w=2">GLSA-200303-24</ref>
            <ref source="GENTOO" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104829040921835&amp;w=2">GLSA-200303-15</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104819602408063&amp;w=2">20030320 [OpenPKG-SA-2003.026] OpenPKG Security Advisory (openssl)</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000625">CLA-2003:625</ref>
            <ref source="CALDERA" url="ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-014.0.txt">CSSA-2003-014.0</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:466" sig="1">oval:org.mitre.oval:def:466</ref>
        </refs>
        <vuln_soft>
            <prod vendor="openpkg" name="openpkg">
                <vers num="1.1" />
                <vers num="1.2" />
            </prod>
            <prod vendor="openssl" name="openssl">
                <vers num="0.9.6" />
                <vers num="0.9.6a" />
                <vers num="0.9.6b" />
                <vers num="0.9.6c" />
                <vers num="0.9.6d" />
                <vers num="0.9.6e" />
                <vers num="0.9.6g" />
                <vers num="0.9.6h" />
                <vers num="0.9.6i" />
                <vers num="0.9.7" />
                <vers num="0.9.7a" />
            </prod>
            <prod vendor="stunnel" name="stunnel">
                <vers num="3.10" />
                <vers num="3.11" />
                <vers num="3.12" />
                <vers num="3.13" />
                <vers num="3.14" />
                <vers num="3.15" />
                <vers num="3.16" />
                <vers num="3.17" />
                <vers num="3.18" />
                <vers num="3.19" />
                <vers num="3.20" />
                <vers num="3.21" />
                <vers num="3.22" />
                <vers num="3.7" />
                <vers num="3.8" />
                <vers num="3.9" />
                <vers num="4.0" />
                <vers num="4.01" />
                <vers num="4.02" />
                <vers num="4.03" />
                <vers num="4.04" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2003-0127" seq="2003-0127" severity="High" type="CVE" published="2003-03-31" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-10">
        <desc>
            <descript source="cve">The kernel module loader in Linux kernel 2.2.x before 2.2.25, and 2.4.x before 2.4.21, allows local users to gain root privileges by using ptrace to attach to a child process that is spawned by the kernel.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/628849" adv="1">VU#628849</ref>
            <ref source="REDHAT" patch="1" url="http://rhn.redhat.com/errata/RHSA-2003-098.html" adv="1">RHSA-2003:098</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-145.html">RHSA-2003:145</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-495">DSA-495</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-423">DSA-423</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-336">DSA-336</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-332">DSA-332</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-312">DSA-312</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-311">DSA-311</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-276">DSA-276</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-270">DSA-270</ref>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200303-17.xml">GLSA-200303-17</ref>
            <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2003-088.html">RHSA-2003:088</ref>
            <ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-020.0.txt">CSSA-2003-020.0</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-103.html">RHSA-2003:103</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:039">MDKSA-2003:039</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:038">MDKSA-2003:038</ref>
            <ref source="ENGARDE" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105301461726555&amp;w=2">ESA-20030515-017</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0134.html">20030317 Fwd: Ptrace hole / Linux 2.2.25</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:254" sig="1">oval:org.mitre.oval:def:254</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="linux_kernel">
                <vers num="2.2.0" />
                <vers num="2.2.1" />
                <vers num="2.2.10" />
                <vers num="2.2.11" />
                <vers num="2.2.12" />
                <vers num="2.2.13" />
                <vers num="2.2.14" />
                <vers num="2.2.15" />
                <vers num="2.2.16" />
                <vers num="2.2.17" />
                <vers num="2.2.18" />
                <vers num="2.2.19" />
                <vers num="2.2.2" />
                <vers num="2.2.20" />
                <vers num="2.2.21" />
                <vers num="2.2.22" />
                <vers num="2.2.23" />
                <vers num="2.2.24" />
                <vers num="2.2.3" />
                <vers num="2.2.4" />
                <vers num="2.2.5" />
                <vers num="2.2.6" />
                <vers num="2.2.7" />
                <vers num="2.2.8" />
                <vers num="2.2.9" />
                <vers num="2.4.0" />
                <vers num="2.4.1" />
                <vers num="2.4.10" />
                <vers num="2.4.11" />
                <vers num="2.4.12" />
                <vers num="2.4.13" />
                <vers num="2.4.14" />
                <vers num="2.4.15" />
                <vers num="2.4.16" />
                <vers num="2.4.17" />
                <vers num="2.4.18" />
                <vers num="2.4.19" />
                <vers num="2.4.2" />
                <vers num="2.4.20" />
                <vers edition="pre1" num="2.4.21" />
                <vers num="2.4.3" />
                <vers num="2.4.4" />
                <vers num="2.4.5" />
                <vers num="2.4.6" />
                <vers num="2.4.7" />
                <vers num="2.4.8" />
                <vers num="2.4.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0109" seq="2003-0109" severity="High" type="CVE" published="2003-03-31" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute arbitrary code, as demonstrated via a WebDAV request to IIS 5.0.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-2003-09.html" adv="1">CA-2003-09</ref>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/117394">VU#117394</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7116" adv="1">7116</ref>
            <ref source="MS" patch="1" url="http://www.microsoft.com/technet/security/bulletin/ms03-007.asp" adv="1">MS03-007</ref>
            <ref source="XF" patch="1" url="http://www.iss.net/security_center/static/11533.php" adv="1">http-webdav-long-request(11533)</ref>
            <ref source="ISS" patch="1" url="http://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=22029" adv="1">20030317 Microsoft IIS WebDAV Remote Compromise Vulnerability</ref>
            <ref source="MISC" url="http://www.nextgenss.com/papers/ms03-007-ntdll.pdf">http://www.nextgenss.com/papers/ms03-007-ntdll.pdf</ref>
            <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q815021">Q815021</ref>
            <ref source="CONFIRM" url="http://microsoft.com/downloads/details.aspx?FamilyId=C9A38D45-5145-4844-B62E-C69D32AC929B&amp;displaylang=en">http://microsoft.com/downloads/details.aspx?FamilyId=C9A38D45-5145-4844-B62E-C69D32AC929B&amp;displaylang=en</ref>
            <ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104826785731151&amp;w=2">20030321 New attack vectors and a vulnerability dissection of MS03-007</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105768156625699&amp;w=2">20030708 WDAV exploit without netcat and with pretty magic number</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104887148323552&amp;w=2">20030328 Fate Research Labs Presents: Analysis of the NTDLL.DLL Exploit</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104869293619064&amp;w=2">20030326 WebDAV exploit: using wide character decoder scheme</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104861839130254&amp;w=2">20030325 IIS 5.0 WebDAV -Proof of concept-. Fully documented.</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104826476427372&amp;w=2">20030321 New attack vectors and a vulnerability dissection of MS03-007</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:109" sig="1">oval:org.mitre.oval:def:109</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="windows_2000">
                <vers edition=":datacenter_server" num="" />
                <vers edition=":professional" num="" />
                <vers edition=":server" num="" />
                <vers edition=":advanced_server" num="" />
                <vers edition="sp1" num="" />
                <vers edition="sp1:professional" num="" />
                <vers edition="sp1:server" num="" />
                <vers edition="sp1:advanced_server" num="" />
                <vers edition="sp1:datacenter_server" num="" />
                <vers edition="sp2" num="" />
                <vers edition="sp2:server" num="" />
                <vers edition="sp2:datacenter_server" num="" />
                <vers edition="sp2:professional" num="" />
                <vers edition="sp2:advanced_server" num="" />
                <vers edition="sp3" num="" />
                <vers edition="sp3:datacenter_server" num="" />
                <vers edition="sp3:advanced_server" num="" />
                <vers edition="sp3:server" num="" />
                <vers edition="sp3:professional" num="" />
            </prod>
            <prod vendor="microsoft" name="windows_2000_terminal_services">
                <vers edition="sp1" num="" />
                <vers edition="sp2" num="" />
                <vers edition="sp3" num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2003-0091" seq="2003-0091" severity="High" type="CVE" published="2003-04-02" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-10">
        <desc>
            <descript source="cve">Stack-based buffer overflow in the bsd_queue() function for lpq on Solaris 2.6 and 7 allows local users to gain root privilege.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="VULNWATCH" patch="1" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0162.html" adv="1">20030331 NSFOCUS SA2003-02: Solaris lpq Stack Buffer Overflow Vulnerability</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/316957/30/25250/threaded">20030331 NSFOCUS SA2003-02: Solaris lpq Stack Buffer Overflow Vulnerability</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/8713">8713</ref>
            <ref source="MISC" url="http://www.nsfocus.com/english/homepage/sa2003-02.htm">http://www.nsfocus.com/english/homepage/sa2003-02.htm</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-068.shtml">N-068</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-52443-1">52443</ref>
            <ref source="MISC" url="http://packetstormsecurity.org/0304-advisories/sa2003-02.txt">http://packetstormsecurity.org/0304-advisories/sa2003-02.txt</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4383" sig="1">oval:org.mitre.oval:def:4383</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers num="2.5.1" />
                <vers num="2.6" />
                <vers num="7.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2003-0092" seq="2003-0092" severity="High" type="CVE" published="2003-04-02" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-10">
        <desc>
            <descript source="cve">Heap-based buffer overflow in dtsession for Solaris 2.5.1 through Solaris 9 allows local users to gain root privileges via a long HOME environment variable.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="VULNWATCH" patch="1" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0163.html" adv="1">20030331 NSFOCUS SA2003-03: Solaris dtsession Heap Buffer Overflow Vulnerability</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/7240">7240</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/316948/30/25250/threaded">20030331 NSFOCUS SA2003-03: Solaris dtsession Heap Buffer Overflow Vulnerability</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-52388-1">52388</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1905" sig="1">oval:org.mitre.oval:def:1905</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers num="2.5.1" />
                <vers num="2.6" />
                <vers num="7.0" />
                <vers num="8.0" />
                <vers edition="" num="9.0" />
                <vers edition=":sparc" num="9.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" name="CVE-2003-0141" seq="2003-0141" severity="Medium" type="CVE" published="2003-04-02" CVSS_version="2.0 incomplete approximation" CVSS_score="5.1" modified="2008-09-05">
        <desc>
            <descript source="cve">The PNG deflate algorithm in RealOne Player 6.0.11.x and earlier, RealPlayer 8/RealPlayer Plus 8 6.0.9.584, and other versions allows remote attackers to corrupt the heap and overwrite arbitrary memory via a PNG graphic file format containing compressed data using fixed trees that contain the length values 286-287, which are treated as a very large length.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/705761" adv="1">VU#705761</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7177" adv="1">7177</ref>
            <ref source="MISC" patch="1" url="http://www.coresecurity.com/common/showdoc.php?idx=311&amp;idxseccion=10" adv="1">http://www.coresecurity.com/common/showdoc.php?idx=311&amp;idxseccion=10</ref>
            <ref source="MISC" url="http://www.coresecurity.com/common/showdoc.php?idx=311&amp;idxseccion=10">http://www.coresecurity.com/common/showdoc.php?idx=311&amp;idxseccion=10</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104887465427579&amp;w=2">20030328 CORE-2003-0306: RealPlayer PNG deflate heap corruption vulnerability</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0156.html">20030328 CORE-2003-0306: RealPlayer PNG deflate heap corruption vulnerability</ref>
        </refs>
        <vuln_soft>
            <prod vendor="realnetworks" name="realone_enterprise_desktop">
                <vers num="6.0.11.774" />
            </prod>
            <prod vendor="realnetworks" name="realone_player">
                <vers num="2.0" />
                <vers edition="gold" num="6.0.10.505" />
                <vers num="6.0.11.818" />
                <vers num="6.0.11.830" />
                <vers num="6.0.11.841" />
                <vers num="6.0.11.853" />
                <vers num="9.0.0.288" />
                <vers num="9.0.0.297" />
            </prod>
            <prod vendor="realnetworks" name="realplayer">
                <vers num="8.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0106" seq="2003-0106" severity="High" type="CVE" published="2003-04-02" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">The HTTP proxy for Symantec Enterprise Firewall (SEF) 7.0 allows proxy users to bypass pattern matching for blocked URLs via requests that are URL-encoded with escapes, Unicode, or UTF-8.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://service1.symantec.com/SUPPORT/ent-gate.nsf/docid/2003032507434754" adv="1">http://service1.symantec.com/SUPPORT/ent-gate.nsf/docid/2003032507434754</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104869513822233&amp;w=2" adv="1">20030326 Corsaire Security Advisory - Symantec Enterprise Firewall (SEF) H TTP URL pattern evasion issue</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/7196" adv="1">7196</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0152.html">20030326 Corsaire Security Advisory - Symantec Enterprise Firewall (SEF) H TTP URL pattern evasion issue</ref>
            <ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104868285106289&amp;w=2">20030326 Corsaire Security Advisory - Symantec Enterprise Firewall (SEF) H TTP URL pattern evasion issue</ref>
        </refs>
        <vuln_soft>
            <prod vendor="symantec" name="enterprise_firewall">
                <vers num="7.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0152" seq="2003-0152" severity="High" type="CVE" published="2003-04-02" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Unknown vulnerability in bonsai Mozilla CVS query tool allows remote attackers to execute arbitrary commands as the www-data user.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7162" adv="1">7162</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-265" adv="1">DSA-265</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mozilla" name="bonsai">
                <vers num="1.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0153" seq="2003-0153" severity="Medium" type="CVE" published="2003-04-02" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">bonsai Mozilla CVS query tool leaks the absolute pathname of the tool in certain error messages generated by (1) cvslog.cgi, (2) cvsview2.cgi, or (3) multidiff.cgi.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-265" adv="1">DSA-265</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/9921">bonsai-path-disclosure(9921)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=102980129101054&amp;w=2" adv="1">20020819 Advisory: Bonsai XSS and Physical Path Revealing Vulnerabilities</ref>
            <ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=187230">http://bugzilla.mozilla.org/show_bug.cgi?id=187230</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/5517">5517</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mozilla" name="bonsai">
                <vers num="1.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" name="CVE-2003-0154" seq="2003-0154" severity="Medium" type="CVE" published="2003-04-02" CVSS_version="2.0 incomplete approximation" CVSS_score="6.8" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting vulnerabilities (XSS) in bonsai Mozilla CVS query tool allow remote attackers to execute arbitrary web script via (1) the file, root, or rev parameters to cvslog.cgi, (2) the file or root parameters to cvsblame.cgi, (3) various parameters to cvsquery.cgi, (4) the person parameter to showcheckins.cgi, (5) the module parameter to cvsqueryform.cgi, and (6) possibly other attack vectors as identified by Mozilla bug #146244.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/5516" adv="1">5516</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-265" adv="1">DSA-265</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/9920.php">bonsai-error-message-xss(9920)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=102980129101054&amp;w=2" adv="1">20020819 Advisory: Bonsai XSS and Physical Path Revealing Vulnerabilities</ref>
            <ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=163573">http://bugzilla.mozilla.org/show_bug.cgi?id=163573</ref>
            <ref source="MISC" url="http://bugzilla.mozilla.org/show_bug.cgi?id=146244">http://bugzilla.mozilla.org/show_bug.cgi?id=146244</ref>
            <ref source="CONFIRM" url="http://bugzilla.mozilla.org/attachment.cgi?id=95985&amp;action=view">http://bugzilla.mozilla.org/attachment.cgi?id=95985&amp;action=view</ref>
            <ref source="CONFIRM" url="http://bugzilla.mozilla.org/attachment.cgi?id=95950&amp;action=view">http://bugzilla.mozilla.org/attachment.cgi?id=95950&amp;action=view</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mozilla" name="bonsai">
                <vers num="1.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0155" seq="2003-0155" severity="Medium" type="CVE" published="2003-04-02" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">bonsai Mozilla CVS query tool allows remote attackers to gain access to the parameters page without authentication.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7163" adv="1">7163</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-265" adv="1">DSA-265</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mozilla" name="bonsai">
                <vers num="1.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2003-0165" seq="2003-0165" severity="Medium" type="CVE" published="2003-04-02" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-10">
        <desc>
            <descript source="cve">Format string vulnerability in Eye Of Gnome (EOG) allows attackers to execute arbitrary code via format string specifiers in a command line argument for the file to display.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/363001">VU#363001</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7121" adv="1">7121</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2003-128.html" adv="1">RHSA-2003:128</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104887189724146&amp;w=2">20030328 CORE-2003-0304-03: Vulnerability in GNOME's Eye of Gnome</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0157.html">20030328 Vulnerability in GNOME's Eye of Gnome</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:048">MDKSA-2003:048</ref>
            <ref source="MISC" url="http://www.coresecurity.com/common/showdoc.php?idx=312&amp;idxseccion=10">http://www.coresecurity.com/common/showdoc.php?idx=312&amp;idxseccion=10</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:52" sig="1">oval:org.mitre.oval:def:52</ref>
        </refs>
        <vuln_soft>
            <prod vendor="gnome" name="eog">
                <vers num="1.0.0" />
                <vers num="1.0.1" />
                <vers num="1.0.2" />
                <vers num="1.0.3" />
                <vers num="1.0.4" />
                <vers num="1.1.1" />
                <vers num="1.1.2" />
                <vers num="1.1.3" />
                <vers num="1.1.4" />
                <vers num="2.2.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0166" seq="2003-0166" severity="High" type="CVE" published="2003-04-02" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Integer signedness error in emalloc() function for PHP before 4.3.2 allow remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via negative arguments to functions such as (1) socket_recv, (2) socket_recvfrom, and possibly other functions.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input bound="1" />
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/7198" adv="1">7198</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/7197" adv="1">7197</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104869828526885&amp;w=2" adv="1">20030326 @(#)Mordred Labs advisory - Integer overflow in PHP memory allocator</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104931415307111&amp;w=2">20030402 Inaccurate Reports Concerning PHP Vulnerabilities</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104878100719467&amp;w=2">20030327 RE: FUD-ALARM: @(#)Mordred Labs advisory - Integer overflow in PHP memory allocator</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000691">CLSA-2003:691</ref>
        </refs>
        <vuln_soft>
            <prod vendor="php" name="php">
                <vers num="4.0" />
                <vers num="4.0.1" />
                <vers num="4.0.2" />
                <vers num="4.0.3" />
                <vers num="4.0.4" />
                <vers num="4.0.5" />
                <vers num="4.0.6" />
                <vers num="4.0.7" />
                <vers num="4.1.0" />
                <vers num="4.1.1" />
                <vers num="4.1.2" />
                <vers num="4.2.0" />
                <vers num="4.2.1" />
                <vers num="4.2.2" />
                <vers num="4.2.3" />
                <vers num="4.3" />
                <vers num="4.3.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0167" seq="2003-0167" severity="High" type="CVE" published="2003-04-02" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple off-by-one buffer overflows in the IMAP capability for Mutt 1.3.28 and earlier, and Balsa 1.2.4 and earlier, allow a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a specially crafted mail folder, a different vulnerability than CVE-2003-0140.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7229" adv="1">7229</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-274" adv="1">DSA-274</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-300">DSA-300</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mutt" name="mutt">
                <vers num="1.3.12" />
                <vers num="1.3.12.1" />
                <vers num="1.3.16" />
                <vers num="1.3.17" />
                <vers num="1.3.22" />
                <vers num="1.3.24" />
                <vers num="1.3.25" />
                <vers num="1.3.27" />
                <vers num="1.3.28" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0168" seq="2003-0168" severity="High" type="CVE" published="2003-04-02" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in Apple QuickTime Player 5.x and 6.0 for Windows allows remote attackers to execute arbitrary code via a long QuickTime URL.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/112553">VU#112553</ref>
            <ref source="MISC" url="http://www.idefense.com/advisory/03.31.03.txt">http://www.idefense.com/advisory/03.31.03.txt</ref>
            <ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00027.html">http://lists.apple.com/mhonarc/security-announce/msg00027.html</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0166.html" adv="1">20030331 iDEFENSE Security Advisory 03.31.03: Buffer Overflow in Windows QuickTime Player</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11671">quicktime-url-bo(11671)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/7247">7247</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/317148/30/25220/threaded">20030401 iDEFENSE Security Advisory 03.31.03: Buffer Overflow in Windows QuickTime Player</ref>
            <ref source="APPLE" url="http://www.securityfocus.com/archive/1/archive/1/317141/30/25220/threaded">APPLE-SA-2003-03-31</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/10561">10561</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apple" name="quicktime">
                <vers num="5.0" />
                <vers num="6.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0159" seq="2003-0159" severity="High" type="CVE" published="2003-04-02" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Heap-based buffer overflow in the NTLMSSP code for Ethereal 0.9.9 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7050" adv="1">7050</ref>
            <ref source="CONFIRM" patch="1" url="http://www.ethereal.com/appnotes/enpa-sa-00008.html" adv="1">http://www.ethereal.com/appnotes/enpa-sa-00008.html</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_019_ethereal.html">SuSE-SA:2003:019</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-077.html">RHSA-2003:077</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:051">MDKSA-2003:051</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104741640924709&amp;w=2">20030309 GLSA:  ethereal (200303-10)</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:55" sig="1">oval:org.mitre.oval:def:55</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ethereal_group" name="ethereal">
                <vers num="0.8.18" />
                <vers num="0.9.0" />
                <vers num="0.9.1" />
                <vers num="0.9.2" />
                <vers num="0.9.3" />
                <vers num="0.9.4" />
                <vers num="0.9.5" />
                <vers num="0.9.6" />
                <vers num="0.9.7" />
                <vers num="0.9.8" />
                <vers num="0.9.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" name="CVE-2003-0160" seq="2003-0160" severity="Medium" type="CVE" published="2003-04-02" CVSS_version="2.0 incomplete approximation" CVSS_score="5.8" modified="2008-09-10">
        <desc>
            <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.2.11 allow remote attackers to inject arbitrary HTML code and steal information from a client's web browser.</descript>
        </desc>
        <loss_types>
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://sourceforge.net/mailarchive/forum.php?thread_id=1641953&amp;forum_id=1988">http://sourceforge.net/mailarchive/forum.php?thread_id=1641953&amp;forum_id=1988</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-112.html">RHSA-2003:112</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:614" sig="1">oval:org.mitre.oval:def:614</ref>
        </refs>
        <vuln_soft>
            <prod vendor="squirrelmail" name="squirrelmail">
                <vers num="1.2.11" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2003-0161" seq="2003-0161" severity="High" type="CVE" published="2003-04-02" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length check to be disabled when Sendmail misinterprets an input value as a special "NOCHAR" control value, allowing attackers to cause a denial of service and possibly execute arbitrary code via a buffer overflow attack using messages, a different vulnerability than CVE-2002-1337.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-2003-12.html" adv="1">CA-2003-12</ref>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/897604">VU#897604</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7230" adv="1">7230</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2003-120.html" adv="1">RHSA-2003:120</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-121.html">RHSA-2003:121</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-290">DSA-290</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-278">DSA-278</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104897487512238&amp;w=2" adv="1">20030329 Sendmail: -1 gone wild</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-March/004295.html">20030329 Sendmail: -1 gone wild</ref>
            <ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00028.html">http://lists.apple.com/mhonarc/security-announce/msg00028.html</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030401-01-P">20030401-01-P</ref>
            <ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.11/SCOSA-2004.11.txt">SCOSA-2004.11</ref>
            <ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-03:07.sendmail.asc">FreeBSD-SA-03:07</ref>
            <ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-016.0.txt">CSSA-2003-016.0</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/317135/30/25220/threaded">20030401 Immunix Secured OS 7+ openssl update</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/316961/30/25250/threaded">20030331 GLSA: sendmail (200303-27)</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/321997">20030520 [Fwd: 127 Research and Development: 127 Day!]</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200303-27.xml">GLSA-200303-27</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-52700-1">52700</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-52620-1">52620</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104914999806315&amp;w=2">20030330 [OpenPKG-SA-2003.027] OpenPKG Security Advisory (sendmail)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104896621106790&amp;w=2">20030329 sendmail 8.12.9 available</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000614">CLA-2003:614</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sendmail" name="sendmail">
                <vers num="2.6" />
                <vers num="2.6.1" />
                <vers num="2.6.2" />
                <vers num="3.0" />
                <vers num="3.0.1" />
                <vers num="3.0.2" />
                <vers num="3.0.3" />
                <vers num="8.10" />
                <vers num="8.10.1" />
                <vers num="8.10.2" />
                <vers num="8.11.0" />
                <vers num="8.11.1" />
                <vers num="8.11.2" />
                <vers num="8.11.3" />
                <vers num="8.11.4" />
                <vers num="8.11.5" />
                <vers num="8.11.6" />
                <vers edition="beta10" num="8.12" />
                <vers edition="beta12" num="8.12" />
                <vers edition="beta16" num="8.12" />
                <vers edition="beta5" num="8.12" />
                <vers edition="beta7" num="8.12" />
                <vers num="8.12.0" />
                <vers num="8.12.1" />
                <vers num="8.12.2" />
                <vers num="8.12.3" />
                <vers num="8.12.4" />
                <vers num="8.12.5" />
                <vers num="8.12.6" />
                <vers num="8.12.7" />
                <vers num="8.12.8" />
                <vers num="8.9.0" />
                <vers num="8.9.1" />
                <vers num="8.9.2" />
                <vers num="8.9.3" />
            </prod>
            <prod vendor="sendmail" name="sendmail_switch">
                <vers num="2.1" />
                <vers num="2.1.1" />
                <vers num="2.1.2" />
                <vers num="2.1.3" />
                <vers num="2.1.4" />
                <vers num="2.1.5" />
                <vers num="2.2" />
                <vers num="2.2.1" />
                <vers num="2.2.2" />
                <vers num="2.2.3" />
                <vers num="2.2.4" />
                <vers num="2.2.5" />
                <vers num="3.0" />
                <vers num="3.0.1" />
                <vers num="3.0.2" />
                <vers num="3.0.3" />
            </prod>
            <prod vendor="compaq" name="tru64">
                <vers num="4.0b" />
                <vers num="4.0d" />
                <vers num="4.0d_pk9_bl17" />
                <vers num="4.0f" />
                <vers num="4.0f_pk6_bl17" />
                <vers num="4.0f_pk7_bl18" />
                <vers num="4.0g" />
                <vers num="4.0g_pk3_bl17" />
                <vers num="5.0" />
                <vers num="5.0_pk4_bl17" />
                <vers num="5.0_pk4_bl18" />
                <vers num="5.0a" />
                <vers num="5.0a_pk3_bl17" />
                <vers num="5.0f" />
                <vers num="5.1" />
                <vers num="5.1_pk3_bl17" />
                <vers num="5.1_pk4_bl18" />
                <vers num="5.1_pk5_bl19" />
                <vers num="5.1_pk6_bl20" />
                <vers num="5.1a" />
                <vers num="5.1a_pk1_bl1" />
                <vers num="5.1a_pk2_bl2" />
                <vers num="5.1a_pk3_bl3" />
                <vers num="5.1b" />
                <vers num="5.1b_pk1_bl1" />
            </prod>
            <prod vendor="hp" name="hp-ux">
                <vers num="10.00" />
                <vers num="10.01" />
                <vers num="10.08" />
                <vers num="10.09" />
                <vers num="10.10" />
                <vers num="10.16" />
                <vers num="10.20" />
                <vers num="10.24" />
                <vers num="10.26" />
                <vers num="10.30" />
                <vers num="10.34" />
                <vers num="11.0.4" />
                <vers num="11.00" />
                <vers num="11.11" />
                <vers num="11.20" />
                <vers num="11.22" />
            </prod>
            <prod vendor="hp" name="hp-ux_series_700">
                <vers num="10.20" />
            </prod>
            <prod vendor="hp" name="hp-ux_series_800">
                <vers num="10.20" />
            </prod>
            <prod vendor="hp" name="sis">
                <vers num="" />
            </prod>
            <prod vendor="sun" name="solaris">
                <vers edition="" num="2.4" />
                <vers edition=":x86" num="2.4" />
                <vers edition="" num="2.5" />
                <vers edition=":x86" num="2.5" />
                <vers edition="" num="2.5.1" />
                <vers edition=":ppc" num="2.5.1" />
                <vers edition=":x86" num="2.5.1" />
                <vers edition="" num="2.6" />
                <vers edition=":x86" num="2.6" />
                <vers edition="" num="7.0" />
                <vers edition=":x86" num="7.0" />
                <vers edition="" num="8.0" />
                <vers edition=":x86" num="8.0" />
                <vers edition="" num="9.0" />
                <vers edition=":x86" num="9.0" />
                <vers edition=":sparc" num="9.0" />
                <vers edition="x86_update_2" num="9.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0162" seq="2003-0162" severity="High" type="CVE" published="2003-04-02" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Ecartis 1.0.0 (formerly listar) before snapshot 20030227 allows remote attackers to reset passwords of other users and gain privileges by modifying hidden form fields in the HTML page.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/6971" adv="1">6971</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11431" adv="1">ecartis-password-reset(11431)</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-271">DSA-271</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104673407728323&amp;w=2" adv="1">20030303 Re: Ecardis Password Reseting Vulnerability</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104636153214262&amp;w=2">20030227 Ecardis Password Reseting Vulnerability</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ecartis" name="ecartis">
                <vers num="1.0.0_snapshot_2002-10-13" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0082" seq="2003-0082" severity="Medium" type="CVE" published="2003-04-02" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes the KDC to corrupt its heap (aka "buffer underrun").</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-266" adv="1">DSA-266</ref>
            <ref source="CONFIRM" patch="1" url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-005-buf.txt" adv="1">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-005-buf.txt</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-091.html">RHSA-2003:091</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-052.html">RHSA-2003:052</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-051.html">RHSA-2003:051</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/7185">7185</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/316960/30/25250/threaded">20030331 GLSA: krb5 &amp; mit-krb5 (200303-28)</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-54042-1">54042</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4430" sig="1">oval:org.mitre.oval:def:4430</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2536" sig="1">oval:org.mitre.oval:def:2536</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:244" sig="1">oval:org.mitre.oval:def:244</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mit" name="kerberos">
                <vers num="1.0" />
                <vers num="1.2.2.beta1" />
                <vers num="5-1.2" />
                <vers num="5-1.2.1" />
                <vers num="5-1.2.2" />
                <vers num="5-1.2.3" />
                <vers num="5-1.2.4" />
                <vers num="5-1.2.5" />
                <vers num="5-1.2.6" />
                <vers num="5-1.2.7" />
                <vers edition="alpha1" num="5-1.3" />
                <vers num="5_1.0.6" />
                <vers num="5_1.1" />
                <vers num="5_1.1.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0083" seq="2003-0083" severity="Medium" type="CVE" published="2003-04-02" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences, a different vulnerability than CVE-2003-0020.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2003-139.html" adv="1">RHSA-2003:139</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108034113406858&amp;w=2" adv="1">20040325 LNSA-#2004-0006: bug workaround for Apache 2.0.48</ref>
            <ref source="CONFIRM" url="http://cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/loggers/mod_log_config.c?only_with_tag=APACHE_2_0_BRANCH">http://cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/loggers/mod_log_config.c?only_with_tag=APACHE_2_0_BRANCH</ref>
            <ref source="CONFIRM" url="http://cvs.apache.org/viewcvs.cgi/apache-1.3/src/modules/standard/mod_log_config.c?only_with_tag=APACHE_1_3_25" adv="1">http://cvs.apache.org/viewcvs.cgi/apache-1.3/src/modules/standard/mod_log_config.c?only_with_tag=APACHE_1_3_25</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/8146">8146</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=108024081011678&amp;w=2">20040325 GLSA200403-04 Multiple security vulnerabilities in Apache 2</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:151" sig="1">oval:org.mitre.oval:def:151</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apache" name="http_server">
                <vers num="1.3" />
                <vers num="2.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0072" seq="2003-0072" severity="Medium" type="CVE" published="2003-04-02" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes an out-of-bounds read of an array (aka "array overrun").</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-266" adv="1">DSA-266</ref>
            <ref source="CONFIRM" patch="1" url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-005-buf.txt" adv="1">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-005-buf.txt</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-052.html">RHSA-2003:052</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-051.html">RHSA-2003:051</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/7184">7184</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/316960/30/25250/threaded">20030331 GLSA: krb5 &amp; mit-krb5 (200303-28)</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-54042-1">54042</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mit" name="kerberos">
                <vers num="1.0" />
                <vers num="1.2.2.beta1" />
                <vers num="5-1.2" />
                <vers num="5-1.2.1" />
                <vers num="5-1.2.2" />
                <vers num="5-1.2.3" />
                <vers num="5-1.2.4" />
                <vers num="5-1.2.5" />
                <vers num="5-1.2.6" />
                <vers num="5-1.2.7" />
                <vers edition="alpha1" num="5-1.3" />
                <vers num="5_1.0.6" />
                <vers num="5_1.1" />
                <vers num="5_1.1.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0172" seq="2003-0172" severity="High" type="CVE" published="2003-04-02" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in openlog function for PHP 4.3.1 on Windows operating system, and possibly other OSes, allows remote attackers to cause a crash and possibly execute arbitrary code via a long filename argument.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7210" adv="1">7210</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104878149020152&amp;w=2" adv="1">20030327 @(#)Mordred Labs advisory - PHP for Win32: buffer overflow in openlog() function</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11637">php-openlog-stack-bo(11637)</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/385238">20041222 PHP v4.3.x exploit for Windows.</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/316583">20030327 Re: @(#)Mordred Labs advisory - PHP for Win32: buffer overflow in openlog() function</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/2113">2113</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104931415307111&amp;w=2">20030402 Inaccurate Reports Concerning PHP Vulnerabilities</ref>
        </refs>
        <vuln_soft>
            <prod vendor="php" name="php">
                <vers num="4.3.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2003-0178" seq="2003-0178" severity="High" type="CVE" published="2003-04-02" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple buffer overflows in Lotus Domino Web Server before 6.0.1 allow remote attackers to cause a denial of service or execute arbitrary code via (1) the s_ViewName option in the PresetFields parameter for iNotes, (2) the Foldername option in the PresetFields parameter for iNotes, or (3) a long Host header, which is inserted into a long Location header and used during a redirect operation.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/772817" adv="1">VU#772817</ref>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/542873">VU#542873</ref>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/206361">VU#206361</ref>
            <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-11.html">CA-2003-11</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/6871" adv="1">6871</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104550063431461&amp;w=2" adv="1">20030217 Lotus Domino Web Server iNotes Overflow (#NISR17022003b)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11337" adv="1">lotus-domino-hostname-bo(11337)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11336">lotus-domino-inotes-bo(11336)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6870">6870</ref>
            <ref source="MISC" url="http://www.nextgenss.com/advisories/lotus-inotesoflow.txt">http://www.nextgenss.com/advisories/lotus-inotesoflow.txt</ref>
            <ref source="MISC" url="http://www.nextgenss.com/advisories/lotus-hostlocbo.txt">http://www.nextgenss.com/advisories/lotus-hostlocbo.txt</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-065.shtml">N-065</ref>
            <ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104558778331387&amp;w=2">20030217 Domino Advisories UPDATE</ref>
            <ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104558777531350&amp;w=2">20030217 Lotus Domino Web Server iNotes Overflow (#NISR17022003b)</ref>
            <ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104558777331345&amp;w=2">20030217 Lotus Domino Web Server Host/Location Buffer Overflow Vulnerability (#NISR17022003a)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104550335103136&amp;w=2">20030217 Domino Advisories UPDATE</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104550063431463&amp;w=2">20030217 Lotus Domino Web Server Host/Location Buffer Overflow Vulnerability (#NISR17022003a)</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0082.html">20030217 Lotus iNotes Client ActiveX Control Buffer Overrun (#NISR17022003c)</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0081.html">20030217 Lotus Domino Web Server iNotes Overflow (#NISR17022003b)</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0080.html">20030217 Lotus Domino Web Server Host/Location Buffer Overflow Vulnerability (#NISR17022003a)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ibm" name="lotus_domino_web_server">
                <vers num="6.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0179" seq="2003-0179" severity="High" type="CVE" published="2003-04-02" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in the COM Object Control Handler for Lotus Domino 6.0.1 and earlier allows remote attackers to execute arbitrary code via multiple attack vectors, as demonstrated using the InitializeUsingNotesUserName method in the iNotes ActiveX control.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/571297" adv="1">VU#571297</ref>
            <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-11.html">CA-2003-11</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/6872" adv="1">6872</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104550124032513&amp;w=2" adv="1">20030217 Lotus iNotes Client ActiveX Control Buffer Overrun (#NISR17022003c)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11339">lotus-notes-activex-bo(11339)</ref>
            <ref source="MISC" url="http://www.nextgenss.com/advisories/lotus-inotesclientaxbo.txt">http://www.nextgenss.com/advisories/lotus-inotesclientaxbo.txt</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-065.shtml">N-065</ref>
            <ref source="CONFIRM" url="http://www-1.ibm.com/support/docview.wss?uid=swg21104543">http://www-1.ibm.com/support/docview.wss?uid=swg21104543</ref>
            <ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104558778331387&amp;w=2">20030217 Domino Advisories UPDATE</ref>
            <ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=104558778131373&amp;w=2">20030217 Lotus iNotes Client ActiveX Control Buffer Overrun (#NISR17022003c)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104550335103136&amp;w=2">20030217 Domino Advisories UPDATE</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0082.html">20030217 Lotus iNotes Client ActiveX Control Buffer Overrun (#NISR17022003c)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ibm" name="lotus_domino_web_server">
                <vers num="6.0" />
            </prod>
            <prod vendor="ibm" name="lotus_notes_client">
                <vers num="6.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0180" seq="2003-0180" severity="Medium" type="CVE" published="2003-04-02" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via an incomplete POST request, as demonstrated using the h_PageUI form.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/355169" adv="1">VU#355169</ref>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-2003-11.html" adv="1">CA-2003-11</ref>
            <ref source="MISC" patch="1" url="http://www.nextgenss.com/advisories/lotus-60dos.txt" adv="1">http://www.nextgenss.com/advisories/lotus-60dos.txt</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11360">lotus-incomplete-post-dos(11360)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6951">6951</ref>
            <ref source="MISC" url="http://www.nextgenss.com/advisories/lotus-60dos.txt">http://www.nextgenss.com/advisories/lotus-60dos.txt</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-065.shtml">N-065</ref>
            <ref source="CONFIRM" url="http://www-1.ibm.com/support/docview.wss?uid=swg21104528">http://www-1.ibm.com/support/docview.wss?uid=swg21104528</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0086.html">20030218 More Lotus Domino Advisories</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ibm" name="lotus_domino_web_server">
                <vers num="6.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0181" seq="2003-0181" severity="Medium" type="CVE" published="2003-04-02" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via a "Fictionary Value Field POST request" as demonstrated using the s_Validation form with a long, unknown parameter name.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-2003-11.html" adv="1">CA-2003-11</ref>
            <ref source="MISC" patch="1" url="http://www.nextgenss.com/advisories/lotus-60dos.txt" adv="1">http://www.nextgenss.com/advisories/lotus-60dos.txt</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11361">lotus-invalid-field-dos(11361)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6951">6951</ref>
            <ref source="CONFIRM" url="http://www-1.ibm.com/support/docview.wss?uid=swg21104528">http://www-1.ibm.com/support/docview.wss?uid=swg21104528</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0086.html">20030218 More Lotus Domino Advisories</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ibm" name="lotus_domino_web_server">
                <vers num="6.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2003-0197" seq="2003-0197" severity="High" type="CVE" published="2003-04-11" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-10">
        <desc>
            <descript source="cve">Buffer overflow gds_lock_mgr of Interbase Database 6.x allows local users to gain privileges via a long ISC_LOCK_ENV environment variable (INTERBASE_LOCK).</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="MISC" patch="1" url="http://www.secnetops.com/research/advisories/SRT2003-04-03-1300.txt" adv="1">http://www.secnetops.com/research/advisories/SRT2003-04-03-1300.txt</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104940730819887&amp;w=2">20030403 SRT2003-04-03-1300 - Interbase ISC_LOCK_ENV overflow</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0003.html">20030403 SRT2003-04-03-1300 - Interbase ISC_LOCK_ENV overflow</ref>
        </refs>
        <vuln_soft>
            <prod vendor="borland_software" name="interbase">
                <vers num="6.0" />
                <vers num="6.4" />
                <vers num="6.5" />
            </prod>
            <prod vendor="firebirdsql" name="firebird">
                <vers num="1.0.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0203" seq="2003-0203" severity="High" type="CVE" published="2003-04-11" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in moxftp 2.2 and earlier allows remote malicious FTP servers to execute arbitrary code via a long FTP banner.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/6921" adv="1">6921</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11399" adv="1">moxftp-welcome-banner-bo(11399)</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-281">DSA-281</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104610380126860&amp;w=2" adv="1">20030223 moxftp arbitrary code execution poc/advisory</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1006156">1006156</ref>
            <ref source="FULLDISC" url="http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2003-02/0338.html">20030223 moxftp arbitrary code execution poc/advisory</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/8136">8136</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104610380126860&amp;w=2">20030223 moxftp arbitrary code execution poc/advisory</ref>
        </refs>
        <vuln_soft>
            <prod vendor="moxftp" name="moxftp">
                <vers num="2.2" />
            </prod>
            <prod vendor="xftp" name="xftp">
                <vers num="2.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0169" seq="2003-0169" severity="Medium" type="CVE" published="2003-04-11" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">hpnst.exe in the GoAhead-Webs webserver for HP Instant TopTools before 5.55 allows remote attackers to cause a denial of service (CPU consumption) via a request to hpnst.exe that calls itself, which causes an infinite loop.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7246" adv="1">7246</ref>
            <ref source="VULNWATCH" patch="1" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0164.html" adv="1">20030331 [DDI-1012] Malformed request causes denial of service in HP Instant TopTools</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104914959705949&amp;w=2">20030331 [DDI-1012] Malformed request causes denial of service in HP Instant TopTools</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="instant_toptools">
                <vers num="5.04" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0134" seq="2003-0134" severity="Medium" type="CVE" published="2003-04-11" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Unknown vulnerability in filestat.c for Apache running on OS2, versions 2.0 through 2.0.45, allows unknown attackers to cause a denial of service via requests related to device names.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104931360606484&amp;w=2" adv="1">20030402 [ANNOUNCE] Apache 2.0.45 Released</ref>
            <ref source="CONFIRM" patch="1" url="http://cvs.apache.org/viewcvs/apr/file_io/os2/filestat.c.diff?r1=1.34&amp;r2=1.35">http://cvs.apache.org/viewcvs/apr/file_io/os2/filestat.c.diff?r1=1.34&amp;r2=1.35</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105418115512559&amp;w=2">20030528 [SECURITY] [ANNOUNCE] Apache 2.0.46 released</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apache" name="http_server">
                <vers num="2.0" />
                <vers num="2.0.28" />
                <vers num="2.0.32" />
                <vers num="2.0.35" />
                <vers num="2.0.36" />
                <vers num="2.0.37" />
                <vers num="2.0.38" />
                <vers num="2.0.39" />
                <vers num="2.0.40" />
                <vers num="2.0.41" />
                <vers num="2.0.42" />
                <vers num="2.0.43" />
                <vers num="2.0.44" />
                <vers num="2.0.45" />
                <vers num="2.0.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0135" seq="2003-0135" severity="High" type="CVE" published="2003-04-11" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">vsftpd FTP daemon in Red Hat Linux 9 is not compiled against TCP wrappers (tcp_wrappers) but is installed as a standalone service, which inadvertently prevents vsftpd from restricting access as intended.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7253" adv="1">7253</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2003-084.html" adv="1">RHSA-2003:084</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:634" sig="1">oval:org.mitre.oval:def:634</ref>
        </refs>
        <vuln_soft>
            <prod vendor="redhat" name="linux">
                <vers edition="" num="9.0" />
                <vers edition=":i386" num="9.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0132" seq="2003-0132" severity="Medium" type="CVE" published="2003-04-11" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2009-05-13">
        <desc>
            <descript source="cve">A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via large chunks of linefeed characters, which causes Apache to allocate 80 bytes for each linefeed.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <design />
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/206537">VU#206537</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104931360606484&amp;w=2" adv="1">20030402 [ANNOUNCE] Apache 2.0.45 Released</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/1233">ADV-2009-1233</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-139.html">RHSA-2003:139</ref>
            <ref source="MISC" url="http://www.idefense.com/advisory/04.08.03.txt">http://www.idefense.com/advisory/04.08.03.txt</ref>
            <ref source="MISC" url="http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=205147">http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=205147</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/8499">8499</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/34920">34920</ref>
            <ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00028.html">http://lists.apple.com/mhonarc/security-announce/msg00028.html</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105013378320711&amp;w=2">20030411 PATCH: [CAN-2003-0132] Apache 2.0.44 Denial of Service</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105001663120995&amp;w=2">20030410 working apache &lt;= 2.0.44 DoS exploit for linux.</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104994309010974&amp;w=2">20030408 Exploit Code Released for Apache 2.x Memory Leak</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104994239010517&amp;w=2">20030409 GLSA:  apache (200304-01)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104982175321731&amp;w=2">20030408 iDEFENSE Security Advisory 04.08.03: Denial of Service in Apache HTTP Server 2.x</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:156" sig="1">oval:org.mitre.oval:def:156</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apache" name="http_server">
                <vers num="2.0" />
                <vers num="2.0.28" />
                <vers num="2.0.32" />
                <vers num="2.0.35" />
                <vers num="2.0.36" />
                <vers num="2.0.37" />
                <vers num="2.0.38" />
                <vers num="2.0.39" />
                <vers num="2.0.40" />
                <vers num="2.0.41" />
                <vers num="2.0.42" />
                <vers num="2.0.43" />
                <vers num="2.0.44" />
                <vers num="2.0.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-1054" seq="2003-1054" severity="Medium" type="CVE" published="2003-04-16" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">mod_access_referer 1.0.2 allows remote attackers to cause a denial of service (crash) via a malformed Referer header that is missing a hostname, as parsed by the ap_parse_uri_components function in Apache, which triggers a null dereference.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7375" adv="1">7375</ref>
            <ref source="MISC" patch="1" url="http://sourceforge.net/project/shownotes.php?release_id=151905">http://sourceforge.net/project/shownotes.php?release_id=151905</ref>
            <ref source="FULLDISC" patch="1" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-April/004555.html" adv="1">20030416 [VulnWatch] Apache mod_access_referer denial of service issue</ref>
            <ref source="CONFIRM" url="http://www.vuxml.org/freebsd/af747389-42ba-11d9-bd37-00065be4b5b6.html" adv="1">http://www.vuxml.org/freebsd/af747389-42ba-11d9-bd37-00065be4b5b6.html</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/8612" adv="1">8612</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mod_access_referer" name="mod_access_referer">
                <vers num="1.0.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-1070" seq="2003-1070" severity="Medium" type="CVE" published="2003-04-28" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Unknown vulnerability in rpcbind for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (rpcbind crash).</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/11906" adv="1">sun-rpcbind-dos(11906)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7455" adv="1">7455</ref>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-50922-1" adv="1">50922</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/8685/" adv="1">8685</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers edition="" num="2.6" />
                <vers edition=":x86" num="2.6" />
                <vers edition="" num="7.0" />
                <vers edition=":x86" num="7.0" />
                <vers edition="" num="8.0" />
                <vers edition=":x86" num="8.0" />
                <vers edition="" num="9.0" />
                <vers edition=":x86" num="9.0" />
                <vers edition=":sparc" num="9.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2003-1072" seq="2003-1072" severity="Low" type="CVE" published="2003-04-28" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-10">
        <desc>
            <descript source="cve">Memory leak in lofiadm in Solaris 8 allows local users to cause a denial of service (kernel memory consumption).</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/8686/">8686</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11895">sun-lofiadm-dos(11895)</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-54100-1" adv="1">54100</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/7454">7454</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers edition="" num="8.0" />
                <vers edition=":x86" num="8.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0133" seq="2003-0133" severity="Medium" type="CVE" published="2003-05-05" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">GtkHTML, as included in Evolution before 1.2.4, allows remote attackers to cause a denial of service (crash) via certain malformed messages.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2003-126.html" adv="1">RHSA-2003:126</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:046">MDKSA-2003:046</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000737">CLA-2003:737</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:138" sig="1">oval:org.mitre.oval:def:138</ref>
        </refs>
        <vuln_soft>
            <prod vendor="gnome" name="gtkhtml">
                <vers num="1.1.10" />
                <vers num="1.1.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2003-0136" seq="2003-0136" severity="Low" type="CVE" published="2003-05-05" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-10">
        <desc>
            <descript source="cve">psbanner in the LPRng package allows local users to overwrite arbitrary files via a symbolic link attack on the /tmp/before file.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2003-142.html" adv="1">RHSA-2003:142</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-285" adv="1">DSA-285</ref>
            <ref source="CONFIRM" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?archive=no&amp;bug=188366">http://bugs.debian.org/cgi-bin/bugreport.cgi?archive=no&amp;bug=188366</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:423" sig="1">oval:org.mitre.oval:def:423</ref>
        </refs>
        <vuln_soft>
            <prod vendor="astart_technologies" name="lprng">
                <vers num="3.7.4" />
                <vers num="3.8.10.1" />
                <vers num="3.8.19" />
                <vers num="3.8.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0163" seq="2003-0163" severity="Medium" type="CVE" published="2003-05-05" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">decrypt_msg for the Gaim-Encryption GAIM plugin 1.15 and earlier does not properly validate a message length parameter, which allows remote attackers to cause a denial of service (crash) via a negative length, which overwrites arbitrary heap memory with a zero byte.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7182" adv="1">7182</ref>
            <ref source="MISC" patch="1" url="http://www.rapid7.com/advisories/R7-0013.html" adv="1">http://www.rapid7.com/advisories/R7-0013.html</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105013281120352&amp;w=2">20030412 R7-0013: Heap Corruption in Gaim-Encryption Plugin</ref>
        </refs>
        <vuln_soft>
            <prod vendor="gaim-encryption" name="gaim-encryption">
                <vers num="1.13" />
                <vers num="1.14" />
                <vers num="1.15" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0110" seq="2003-0110" severity="Medium" type="CVE" published="2003-05-05" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">The Winsock Proxy service in Microsoft Proxy Server 2.0 and the Microsoft Firewall service in Internet Security and Acceleration (ISA) Server 2000 allow remote attackers to cause a denial of service (CPU consumption or packet storm) via a spoofed, malformed packet to UDP port 1745.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MS" patch="1" url="http://www.microsoft.com/technet/security/bulletin/ms03-012.asp" adv="1">MS03-012</ref>
            <ref source="MISC" patch="1" url="http://www.idefense.com/advisory/04.09.03.txt" adv="1">http://www.idefense.com/advisory/04.09.03.txt</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104994487012027&amp;w=2">20030409 iDEFENSE Security Advisory 04.09.03: Denial of Service in Microsoft Proxy Server and Internet Security and Acceleration Server 2000</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:406" sig="1">oval:org.mitre.oval:def:406</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="isa_server">
                <vers edition="fp1" num="2000" />
                <vers edition="sp1" num="2000" />
            </prod>
            <prod vendor="microsoft" name="proxy_server">
                <vers edition="sp1" num="2.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0111" seq="2003-0111" severity="High" type="CVE" published="2003-05-05" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">The ByteCode Verifier component of Microsoft Virtual Machine (VM) build 5.0.3809 and earlier, as used in Windows and Internet Explorer, allows remote attackers to bypass security checks and execute arbitrary code via a malicious Java applet, aka "Flaw in Microsoft VM Could Enable System Compromise."</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/447569" adv="1">VU#447569</ref>
            <ref source="MS" patch="1" url="http://www.microsoft.com/technet/security/bulletin/ms03-011.asp" adv="1">MS03-011</ref>
            <ref source="XF" patch="1" url="http://www.iss.net/security_center/static/11751.php" adv="1">msvm-bytecode-improper-validation(11751)</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:136" sig="1">oval:org.mitre.oval:def:136</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="virtual_machine">
                <vers num="3802" />
                <vers num="3805" />
                <vers num="3809" />
            </prod>
            <prod vendor="microsoft" name="windows_2000">
                <vers edition=":datacenter_server" num="" />
                <vers edition=":professional" num="" />
                <vers edition=":server" num="" />
                <vers edition=":advanced_server" num="" />
                <vers edition="sp1" num="" />
                <vers edition="sp1:professional" num="" />
                <vers edition="sp1:server" num="" />
                <vers edition="sp1:advanced_server" num="" />
                <vers edition="sp1:datacenter_server" num="" />
                <vers edition="sp2" num="" />
                <vers edition="sp2:server" num="" />
                <vers edition="sp2:datacenter_server" num="" />
                <vers edition="sp2:professional" num="" />
                <vers edition="sp2:advanced_server" num="" />
                <vers edition="sp3" num="" />
                <vers edition="sp3:datacenter_server" num="" />
                <vers edition="sp3:advanced_server" num="" />
                <vers edition="sp3:server" num="" />
                <vers edition="sp3:professional" num="" />
            </prod>
            <prod vendor="microsoft" name="windows_2000_terminal_services">
                <vers edition="sp1" num="" />
                <vers edition="sp2" num="" />
                <vers edition="sp3" num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0204" seq="2003-0204" severity="High" type="CVE" published="2003-05-05" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">KDE 2 and KDE 3.1.1 and earlier 3.x versions allows attackers to execute arbitrary commands via (1) PostScript (PS) or (2) PDF files, related to missing -dPARANOIDSAFER and -dSAFER arguments when using the kghostview Ghostscript viewer.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.kde.org/info/security/advisory-20030409-1.txt" adv="1">http://www.kde.org/info/security/advisory-20030409-1.txt</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-284" adv="1">DSA-284</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-002.html">RHSA-2003:002</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-296">DSA-296</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-293">DSA-293</ref>
            <ref source="CONFIRM" url="http://bugs.kde.org/show_bug.cgi?id=56808">http://bugs.kde.org/show_bug.cgi?id=56808</ref>
            <ref source="CONFIRM" url="http://bugs.kde.org/show_bug.cgi?id=53343">http://bugs.kde.org/show_bug.cgi?id=53343</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:049">MDKSA-2003:049</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105034222521369&amp;w=2">20030414 GLSA:  kde-2.x (200304-05.1)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105017403010459&amp;w=2">20030412 [Sorcerer-spells] KDE-SORCERER2003-04-12</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105012994719099&amp;w=2">20030411 GLSA:  kde-2.x (200304-05)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105001557020141&amp;w=2">20030410 GLSA:  kde-3.x (200304-04)</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000747">CLA-2003:747</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000668">CLA-2003:668</ref>
        </refs>
        <vuln_soft>
            <prod vendor="kde" name="kde">
                <vers num="2.0" />
                <vers num="2.0.1" />
                <vers num="2.1" />
                <vers num="2.1.1" />
                <vers num="2.1.2" />
                <vers num="2.2" />
                <vers num="2.2.1" />
                <vers num="2.2.2" />
                <vers num="3.0" />
                <vers num="3.0.1" />
                <vers num="3.0.2" />
                <vers num="3.0.3" />
                <vers num="3.0.3a" />
                <vers num="3.0.4" />
                <vers num="3.0.5" />
                <vers num="3.0.5a" />
                <vers num="3.1" />
                <vers num="3.1.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" name="CVE-2003-0198" seq="2003-0198" severity="Medium" type="CVE" published="2003-05-05" CVSS_version="2.0 incomplete approximation" CVSS_score="6.4" modified="2008-09-10">
        <desc>
            <descript source="cve">Mac OS X before 10.2.5 allows guest users to modify the permissions of the DropBox folder and read unauthorized files.</descript>
        </desc>
        <loss_types>
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00028.html">http://lists.apple.com/mhonarc/security-announce/msg00028.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apple" name="mac_os_x">
                <vers num="10.0" />
                <vers num="10.0.1" />
                <vers num="10.0.2" />
                <vers num="10.0.3" />
                <vers num="10.0.4" />
                <vers num="10.1" />
                <vers num="10.1.1" />
                <vers num="10.1.2" />
                <vers num="10.1.3" />
                <vers num="10.1.4" />
                <vers num="10.1.5" />
                <vers num="10.2.1" />
                <vers num="10.2.2" />
                <vers num="10.2.3" />
                <vers num="10.2.4" />
            </prod>
            <prod vendor="apple" name="mac_os_x_server">
                <vers num="10.0" />
                <vers num="10.2" />
                <vers num="10.2.1" />
                <vers num="10.2.2" />
                <vers num="10.2.3" />
                <vers num="10.2.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2003-0201" seq="2003-0201" severity="High" type="CVE" published="2003-05-05" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/267873">VU#267873</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7294" adv="1">7294</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-280" adv="1">DSA-280</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104972664226781&amp;w=2" adv="1">20030407 [DDI-1013] Buffer Overflow in Samba allows remote root compromise</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-137.html">RHSA-2003:137</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_025_samba.html">SuSE-SA:2003:025</ref>
            <ref source="MISC" url="http://www.digitaldefense.net/labs/advisories/DDI-1013.txt">http://www.digitaldefense.net/labs/advisories/DDI-1013.txt</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030403-01-P">20030403-01-P</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:044">MDKSA-2003:044</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104994564212488&amp;w=2">20030409 GLSA:  samba (200304-02)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104981682014565&amp;w=2">20030408 [Sorcerer-spells] SAMBA--SORCERER2003-04-08</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104974612519064&amp;w=2">20030407 Immunix Secured OS 7+ samba update</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000624">CLA-2003:624</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:567" sig="1">oval:org.mitre.oval:def:567</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2163" sig="1">oval:org.mitre.oval:def:2163</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="cifs-9000_server">
                <vers num="a.01.05" />
                <vers num="a.01.06" />
                <vers num="a.01.07" />
                <vers num="a.01.08" />
                <vers num="a.01.08.01" />
                <vers num="a.01.09" />
                <vers num="a.01.09.01" />
                <vers num="a.01.09.02" />
            </prod>
            <prod vendor="samba" name="samba">
                <vers num="2.0.0" />
                <vers num="2.0.1" />
                <vers num="2.0.10" />
                <vers num="2.0.2" />
                <vers num="2.0.3" />
                <vers num="2.0.4" />
                <vers num="2.0.5" />
                <vers num="2.0.6" />
                <vers num="2.0.7" />
                <vers num="2.0.8" />
                <vers num="2.0.9" />
                <vers num="2.2.0" />
                <vers num="2.2.0a" />
                <vers num="2.2.1a" />
                <vers num="2.2.3a" />
                <vers num="2.2.4" />
                <vers num="2.2.5" />
                <vers num="2.2.6" />
                <vers num="2.2.7" />
                <vers num="2.2.7a" />
                <vers num="2.2.8" />
            </prod>
            <prod vendor="samba-tng" name="samba-tng">
                <vers num="0.3" />
                <vers num="0.3.1" />
            </prod>
            <prod vendor="apple" name="mac_os_x">
                <vers num="10.2" />
                <vers num="10.2.1" />
                <vers num="10.2.2" />
                <vers num="10.2.3" />
                <vers num="10.2.4" />
            </prod>
            <prod vendor="compaq" name="tru64">
                <vers num="4.0b" />
                <vers num="4.0d" />
                <vers num="4.0d_pk9_bl17" />
                <vers num="4.0f" />
                <vers num="4.0f_pk6_bl17" />
                <vers num="4.0f_pk7_bl18" />
                <vers num="4.0g" />
                <vers num="4.0g_pk3_bl17" />
                <vers num="5.0" />
                <vers num="5.0_pk4_bl17" />
                <vers num="5.0_pk4_bl18" />
                <vers num="5.0a" />
                <vers num="5.0a_pk3_bl17" />
                <vers num="5.0f" />
                <vers num="5.1" />
                <vers num="5.1_pk3_bl17" />
                <vers num="5.1_pk4_bl18" />
                <vers num="5.1_pk5_bl19" />
                <vers num="5.1_pk6_bl20" />
                <vers num="5.1a" />
                <vers num="5.1a_pk1_bl1" />
                <vers num="5.1a_pk2_bl2" />
                <vers num="5.1a_pk3_bl3" />
                <vers num="5.1b" />
                <vers num="5.1b_pk1_bl1" />
            </prod>
            <prod vendor="hp" name="hp-ux">
                <vers num="10.01" />
                <vers num="10.20" />
                <vers num="10.24" />
                <vers num="11.00" />
                <vers num="11.04" />
                <vers num="11.11" />
                <vers num="11.20" />
                <vers num="11.22" />
            </prod>
            <prod vendor="sun" name="solaris">
                <vers edition="" num="2.5.1" />
                <vers edition=":x86" num="2.5.1" />
                <vers edition=":ppc" num="2.5.1" />
                <vers edition="" num="2.6" />
                <vers edition=":x86" num="2.6" />
                <vers edition="" num="7.0" />
                <vers edition=":x86" num="7.0" />
                <vers edition="" num="8.0" />
                <vers edition=":x86" num="8.0" />
                <vers edition="" num="9.0" />
                <vers edition=":sparc" num="9.0" />
                <vers edition=":x86" num="9.0" />
                <vers edition="x86_update_2" num="9.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2003-0207" seq="2003-0207" severity="Low" type="CVE" published="2003-05-05" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-10">
        <desc>
            <descript source="cve">ps2epsi creates insecure temporary files when calling ghostscript, which allows local attackers to overwrite arbitrary files.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-286" adv="1">DSA-286</ref>
        </refs>
        <vuln_soft>
            <prod vendor="gs-common" name="gs-common">
                <vers num="0.3.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2003-0208" seq="2003-0208" severity="Medium" type="CVE" published="2003-05-05" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in Macromedia Flash ad user tracking capability allows remote attackers to insert arbitrary Javascript via the clickTAG field.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MISC" patch="1" url="http://www.securiteam.com/securitynews/5XP0B0U9PE.html" adv="1">http://www.securiteam.com/securitynews/5XP0B0U9PE.html</ref>
            <ref source="CONFIRM" patch="1" url="http://www.macromedia.com/support/flash/ts/documents/clicktag_security.htm" adv="1">http://www.macromedia.com/support/flash/ts/documents/clicktag_security.htm</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-April/004514.html">20030413 Misuse of Macromedia Flash Ads clickTAG Option May Lead to Privacy Breach</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105033712615013&amp;w=2">20030413 Misuse of Macromedia Flash Ads clickTAG Option May Lead to Privacy Breach</ref>
        </refs>
        <vuln_soft>
            <prod vendor="macromedia" name="flash">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2003-0209" seq="2003-0209" severity="High" type="CVE" published="2003-05-05" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Integer overflow in the TCP stream reassembly module (stream4) for Snort 2.0 and earlier allows remote attackers to execute arbitrary code via large sequence numbers in packets, which enable a heap-based buffer overflow.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/139129" adv="1">VU#139129</ref>
            <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-13.html">CA-2003-13</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7178" adv="1">7178</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-297">DSA-297</ref>
            <ref source="MISC" url="http://www.coresecurity.com/common/showdoc.php?idx=313&amp;idxseccion=10">http://www.coresecurity.com/common/showdoc.php?idx=313&amp;idxseccion=10</ref>
            <ref source="ENGARDE" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105172790914107&amp;w=2">ESA-20030430-013</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105154530427824&amp;w=2">20030428 GLSA:  snort (200304-06)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105111217731583&amp;w=2">20030423 Snort &lt;=1.9.1 exploit</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105103586927007&amp;w=2">20030422 GLSA:  snort (200304-05)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105043563016235&amp;w=2">20030415 CORE-2003-0307: Snort TCP Stream Reassembly Integer Overflow Vulnerability</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:052">MDKSA-2003:052</ref>
        </refs>
        <vuln_soft>
            <prod vendor="smoothwall" name="smoothwall">
                <vers num="2.0_beta_4" />
            </prod>
            <prod vendor="sourcefire" name="snort">
                <vers num="1.8" />
                <vers num="1.8.1" />
                <vers num="1.8.2" />
                <vers num="1.8.3" />
                <vers num="1.8.4" />
                <vers num="1.8.5" />
                <vers num="1.8.6" />
                <vers num="1.8.7" />
                <vers num="1.9" />
                <vers num="1.9.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0211" seq="2003-0211" severity="Medium" type="CVE" published="2003-05-05" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Memory leak in xinetd 2.3.10 allows remote attackers to cause a denial of service (memory consumption) via a large number of rejected connections.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105068673220605&amp;w=2" adv="1">20030418 Xinetd 2.3.10 Memory Leaks</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-160.html">RHSA-2003:160</ref>
            <ref source="CONFIRM" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=88537">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=88537</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:056">MDKSA-2003:056</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000782">CLA-2003:782</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:657" sig="1">oval:org.mitre.oval:def:657</ref>
        </refs>
        <vuln_soft>
            <prod vendor="xinetd" name="xinetd">
                <vers num="2.3.0" />
                <vers num="2.3.1" />
                <vers num="2.3.10" />
                <vers num="2.3.2" />
                <vers num="2.3.3" />
                <vers num="2.3.4" />
                <vers num="2.3.5" />
                <vers num="2.3.6" />
                <vers num="2.3.7" />
                <vers num="2.3.8" />
                <vers num="2.3.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2003-0173" seq="2003-0173" severity="High" type="CVE" published="2003-05-05" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-10">
        <desc>
            <descript source="cve">xfsdq in xfsdump does not create quota information files securely, which allows local users to gain root privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/111673">VU#111673</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-283" adv="1">DSA-283</ref>
            <ref source="SGI" patch="1" url="ftp://patches.sgi.com/support/free/security/advisories/20030404-01-P" adv="1">20030404-01-P</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:047">MDKSA-2003:047</ref>
        </refs>
        <vuln_soft>
            <prod vendor="xfsdump" name="xfsdump">
                <vers num="2.0.0" />
                <vers num="2.0.1" />
                <vers num="2.0.2" />
                <vers num="2.0.3" />
                <vers num="2.0.4" />
                <vers num="2.0.5" />
            </prod>
            <prod vendor="sgi" name="irix">
                <vers num="6.5" />
                <vers num="6.5.1" />
                <vers num="6.5.10" />
                <vers num="6.5.10f" />
                <vers num="6.5.10m" />
                <vers num="6.5.11" />
                <vers num="6.5.11f" />
                <vers num="6.5.11m" />
                <vers num="6.5.12" />
                <vers num="6.5.12f" />
                <vers num="6.5.12m" />
                <vers num="6.5.13" />
                <vers num="6.5.13f" />
                <vers num="6.5.13m" />
                <vers num="6.5.14" />
                <vers num="6.5.14f" />
                <vers num="6.5.14m" />
                <vers num="6.5.15" />
                <vers num="6.5.15f" />
                <vers num="6.5.15m" />
                <vers num="6.5.16" />
                <vers num="6.5.16f" />
                <vers num="6.5.16m" />
                <vers num="6.5.17" />
                <vers num="6.5.17f" />
                <vers num="6.5.17m" />
                <vers num="6.5.18" />
                <vers num="6.5.18f" />
                <vers num="6.5.18m" />
                <vers num="6.5.19" />
                <vers num="6.5.19f" />
                <vers num="6.5.19m" />
                <vers num="6.5.2" />
                <vers num="6.5.2f" />
                <vers num="6.5.2m" />
                <vers num="6.5.3" />
                <vers num="6.5.3f" />
                <vers num="6.5.3m" />
                <vers num="6.5.4" />
                <vers num="6.5.4f" />
                <vers num="6.5.4m" />
                <vers num="6.5.5" />
                <vers num="6.5.5f" />
                <vers num="6.5.5m" />
                <vers num="6.5.6" />
                <vers num="6.5.6f" />
                <vers num="6.5.6m" />
                <vers num="6.5.7" />
                <vers num="6.5.7f" />
                <vers num="6.5.7m" />
                <vers num="6.5.8" />
                <vers num="6.5.8f" />
                <vers num="6.5.8m" />
                <vers num="6.5.9" />
                <vers num="6.5.9f" />
                <vers num="6.5.9m" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2003-0171" seq="2003-0171" severity="High" type="CVE" published="2003-05-05" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-10">
        <desc>
            <descript source="cve">DirectoryServices in MacOS X trusts the PATH environment variable to locate and execute the touch command, which allows local users to execute arbitrary commands by modifying the PATH to point to a directory containing a malicious touch program.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2003/a041003-1.txt" adv="1">A041003-1</ref>
            <ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00028.html">http://lists.apple.com/mhonarc/security-announce/msg00028.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apple" name="mac_os_x">
                <vers num="10.0" />
                <vers num="10.0.1" />
                <vers num="10.0.2" />
                <vers num="10.0.3" />
                <vers num="10.0.4" />
                <vers num="10.1" />
                <vers num="10.1.1" />
                <vers num="10.1.2" />
                <vers num="10.1.3" />
                <vers num="10.1.4" />
                <vers num="10.1.5" />
                <vers num="10.2" />
                <vers num="10.2.1" />
                <vers num="10.2.2" />
                <vers num="10.2.3" />
                <vers num="10.2.4" />
            </prod>
            <prod vendor="apple" name="mac_os_x_server">
                <vers num="10.0" />
                <vers num="10.2" />
                <vers num="10.2.1" />
                <vers num="10.2.2" />
                <vers num="10.2.3" />
                <vers num="10.2.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2003-0196" seq="2003-0196" severity="High" type="CVE" published="2003-05-05" CVSS_version="2.0 incomplete approximation" CVSS_score="10.0" modified="2008-09-10">
        <desc>
            <descript source="cve">Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discovered by the Samba team and a different vulnerability than CVE-2003-0201.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2003-137.html" adv="1">RHSA-2003:137</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-280" adv="1">DSA-280</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104973186901597&amp;w=2" adv="1">20030407 [OpenPKG-SA-2003.028] OpenPKG Security Advisory (samba)</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:044">MDKSA-2003:044</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104974612519064&amp;w=2">20030407 Immunix Secured OS 7+ samba update</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:564" sig="1">oval:org.mitre.oval:def:564</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="cifs-9000_server">
                <vers num="a.01.05" />
                <vers num="a.01.06" />
                <vers num="a.01.07" />
                <vers num="a.01.08" />
                <vers num="a.01.08.01" />
                <vers num="a.01.09" />
                <vers num="a.01.09.01" />
                <vers num="a.01.09.02" />
            </prod>
            <prod vendor="samba" name="samba">
                <vers num="2.0.0" />
                <vers num="2.0.1" />
                <vers num="2.0.10" />
                <vers num="2.0.2" />
                <vers num="2.0.3" />
                <vers num="2.0.4" />
                <vers num="2.0.5" />
                <vers num="2.0.6" />
                <vers num="2.0.7" />
                <vers num="2.0.8" />
                <vers num="2.0.9" />
                <vers num="2.2.0" />
                <vers num="2.2.0a" />
                <vers num="2.2.1a" />
                <vers num="2.2.2" />
                <vers num="2.2.3" />
                <vers num="2.2.3a" />
                <vers num="2.2.4" />
                <vers num="2.2.5" />
                <vers num="2.2.6" />
                <vers num="2.2.7" />
                <vers num="2.2.7a" />
                <vers num="2.2.8" />
            </prod>
            <prod vendor="samba-tng" name="samba-tng">
                <vers num="0.3" />
                <vers num="0.3.1" />
            </prod>
            <prod vendor="compaq" name="tru64">
                <vers num="4.0b" />
                <vers num="4.0d" />
                <vers num="4.0d_pk9_bl17" />
                <vers num="4.0f" />
                <vers num="4.0f_pk6_bl17" />
                <vers num="4.0f_pk7_bl18" />
                <vers num="4.0g" />
                <vers num="4.0g_pk3_bl17" />
                <vers num="5.0" />
                <vers num="5.0_pk4_bl17" />
                <vers num="5.0_pk4_bl18" />
                <vers num="5.0a" />
                <vers num="5.0a_pk3_bl17" />
                <vers num="5.0f" />
                <vers num="5.1" />
                <vers num="5.1_pk3_bl17" />
                <vers num="5.1_pk4_bl18" />
                <vers num="5.1_pk5_bl19" />
                <vers num="5.1_pk6_bl20" />
                <vers num="5.1a" />
                <vers num="5.1a_pk1_bl1" />
                <vers num="5.1a_pk2_bl2" />
                <vers num="5.1a_pk3_bl3" />
                <vers num="5.1b" />
                <vers num="5.1b_pk1_bl1" />
            </prod>
            <prod vendor="hp" name="hp-ux">
                <vers num="10.01" />
                <vers num="10.20" />
                <vers num="10.24" />
                <vers num="11.00" />
                <vers num="11.04" />
                <vers num="11.11" />
                <vers num="11.20" />
                <vers num="11.22" />
            </prod>
            <prod vendor="sun" name="solaris">
                <vers edition="" num="2.5.1" />
                <vers edition=":x86" num="2.5.1" />
                <vers edition=":ppc" num="2.5.1" />
                <vers edition="" num="2.6" />
                <vers edition=":x86" num="2.6" />
                <vers edition="" num="7.0" />
                <vers edition=":x86" num="7.0" />
                <vers edition="" num="8.0" />
                <vers edition=":x86" num="8.0" />
                <vers edition="" num="9.0" />
                <vers edition=":sparc" num="9.0" />
                <vers edition=":x86" num="9.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2003-0334" seq="2003-0334" severity="Low" type="CVE" published="2003-05-10" CVSS_version="2.0 incomplete approximation" CVSS_score="2.1" modified="2008-09-10">
        <desc>
            <descript source="cve">BitchX IRC client 1.0c20cvs and earlier allows attackers to cause a denial of service (core dump) via certain channel mode changes that are not properly handled in names.c.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105259643606984&amp;w=2" adv="1">20030510 BitchX: Crash when channel modes change</ref>
            <ref source="CONECTIVA" patch="1" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000655" adv="1">CLA-2003:655</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/12008">bitchx-mode-change-dos(12008)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/7551">7551</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2003:069">MDKSA-2003:069</ref>
        </refs>
        <vuln_soft>
            <prod vendor="colten_edwards" name="bitchx">
                <vers num="1.0c20cvs" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" name="CVE-2003-1146" seq="2003-1146" severity="Medium" type="CVE" published="2003-05-11" CVSS_version="2.0 incomplete approximation" CVSS_score="6.8" modified="2008-09-05">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in John Beatty Easy PHP Photo Album 1.0 allows remote attackers to inject arbitrary web script or HTML via the dir parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/8977" adv="1">8977</ref>
            <ref source="MISC" url="http://security.nnov.ru/docs5347.html" adv="1">http://security.nnov.ru/docs5347.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="john_beatty" name="easy_php_photo_album">
                <vers num="1.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0218" seq="2003-0218" severity="High" type="CVE" published="2003-05-12" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in PostMethod() function for Monkey HTTP Daemon (monkeyd) 0.6.1 and earlier allows remote attackers to execute arbitrary code via a POST request with a large body.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7202" adv="1">7202</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105154473526898&amp;w=2" adv="1">20030428 GLSA:  monkeyd (200304-07.1)</ref>
            <ref source="VULNWATCH" patch="1" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0029.html" adv="1">20030420 Monkey HTTPd Remote Buffer Overflow</ref>
            <ref source="CONFIRM" url="http://monkeyd.sourceforge.net/Changelog.txt">http://monkeyd.sourceforge.net/Changelog.txt</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105094204204166&amp;w=2">20030420 Monkey HTTPd Remote Buffer Overflow</ref>
        </refs>
        <vuln_soft>
            <prod vendor="monkey" name="monkey_http_daemon">
                <vers num="0.4" />
                <vers num="0.4.1" />
                <vers num="0.4.2" />
                <vers num="0.5" />
                <vers num="0.5.1" />
                <vers num="0.6" />
                <vers num="0.6.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0219" seq="2003-0219" severity="High" type="CVE" published="2003-05-12" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to execute administrator commands by sniffing packets from a valid session and replaying them against the remote administration server.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/641012">VU#641012</ref>
            <ref source="MISC" patch="1" url="http://www.coresecurity.com/common/showdoc.php?idx=314&amp;idxseccion=10" adv="1">http://www.coresecurity.com/common/showdoc.php?idx=314&amp;idxseccion=10</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/7179">7179</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105155734411836&amp;w=2">20030428 CORE-2003-0305-02: Vulnerabilities in Kerio Personal Firewall</ref>
        </refs>
        <vuln_soft>
            <prod vendor="kerio" name="personal_firewall_2">
                <vers num="2.1" />
                <vers num="2.1.1" />
                <vers num="2.1.2" />
                <vers num="2.1.3" />
                <vers num="2.1.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0220" seq="2003-0220" severity="High" type="CVE" published="2003-05-12" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">Buffer overflow in the administrator authentication process for Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to execute arbitrary code via a handshake packet.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/454716">VU#454716</ref>
            <ref source="MISC" patch="1" url="http://www.coresecurity.com/common/showdoc.php?idx=314&amp;idxseccion=10" adv="1">http://www.coresecurity.com/common/showdoc.php?idx=314&amp;idxseccion=10</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/7180">7180</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105155734411836&amp;w=2">20030428 CORE-2003-0305-02: Vulnerabilities in Kerio Personal Firewall</ref>
        </refs>
        <vuln_soft>
            <prod vendor="kerio" name="personal_firewall_2">
                <vers num="2.1" />
                <vers num="2.1.1" />
                <vers num="2.1.2" />
                <vers num="2.1.3" />
                <vers num="2.1.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2003-0221" seq="2003-0221" severity="High" type="CVE" published="2003-05-12" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">The (1) dupatch and (2) setld utilities in HP Tru64 UNIX 5.1B PK1 and earlier allows local users to overwrite files and possibly gain root privileges via a symlink attack.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11892">tru64-dupatch-setld-symlink(11892)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/7452">7452</ref>
            <ref source="HP" url="http://www.ciac.org/ciac/bulletins/n-086.shtml">SSRT3471</ref>
        </refs>
        <vuln_soft>
            <prod vendor="hp" name="tru64">
                <vers edition="pk1" num="5.1b" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" name="CVE-2003-0222" seq="2003-0222" severity="High" type="CVE" published="2003-05-12" CVSS_version="2.0" CVSS_score="9.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Stack-based buffer overflow in Oracle Net Services for Oracle Database Server 9i release 2 and earlier allows attackers to execute arbitrary code via a "CREATE DATABASE LINK" query containing a connect string with a long USING parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7453" adv="1">7453</ref>
            <ref source="CONFIRM" patch="1" url="http://otn.oracle.com/deploy/security/pdf/2003alert54.pdf" adv="1">http://otn.oracle.com/deploy/security/pdf/2003alert54.pdf</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11885">oracle-database-link-bo(11885)</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-085.shtml">N-085</ref>
            <ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105163376015735&amp;w=2">20030429 Oracle Database Server Buffer Overflow Vulnerability (#NISR29042003)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105162831008176&amp;w=2">20030429 Oracle Database Server Buffer Overflow Vulnerability (#NISR29042003)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="database_server">
                <vers num="7.3.3" />
                <vers num="7.3.4" />
                <vers num="8.0.1" />
                <vers num="8.0.2" />
                <vers num="8.0.3" />
                <vers num="8.0.4" />
                <vers num="8.0.5" />
                <vers num="8.0.5.1" />
                <vers num="8.0.6" />
                <vers num="8.1.5" />
                <vers num="8.1.6" />
                <vers num="8.1.7" />
                <vers num="9.2.1" />
                <vers num="9.2.2" />
            </prod>
            <prod vendor="oracle" name="oracle8i">
                <vers num="8.0.6" />
                <vers num="8.0.6.3" />
                <vers num="8.0x" />
                <vers num="8.1.5" />
                <vers num="8.1.6" />
                <vers num="8.1.7" />
                <vers num="8.1.7.1" />
                <vers num="8.1.7.4" />
                <vers num="8.1x" />
            </prod>
            <prod vendor="oracle" name="oracle9i">
                <vers num="9.0" />
                <vers num="9.0.1" />
                <vers num="9.0.1.2" />
                <vers num="9.0.1.3" />
                <vers num="9.0.1.4" />
                <vers num="9.0.2" />
                <vers num="9.2.0.1" />
                <vers num="9.2.0.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0233" seq="2003-0233" severity="High" type="CVE" published="2003-05-12" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Heap-based buffer overflow in plugin.ocx for Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via the Load() method, a different vulnerability than CVE-2003-0115.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MS" patch="1" url="http://www.microsoft.com/technet/security/bulletin/ms03-015.asp" adv="1">MS03-015</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105120164927952&amp;w=2" adv="1">20030424 Internet Explorer Plugin.ocx heap overflow (#NISR24042003)</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/11854.php" adv="1">ie-plugin-load-bo(11854)</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1094" sig="1">oval:org.mitre.oval:def:1094</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="ie">
                <vers edition="sp1" num="5.0.1" />
                <vers edition="sp2" num="5.0.1" />
                <vers edition="sp3" num="5.0.1" />
                <vers edition="sp1" num="5.5" />
                <vers edition="sp2" num="5.5" />
                <vers edition="sp1" num="6.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0174" seq="2003-0174" severity="High" type="CVE" published="2003-05-12" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been provided by an LDAP server, which could allow attackers to log in without a password.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7442" adv="1">7442</ref>
            <ref source="SGI" patch="1" url="ftp://patches.sgi.com/support/free/security/advisories/20030407-01-P" adv="1">20030407-01-P</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11860">irix-ldap-authentication-bypass(11860)</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-084.shtml">N-084</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sgi" name="irix">
                <vers num="6.5" />
                <vers num="6.5.1" />
                <vers num="6.5.10" />
                <vers num="6.5.10f" />
                <vers num="6.5.10m" />
                <vers num="6.5.11" />
                <vers num="6.5.11f" />
                <vers num="6.5.11m" />
                <vers num="6.5.12" />
                <vers num="6.5.12f" />
                <vers num="6.5.12m" />
                <vers num="6.5.13" />
                <vers num="6.5.13f" />
                <vers num="6.5.13m" />
                <vers num="6.5.14" />
                <vers num="6.5.14f" />
                <vers num="6.5.14m" />
                <vers num="6.5.15" />
                <vers num="6.5.15f" />
                <vers num="6.5.15m" />
                <vers num="6.5.16" />
                <vers num="6.5.16f" />
                <vers num="6.5.16m" />
                <vers num="6.5.17" />
                <vers num="6.5.17f" />
                <vers num="6.5.17m" />
                <vers num="6.5.18" />
                <vers num="6.5.18f" />
                <vers num="6.5.18m" />
                <vers num="6.5.19" />
                <vers num="6.5.19f" />
                <vers num="6.5.19m" />
                <vers num="6.5.2" />
                <vers num="6.5.2f" />
                <vers num="6.5.2m" />
                <vers num="6.5.3" />
                <vers num="6.5.3f" />
                <vers num="6.5.3m" />
                <vers num="6.5.4" />
                <vers num="6.5.4f" />
                <vers num="6.5.4m" />
                <vers num="6.5.5" />
                <vers num="6.5.5f" />
                <vers num="6.5.5m" />
                <vers num="6.5.6" />
                <vers num="6.5.6f" />
                <vers num="6.5.6m" />
                <vers num="6.5.7" />
                <vers num="6.5.7f" />
                <vers num="6.5.7m" />
                <vers num="6.5.8" />
                <vers num="6.5.8f" />
                <vers num="6.5.8m" />
                <vers num="6.5.9" />
                <vers num="6.5.9f" />
                <vers num="6.5.9m" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0190" seq="2003-0190" severity="Medium" type="CVE" published="2003-05-12" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7467" adv="1">7467</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105172058404810&amp;w=2" adv="1">20030430 OpenSSH/PAM timing attack allows remote users identification</ref>
            <ref source="TURBO" url="http://www.turbolinux.com/security/TLSA-2003-31.txt">TLSA-2003-31</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-224.html">RHSA-2003:224</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-222.html">RHSA-2003:222</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=106018677302607&amp;w=2">20030806 [OpenPKG-SA-2003.035] OpenPKG Security Advisory (openssh)</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105172058404810&amp;w=2">20030430 OpenSSH/PAM timing attack allows remote users identification</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2003-April/004815.html">20030430 OpenSSH/PAM timing attack allows remote users identification</ref>
            <ref source="MISC" url="http://lab.mediaservice.net/advisory/2003-01-openssh.txt">http://lab.mediaservice.net/advisory/2003-01-openssh.txt</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:445" sig="1">oval:org.mitre.oval:def:445</ref>
        </refs>
        <vuln_soft>
            <prod vendor="openbsd" name="openssh">
                <vers num="3.4p1" />
                <vers num="3.6.1p1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0212" seq="2003-0212" severity="High" type="CVE" published="2003-05-12" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">handleAccept in rinetd before 0.62 does not properly resize the connection list when it becomes full and sets an array index incorrectly, which allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large number of connections.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-289" adv="1">DSA-289</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105059298502830&amp;w=2" adv="1">20030417 Vulnerability in rinetd</ref>
        </refs>
        <vuln_soft>
            <prod vendor="rinetd" name="rinetd">
                <vers num="0.52" />
                <vers num="0.61" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0213" seq="2003-0213" severity="High" type="CVE" published="2003-05-12" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">ctrlpacket.c in PoPToP PPTP server before 1.1.4-b3 allows remote attackers to cause a denial of service via a length field of 0 or 1, which causes a negative value to be fed into a read operation, leading to a buffer overflow.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/673993">VU#673993</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7316" adv="1">7316</ref>
            <ref source="BUGTRAQ" patch="1" url="http://www.securityfocus.com/archive/1/317995" adv="1">20030409 PoPToP PPTP server remotely exploitable buffer overflow</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-295" adv="1">DSA-295</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2003_029.html">SuSE-SA:2003:029</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105068728421160&amp;w=2" adv="1">20030418 Exploit for PoPToP PPTP server</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/319428">20030422 Re: Exploit for PoPToP PPTP server - Linux version</ref>
            <ref source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=138437">http://sourceforge.net/project/shownotes.php?release_id=138437</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105154539727967&amp;w=2">20030428 GLSA:  pptpd (200304-08)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="poptop" name="pptp_server">
                <vers num="1.0.1" />
                <vers num="1.1.2" />
                <vers num="1.1.3" />
                <vers num="1.1.3_2002-10-09" />
                <vers num="1.1.4b1" />
                <vers num="1.1.4b2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2003-0214" seq="2003-0214" severity="Medium" type="CVE" published="2003-05-12" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-05">
        <desc>
            <descript source="cve">run-mailcap in mime-support 3.22 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-292" adv="1">DSA-292</ref>
        </refs>
        <vuln_soft>
            <prod vendor="debian" name="mime-support">
                <vers num="3.10" />
                <vers num="3.11" />
                <vers num="3.12" />
                <vers num="3.13" />
                <vers num="3.14" />
                <vers num="3.15" />
                <vers num="3.16" />
                <vers num="3.17" />
                <vers num="3.18" />
                <vers num="3.19" />
                <vers num="3.20" />
                <vers num="3.21" />
                <vers num="3.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0215" seq="2003-0215" severity="High" type="CVE" published="2003-05-12" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">SQL injection vulnerability in bttlxeForum 2.0 beta 3 and earlier allows remote attackers to bypass authentication via the (1) username and (2) password fields, and possibly other fields.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <access />
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.battleaxesoftware.com/forums/forum.asp?forumid=36&amp;select=1812" adv="1">http://www.battleaxesoftware.com/forums/forum.asp?forumid=36&amp;select=1812</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105120052725940&amp;w=2" adv="1">20030424 SQL injection in BttlxeForum</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1006632">1006632</ref>
        </refs>
        <vuln_soft>
            <prod vendor="battleaxe_software" name="bttlxeforum">
                <vers num="2.0_beta_3" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2003-0216" seq="2003-0216" severity="High" type="CVE" published="2003-05-12" CVSS_version="2.0" CVSS_score="9.3" modified="2008-09-10">
        <desc>
            <descript source="cve">Unknown vulnerability in Cisco Catalyst 7.5(1) allows local users to bypass authentication and gain access to the enable mode without a password.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <access />
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/443257">VU#443257</ref>
            <ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20030424-catos.shtml.">20030424 Cisco Security Advisory: Cisco Catalyst Enable Password Bypass Vulnerability</ref>
        </refs>
        <vuln_soft>
            <prod vendor="cisco" name="catos">
                <vers num="7.5(1)" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0210" seq="2003-0210" severity="High" type="CVE" published="2003-05-12" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Buffer overflow in the administration service (CSAdmin) for Cisco Secure ACS before 3.1.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long user parameter to port 2002.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/697049">VU#697049</ref>
            <ref source="CISCO" patch="1" url="http://www.cisco.com/warp/public/707/cisco-sa-20030423-ACS.shtml" adv="1">20030423 Cisco Secure Access Control Server for Windows Admin Buffer Overflow Vulnerability</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105120066126196&amp;w=2" adv="1">20030424 NSFOCUS SA2003-04 : Remote Buffer Overflow Vulnerability in Web Management Interface of Cisco Secure ACS</ref>
            <ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=105118056332344&amp;w=2">20030424 NSFOCUS SA2003-04 : Remote Buffer Overflow Vulnerability in Web Management Interface of Cisco Secure ACS</ref>
        </refs>
        <vuln_soft>
            <prod vendor="cisco" name="secure_access_control_server">
                <vers num="2.1" />
                <vers num="2.3" />
                <vers num="2.4" />
                <vers num="2.5" />
                <vers num="2.6" />
                <vers num="2.6.2" />
                <vers num="2.6.3" />
                <vers num="2.6.4" />
                <vers num="3.0" />
                <vers num="3.0.1" />
                <vers num="3.0.3" />
                <vers num="3.1.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0205" seq="2003-0205" severity="High" type="CVE" published="2003-05-12" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">gkrellm-newsticker gkrellm plugin before 0.3-3.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the ticker title of a URI.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-294" adv="1">DSA-294</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105111327000755&amp;w=2" adv="1">20030423 Security problems in gkrellm-newsticker</ref>
        </refs>
        <vuln_soft>
            <prod vendor="gkrellm_newsticker" name="gkrellm_newsticker">
                <vers num="0.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0206" seq="2003-0206" severity="Medium" type="CVE" published="2003-05-12" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">gkrellm-newsticker gkrellm plugin before 0.3-3.1 allows remote attackers to cause a denial of service (crash) via (1) link or (2) title elements that contain multiple lines.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-294" adv="1">DSA-294</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105111327000755&amp;w=2" adv="1">20030423 Security problems in gkrellm-newsticker</ref>
        </refs>
        <vuln_soft>
            <prod vendor="gkrellm_newsticker" name="gkrellm_newsticker">
                <vers num="0.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2003-0112" seq="2003-0112" severity="Medium" type="CVE" published="2003-05-12" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2008-09-10">
        <desc>
            <descript source="cve">Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/446338">VU#446338</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7370" adv="1">7370</ref>
            <ref source="MS" patch="1" url="http://www.microsoft.com/technet/security/bulletin/MS03-013.asp" adv="1">MS03-013</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11803">win-kernel-lpcrequestwaitreplyport-bo(11803)</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:779" sig="1">oval:org.mitre.oval:def:779</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3145" sig="1">oval:org.mitre.oval:def:3145</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:262" sig="1">oval:org.mitre.oval:def:262</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2265" sig="1">oval:org.mitre.oval:def:2265</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2022" sig="1">oval:org.mitre.oval:def:2022</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:142" sig="1">oval:org.mitre.oval:def:142</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1264" sig="1">oval:org.mitre.oval:def:1264</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="windows_2000">
                <vers edition=":professional" num="" />
                <vers edition=":datacenter_server" num="" />
                <vers edition=":server" num="" />
                <vers edition=":advanced_server" num="" />
                <vers edition="sp1" num="" />
                <vers edition="sp1:server" num="" />
                <vers edition="sp1:professional" num="" />
                <vers edition="sp1:datacenter_server" num="" />
                <vers edition="sp1:advanced_server" num="" />
                <vers edition="sp2" num="" />
                <vers edition="sp2:server" num="" />
                <vers edition="sp2:advanced_server" num="" />
                <vers edition="sp2:datacenter_server" num="" />
                <vers edition="sp2:professional" num="" />
                <vers edition="sp3" num="" />
                <vers edition="sp3:advanced_server" num="" />
                <vers edition="sp3:professional" num="" />
                <vers edition="sp3:datacenter_server" num="" />
                <vers edition="sp3:server" num="" />
            </prod>
            <prod vendor="microsoft" name="windows_2000_terminal_services">
                <vers edition="sp1" num="" />
                <vers edition="sp2" num="" />
                <vers edition="sp3" num="" />
            </prod>
            <prod vendor="microsoft" name="windows_nt">
                <vers edition="" num="4.0" />
                <vers edition=":terminal_server" num="4.0" />
                <vers edition=":workstation" num="4.0" />
                <vers edition=":enterprise_server" num="4.0" />
                <vers edition=":server" num="4.0" />
                <vers edition="sp1" num="4.0" />
                <vers edition="sp1:server" num="4.0" />
                <vers edition="sp1:enterprise_server" num="4.0" />
                <vers edition="sp1:workstation" num="4.0" />
                <vers edition="sp1:terminal_server" num="4.0" />
                <vers edition="sp2" num="4.0" />
                <vers edition="sp2:terminal_server" num="4.0" />
                <vers edition="sp2:workstation" num="4.0" />
                <vers edition="sp2:server" num="4.0" />
                <vers edition="sp2:enterprise_server" num="4.0" />
                <vers edition="sp3" num="4.0" />
                <vers edition="sp3:terminal_server" num="4.0" />
                <vers edition="sp3:enterprise_server" num="4.0" />
                <vers edition="sp3:server" num="4.0" />
                <vers edition="sp3:workstation" num="4.0" />
                <vers edition="sp4" num="4.0" />
                <vers edition="sp4:terminal_server" num="4.0" />
                <vers edition="sp4:enterprise_server" num="4.0" />
                <vers edition="sp4:workstation" num="4.0" />
                <vers edition="sp4:server" num="4.0" />
                <vers edition="sp5" num="4.0" />
                <vers edition="sp5:terminal_server" num="4.0" />
                <vers edition="sp5:server" num="4.0" />
                <vers edition="sp5:workstation" num="4.0" />
                <vers edition="sp5:enterprise_server" num="4.0" />
                <vers edition="sp6" num="4.0" />
                <vers edition="sp6:enterprise_server" num="4.0" />
                <vers edition="sp6:terminal_server" num="4.0" />
                <vers edition="sp6:server" num="4.0" />
                <vers edition="sp6:workstation" num="4.0" />
                <vers edition="sp6a" num="4.0" />
                <vers edition="sp6a:terminal_server" num="4.0" />
                <vers edition="sp6a:server" num="4.0" />
                <vers edition="sp6a:workstation" num="4.0" />
                <vers edition="sp6a:enterprise_server" num="4.0" />
            </prod>
            <prod vendor="microsoft" name="windows_xp">
                <vers edition=":64-bit" num="" />
                <vers edition=":home" num="" />
                <vers edition="gold" num="" />
                <vers edition="gold:professional" num="" />
                <vers edition="sp1" num="" />
                <vers edition="sp1:64-bit" num="" />
                <vers edition="sp1:home" num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0113" seq="2003-0113" severity="High" type="CVE" published="2003-05-12" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via an HTTP response containing long values in (1) Content-type and (2) Content-encoding fields.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/169753">VU#169753</ref>
            <ref source="MS" patch="1" url="http://www.microsoft.com/technet/security/bulletin/ms03-015.asp" adv="1">MS03-015</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105138417416900&amp;w=2" adv="1">20030426 Buffer overflow in Internet Explorer's HTTP parsing code</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105718285107246&amp;w=2">20030701 URLMON.DLL buffer overflow - technical details</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:926" sig="1">oval:org.mitre.oval:def:926</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="ie">
                <vers edition="sp1" num="5.0.1" />
                <vers edition="sp2" num="5.0.1" />
                <vers edition="sp3" num="5.0.1" />
                <vers edition="sp1" num="5.5" />
                <vers edition="sp2" num="5.5" />
                <vers edition="sp1" num="6.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0114" seq="2003-0114" severity="Medium" type="CVE" published="2003-05-12" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-10">
        <desc>
            <descript source="cve">The file upload control in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to automatically upload files from the local system via a web page containing a script to upload the files.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MS" patch="1" url="http://www.microsoft.com/technet/security/bulletin/ms03-015.asp" adv="1">MS03-015</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=104429340817718&amp;w=2" adv="1">20030203 internet explorer local file reading</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:963" sig="1">oval:org.mitre.oval:def:963</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="ie">
                <vers edition="sp1" num="5.0.1" />
                <vers edition="sp2" num="5.0.1" />
                <vers edition="sp3" num="5.0.1" />
                <vers edition="sp1" num="5.5" />
                <vers edition="sp2" num="5.5" />
                <vers edition="sp1" num="6.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0115" seq="2003-0115" severity="High" type="CVE" published="2003-05-12" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check parameters that are passed during third party rendering, which could allow remote attackers to execute arbitrary web script, aka the "Third Party Plugin Rendering" vulnerability, a different vulnerability than CVE-2003-0233.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MS" patch="1" url="http://www.microsoft.com/technet/security/bulletin/ms03-015.asp" adv="1">MS03-015</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/11848.php" adv="1">ie-improper-thirdparty-rendering(11848)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="ie">
                <vers edition="sp1" num="5.0.1" />
                <vers edition="sp2" num="5.0.1" />
                <vers edition="sp3" num="5.0.1" />
                <vers edition="sp1" num="5.5" />
                <vers edition="sp2" num="5.5" />
                <vers edition="sp1" num="6.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0116" seq="2003-0116" severity="Medium" type="CVE" published="2003-05-12" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2008-09-05">
        <desc>
            <descript source="cve">Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check the Cascading Style Sheet input parameter for Modal dialogs, which allows remote attackers to read files on the local system via a web page containing script that creates a dialog and then accesses the target files, aka "Modal Dialog script execution."</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/244729">VU#244729</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/6306" adv="1">6306</ref>
            <ref source="MS" patch="1" url="http://www.microsoft.com/technet/security/bulletin/ms03-015.asp" adv="1">MS03-015</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/301945">20021203 Poisonous Style for Dialog window turns the zone off.</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="ie">
                <vers edition="sp1" num="5.0.1" />
                <vers edition="sp2" num="5.0.1" />
                <vers edition="sp3" num="5.0.1" />
                <vers edition="sp1" num="5.5" />
                <vers edition="sp2" num="5.5" />
                <vers edition="sp1" num="6.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0117" seq="2003-0117" severity="High" type="CVE" published="2003-05-12" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">Buffer overflow in the HTTP receiver function (BizTalkHTTPReceive.dll ISAPI) of Microsoft BizTalk Server 2002 allows attackers to execute arbitrary code via a certain request to the HTTP receiver.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MS" patch="1" url="http://www.microsoft.com/technet/security/bulletin/ms03-016.asp" adv="1">MS03-016</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105216866132289&amp;w=2">20030505 Microsoft Biztalk Server ISAPI HTTP Receive function buffer overflow</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="biztalk_server">
                <vers edition="" num="2002" />
                <vers edition=":enterprise" num="2002" />
                <vers edition=":developer" num="2002" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0118" seq="2003-0118" severity="High" type="CVE" published="2003-05-12" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-10">
        <desc>
            <descript source="cve">SQL injection vulnerability in the Document Tracking and Administration (DTA) website of Microsoft BizTalk Server 2000 and 2002 allows remote attackers to execute operating system commands via a request to (1) rawdocdata.asp or (2) RawCustomSearchField.asp containing an embedded SQL statement.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MS" patch="1" url="http://www.microsoft.com/technet/security/bulletin/ms03-016.asp" adv="1">MS03-016</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=105216839231951&amp;w=2">20030505 Microsoft Biztalk Server DTA vulnerable to SQL injection</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="biztalk_server">
                <vers edition="" num="2000" />
                <vers edition=":standard" num="2000" />
                <vers edition=":enterprise" num="2000" />
                <vers edition=":developer" num="2000" />
                <vers edition="sp1a" num="2000" />
                <vers edition="sp1a:enterprise" num="2000" />
                <vers edition="sp1a:developer" num="2000" />
                <vers edition="sp1a:standard" num="2000" />
                <vers edition="sp2" num="2000" />
                <vers edition="sp2:standard" num="2000" />
                <vers edition="sp2:developer" num="2000" />
                <vers edition="sp2:enterprise" num="2000" />
                <vers edition="" num="2002" />
                <vers edition=":enterprise" num="2002" />
                <vers edition=":developer" num="2002" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2003-0084" seq="2003-0084" severity="High" type="CVE" published="2003-05-12" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2008-09-05">
        <desc>
            <descript source="cve">mod_auth_any package in Red Hat Enterprise Linux 2.1 and other operating systems does not properly escape arguments when calling other programs, which allows attackers to execute arbitrary commands via shell metacharacters.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/7448" adv="1">7448</ref>
            <ref source="REDHAT" patch="1" url="http://rhn.redhat.com/errata/RHSA-2003-114.html" adv="1">RHSA-2003:114</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11893">modauthany-command-execution(11893)</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-113.html">RHSA-2003:113</ref>
            <ref source="CONFIRM" url="http://www.itlab.musc.edu/webNIS/mod_auth_any.html">http://www.itlab.musc.edu/webNIS/mod_auth_any.html</ref>
            <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/n-090.shtml">N-090</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mod_auth_any" name="mod_auth_any">
                <vers num="1.2.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2003-0308" seq="2003-0308" severity="High" type="CVE" published="2003-05-15" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-11-11">
        <desc>
            <descript source="cve">The Sendmail 8.12.3 package in Debian GNU/Linux 3.0 does not securely create temporary files, which could allow local users to gain additional privileges via (1) expn, (2) checksendmail, or (3) doublebounce.pl.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2003/dsa-305">DSA-305</ref>
            <ref source="CONFIRM" url="https://bugs.gentoo.org/show_bug.cgi?id=235770">https://bugs.gentoo.org/show_bug.cgi?id=235770</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2008/10/30/2">[oss-security] 20081030 CVE requests: tempfile issues for aview, mgetty, openoffice, crossfire</ref>
            <ref source="CONFIRM" url="http://dev.gentoo.org/~rbu/security/debiantemp/sendmail-base">http://dev.gentoo.org/~rbu/security/debiantemp/sendmail-base</ref>
            <ref source="CONFIRM" url="http://bugs.debian.org/496408">http://bugs.debian.org/496408</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sendmail" name="sendmail">
                <vers num="8.12.3" />
                <vers num="8.12.9" />
                <vers num="8.9.3" />
            </prod>
            <prod vendor="debian" name="debian_linux">
                <vers num="3.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2003-0333" seq="2003-0333" severity="High" type="CVE" published="2003-05-19" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2008-09-05">
        <desc>
            <descript source="cve">Multiple buffer overflows in kermit in HP-UX 10.20 and 11.00 (C-Kermit 6.0.192 and possibly other versions before 8.0) allow local users to gain privileges via long arguments to (1) ask, (2) askq, (3) define, (4) assign, and (5) getc, some of which may share the same underlying function "doask," a different vulnerability than CVE-2001-0085.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb